Tag Windows

Iranian Hackers Disrupt Operations at Key U.S. Infrastructure Sites

Iranian Hackers Targeting US Critical Infrastructure Amid Ongoing Tensions Recent reports indicate that hackers tied to the Iranian government are actively disrupting operations at various critical infrastructure sites across the United States. This disruption appears to be a reaction to the heightened geopolitical conflict between Iran and the U.S., as…

Read MoreIranian Hackers Disrupt Operations at Key U.S. Infrastructure Sites

Unresolved Unauthorized File Read Vulnerability Impacts Microsoft Windows OS

On November 30, 2021, it was reported that unofficial patches have been released to address a poorly patched Windows security flaw which poses risks for information disclosure and local privilege escalation (LPE) on affected systems. Identified as CVE-2021-24084 (CVSS score: 5.5), this vulnerability is linked to the Windows Mobile Device Management component, potentially allowing attackers to gain unauthorized access to the file system and read arbitrary files. Security researcher Abdelhamid Naceri discovered and reported the issue in October 2020, leading Microsoft to include it in their February 2021 Patch Tuesday updates. However, as noted by Naceri in June 2021, the patch can be bypassed, and it has also been found that the inadequately addressed vulnerability enables attackers to gain administrator privileges and execute malicious code on Windows 10 systems.

Unpatched Unauthorized File Read Vulnerability Exposes Microsoft Windows OS Published: November 30, 2021 A security vulnerability affecting Microsoft Windows operating systems has come to light, revealing potential risks for data disclosure and local privilege escalation. This flaw, identified as CVE-2021-24084 and assigned a CVSS score of 5.5, pertains specifically to…

Read More

Unresolved Unauthorized File Read Vulnerability Impacts Microsoft Windows OS

On November 30, 2021, it was reported that unofficial patches have been released to address a poorly patched Windows security flaw which poses risks for information disclosure and local privilege escalation (LPE) on affected systems. Identified as CVE-2021-24084 (CVSS score: 5.5), this vulnerability is linked to the Windows Mobile Device Management component, potentially allowing attackers to gain unauthorized access to the file system and read arbitrary files. Security researcher Abdelhamid Naceri discovered and reported the issue in October 2020, leading Microsoft to include it in their February 2021 Patch Tuesday updates. However, as noted by Naceri in June 2021, the patch can be bypassed, and it has also been found that the inadequately addressed vulnerability enables attackers to gain administrator privileges and execute malicious code on Windows 10 systems.

StoneDrill Disk Wiping Malware Discovered Targeting European Industries

A newly identified disk-wiping malware known as StoneDrill has emerged, targeting a petroleum company in Europe. This malware bears similarities to the infamous Shamoon, which notoriously deleted data from 35,000 computers at Saudi Arabia’s national oil company back in 2012. Disk-wiping malware like StoneDrill can inflict severe damage on organizations…

Read MoreStoneDrill Disk Wiping Malware Discovered Targeting European Industries

Samba Releases Security Updates to Address Several High-Severity Vulnerabilities

The open-source software suite Samba has issued critical updates to address several high-severity vulnerabilities that pose significant risks to system security. If exploited, these flaws could allow unauthorized users to gain control over the affected systems. The vulnerabilities, identified as CVE-2022-38023, CVE-2022-37966, CVE-2022-37967, and CVE-2022-45141, have been patched in the…

Read MoreSamba Releases Security Updates to Address Several High-Severity Vulnerabilities

Caution: Virus Alert on Windows, MacOS, and Linux Spreading via Facebook Messenger

### Recent Facebook Messenger Malware Campaign A concerning cybersecurity threat has emerged within Facebook Messenger, where users are encountering deceptive video links purportedly sent by friends, which can lead to malicious software installations. Researchers at Kaspersky Lab have uncovered a cross-platform malware campaign targeting users through these seemingly innocuous links.…

Read MoreCaution: Virus Alert on Windows, MacOS, and Linux Spreading via Facebook Messenger

LockBit Ransomware Launches Powerful 5.0 Version Targeting Windows, Linux, and ESXi Systems – Cyber Press

LockBit Ransomware: Version 5.0 Targets Windows, Linux, and ESXi Systems In recent developments within the cybersecurity landscape, the notorious LockBit ransomware group has unleashed a new and highly sophisticated variant, version 5.0. This latest iteration is designed to target a multitude of operating systems, including Windows, Linux, and virtual environments…

Read MoreLockBit Ransomware Launches Powerful 5.0 Version Targeting Windows, Linux, and ESXi Systems – Cyber Press

Revealed: ‘SowBug’ Cyber-Espionage Group Stealing Diplomatic Secrets Since 2015

Security researchers at Symantec have identified a previously undisclosed cyber-espionage group, codenamed Sowbug, that has been active since at least 2015. This group has focused its attacks on government entities across South America and Southeast Asia, aiming to exfiltrate sensitive data from institutions engaged in foreign policy and diplomatic affairs.…

Read MoreRevealed: ‘SowBug’ Cyber-Espionage Group Stealing Diplomatic Secrets Since 2015

Microsoft Releases Patches for 80 Vulnerabilities, Including Two Currently Under Attack

In its March 2023 Patch Tuesday update, Microsoft disclosed fixes for 80 security vulnerabilities, two of which have been actively exploited in the wild. These vulnerabilities target critical components within the Microsoft ecosystem, with eight categorized as Critical, 71 as Important, and one as Moderate in severity. This update continues…

Read MoreMicrosoft Releases Patches for 80 Vulnerabilities, Including Two Currently Under Attack