Security

MicrosoftSecurity

IoT devices and Linux-based systems targeted by OpenSSH trojan campaign

Credit to Author: Microsoft Threat Intelligence| Date: Thu, 22 Jun 2023 16:00:00 +0000

Microsoft has uncovered an attack leveraging custom and open-source tools to target internet-facing IoT devices and Linux-based systems. The attack involves deploying a patched version of OpenSSH on affected devices to allow root login and the hijack of SSH credentials.

The post IoT devices and Linux-based systems targeted by OpenSSH trojan campaign appeared first on Microsoft Security Blog.

Read More
MalwareBytesSecurity

Update now! Apple fixes three actively exploited vulnerabilities

Categories: Apple

Categories: Exploits and vulnerabilities

Categories: News

Tags: Apple

Tags: kernel webkit

Tags: CVE-2023-32434

Tags: CVE-2023-32435

Tags: CVE-2023-32439

Tags: type confusion

Tags: integer overflow

Tags: operation triangulation

Apple has released security updates for several products to address a set of flaws it said were being actively exploited.

(Read more…)

The post Update now! Apple fixes three actively exploited vulnerabilities appeared first on Malwarebytes Labs.

Read More
MalwareBytesSecurity

Reducing your attack surface is more effective than playing patch-a-mole

Categories: News

Tags: CISA

Tags: BOD 23-02

Tags: Internet exposed

Tags: management interfaces

Tags: vulnerabilities

Tags: CVE-2023-27992

Tags: CVE-2023-20887

There is a lot to be said for the strategy of shielding management interfaces from public internet access

(Read more…)

The post Reducing your attack surface is more effective than playing patch-a-mole appeared first on Malwarebytes Labs.

Read More