FBI Cracks Down on Dark Web Marketplace Managed by Russian and Kazakh Nationals – OfficialSarkar

FBI Cracks Down on Dark Web Marketplace Managed by Russian and Kazakh Nationals – OfficialSarkar

Sep 07, 2024Ravie LakshmananCybercrime / Dark Web Two men have been indicted in the U.S. for their alleged involvement in managing a dark web marketplace called WWH Club that specializes in the sale of sensitive personal and financial information. Alex Khodyrev, a 35-year-old Kazakhstan national, and Pavel Kublitskii, a 37-year-old Russian national, have been charged…

North Korean Threat Actors Deploy COVERTCATCH Malware via LinkedIn Job Scams – OfficialSarkar

North Korean Threat Actors Deploy COVERTCATCH Malware via LinkedIn Job Scams – OfficialSarkar

Sep 07, 2024Ravie LakshmananCyber Security / Malware Threat actors affiliated with North Korea have been observed leveraging LinkedIn as a way to target developers as part of a fake job recruiting operation. These attacks employ coding tests as a common initial infection vector, Google-owned Mandiant said in a new report about threats faced by the…

GitHub Actions Vulnerable to Typosquatting, Exposing Developers to Hidden Malicious Code – OfficialSarkar

GitHub Actions Vulnerable to Typosquatting, Exposing Developers to Hidden Malicious Code – OfficialSarkar

Sep 06, 2024Ravie LakshmananSoftware Security / Hacking Threat actors have long leveraged typosquatting as a means to trick unsuspecting users into visiting malicious websites or downloading booby-trapped software and packages. These attacks typically involve registering domains or packages with names slightly altered from their legitimate counterparts (e.g., goog1e.com vs. google.com). Adversaries targeting open-source repositories across…

SonicWall Urges Users to Patch Critical Firewall Flaw Amid Possible Exploitation – OfficialSarkar

SonicWall Urges Users to Patch Critical Firewall Flaw Amid Possible Exploitation – OfficialSarkar

Sep 06, 2024Ravie LakshmananNetwork Security / Threat Detection SonicWall has revealed that a recently patched critical security flaw impacting SonicOS may have come under active exploitation, making it essential that users apply the patches as soon as possible. The vulnerability, tracked as CVE-2024-40766, carries a CVSS score of 9.3 out of a maximum of 10….

GeoServer Vulnerability Targeted by Hackers to Deliver Backdoors and Botnet Malware – OfficialSarkar

GeoServer Vulnerability Targeted by Hackers to Deliver Backdoors and Botnet Malware – OfficialSarkar

Sep 06, 2024Ravie LakshmananCryptocurrency / APT Attack A recently disclosed security flaw in OSGeo GeoServer GeoTools has been exploited as part of multiple campaigns to deliver cryptocurrency miners, botnet malware such as Condi and JenX, and a known backdoor called SideWalk. The security vulnerability is a critical remote code execution bug (CVE-2024-36401, CVSS score: 9.8)…

MSP/MSSP Security Strategies for 2025 – OfficialSarkar

MSP/MSSP Security Strategies for 2025 – OfficialSarkar

The 2024 State of the vCISO Report continues Cynomi’s tradition of examining the growing popularity of virtual Chief Information Security Officer (vCISO) services. According to the independent survey, the demand for these services is increasing, with both providers and clients reaping the rewards. The upward trend is set to continue, with even faster growth expected…

Critical Security Flaw Found in LiteSpeed Cache Plugin for WordPress – OfficialSarkar

Critical Security Flaw Found in LiteSpeed Cache Plugin for WordPress – OfficialSarkar

Sep 06, 2024Ravie LakshmananWordPress / Webinar Security Cybersecurity researchers have discovered yet another critical security flaw in the LiteSpeed Cache plugin for WordPress that could allow unauthenticated users to take control of arbitrary accounts. The vulnerability, tracked as CVE-2024-44000 (CVSS score: 7.5), impacts versions before and including 6.4.1. It has been addressed in version 6.5.0.1….

Pavel Durov Criticizes Outdated Laws After Arrest Over Telegram Criminal Activity – OfficialSarkar

Pavel Durov Criticizes Outdated Laws After Arrest Over Telegram Criminal Activity – OfficialSarkar

Sep 06, 2024Ravie LakshmananPrivacy / Data Security Telegram CEO Pavel Durov has broken his silence nearly two weeks after his arrest in France, stating the charges are misguided. “If a country is unhappy with an internet service, the established practice is to start a legal action against the service itself,” Durov said in a 600-word…

Apache OFBiz Update Fixes High-Severity Flaw Leading to Remote Code Execution – OfficialSarkar

Apache OFBiz Update Fixes High-Severity Flaw Leading to Remote Code Execution – OfficialSarkar

Sep 06, 2024Ravie LakshmananCybersecurity / Vulnerability A new security flaw has been addressed in the Apache OFBiz open-source enterprise resource planning (ERP) system that, if successfully exploited, could lead to unauthenticated remote code execution on Linux and Windows. The high-severity vulnerability, tracked as CVE-2024-45195 (CVSS score: 7.5), affects all versions of the software before 18.12.16….

Veeam Releases Security Updates to Fix 18 Flaws, Including 5 Critical Issues – OfficialSarkar

Veeam Releases Security Updates to Fix 18 Flaws, Including 5 Critical Issues – OfficialSarkar

Sep 05, 2024Ravie LakshmananThreat Prevention / Software Security Veeam has shipped security updates to address a total of 18 security flaws impacting its software products, including five critical vulnerabilities that could result in remote code execution. The list of shortcomings is below – CVE-2024-40711 (CVSS score: 9.8) – A vulnerability in Veeam Backup & Replication…