The Breach News

Flawed Rowhammer Solutions on DDR4 DRAM Chips Reactivate Bit Flipping Vulnerabilities

The Rowhammer vulnerability has resurfaced as a significant concern for modern dynamic random access memory (DRAM) chips, enabling attackers to escalate privileges within targeted systems by exploiting memory access patterns that result in unintended bit flips. This critical issue arises from continuous access to specific memory rows, raising the potential…

Read MoreFlawed Rowhammer Solutions on DDR4 DRAM Chips Reactivate Bit Flipping Vulnerabilities

Vulnerable Robot Lawn Mower Opens the Door to New Concerns

Cramming for finals has become increasingly challenging, especially when educational platforms experience unexpected shutdowns. Recently, numerous students across the United States faced significant disruptions when Canvas entered “maintenance mode” due to a ransomware attack on its parent company, Instructure. The hacking group known as ShinyHunters has claimed responsibility for the…

Read MoreVulnerable Robot Lawn Mower Opens the Door to New Concerns

Adobe Issues Urgent Updates for Acrobat Reader, Photoshop, Bridge, and ColdFusion

In a significant move outside of the regular Patch Tuesday schedule, Adobe has released an extensive set of out-of-band software updates aimed at addressing a total of 41 newly discovered security vulnerabilities across six different products. This proactive approach follows Adobe’s recent communication regarding an impending security update for its…

Read MoreAdobe Issues Urgent Updates for Acrobat Reader, Photoshop, Bridge, and ColdFusion

Severe RCE Vulnerability Impacts Millions of OpenWrt-based Networking Devices

In a significant cybersecurity revelation, a researcher has unveiled critical technical details regarding a remote code execution vulnerability impacting OpenWrt, a commonly utilized Linux-based operating system for network devices such as routers and gateways. This vulnerability, cataloged as CVE-2020-7982, is tied to the OPKG package manager’s flaw in its integrity…

Read MoreSevere RCE Vulnerability Impacts Millions of OpenWrt-based Networking Devices

Chaos Unfolds as Cyberattack Disrupts Canvas Learning Platform During Finals

Cyberattack Disrupts US Educational Institutions Amid Final Exams A significant cyberattack impacted schools and universities across the United States on Thursday, coinciding with student final exams. The online learning platform, Canvas, which is widely used in educational settings, experienced substantial disruptions as students prepared for crucial assessments. Instructure, the parent…

Read MoreChaos Unfolds as Cyberattack Disrupts Canvas Learning Platform During Finals

CISA Alerts: Patched Pulse Secure VPNs May Still Leave Organizations Vulnerable to Hackers

The United States Cybersecurity and Infrastructure Security Agency (CISA) has recently issued an advisory urging organizations to update all Active Directory credentials to enhance security against cyberattacks exploiting a known remote code execution (RCE) vulnerability within Pulse Secure VPN servers, regardless of whether they have applied patches. This warning follows…

Read MoreCISA Alerts: Patched Pulse Secure VPNs May Still Leave Organizations Vulnerable to Hackers

Severe SaltStack RCE Vulnerability (CVSS Score 10) Impacts Thousands of Data Centers

Two critical security vulnerabilities have recently been uncovered in the open-source **SaltStack Salt configuration framework**, posing significant risks to servers operating in both data center and cloud settings. These vulnerabilities could potentially enable threat actors to execute arbitrary code remotely. The vulnerabilities, disclosed by F-Secure researchers this past Thursday, were…

Read MoreSevere SaltStack RCE Vulnerability (CVSS Score 10) Impacts Thousands of Data Centers

Introducing Rassvet: Russia’s Response to Starlink

In late March, Russian company Bureau 1440 successfully launched the first 16 satellites of its broadband internet constellation known as Rassvet, which observers have compared to SpaceX’s Starlink. This initiative aims to establish a global internet network, potentially masking larger strategic objectives, including military and communication control. The launch occurred…

Read MoreIntroducing Rassvet: Russia’s Response to Starlink