Oracle WebLogic Server vulnerability added to CISA list as “known to be exploited”

Categories: Exploits and vulnerabilities

Categories: News

Tags: Oracle

Tags: WebLogic

Tags: CVE-2023-21839

Tags: CVE-2023-1389

Tags: CVE-2021-45046

Tags: CISA

Tags: reverse shell

An easy to exploit vulnerability in Oracle WebLogic Server has been added to the CISA list of things you really, really need to patch.

(Read more…)

The post Oracle WebLogic Server vulnerability added to CISA list as “known to be exploited” appeared first on Malwarebytes Labs.

Read more

Pre-ransomware notifications are paying off right from the bat

Categories: News

Categories: Ransomware

Tags: pre-ransomware notifications

Tags: JCDC

Tags: CISA

Tags: ransomware

Tags: IRS

Tags: Emotet

Tags: MDR

CISA has published the first results of its pre-ransomware notifications that were introduced at the start of 2023. And they appear to be working.

(Read more…)

The post Pre-ransomware notifications are paying off right from the bat appeared first on Malwarebytes Labs.

Read more

Warning issued over Royal ransomware

Categories: News

Categories: Ransomware

Tags: CISA

Tags: Royal

Tags: ransomware

Tags: phishing

Tags: RDP

Tags: public facing applications

In a Cybersecurity Advisory, CISA and the FBI have shared information about Royal ransomware, which despite being rather new has made a real name for itself.

(Read more…)

The post Warning issued over Royal ransomware appeared first on Malwarebytes Labs.

Read more

GoAnywhere zero-day opened door to Clop ransomware

Categories: News

Categories: Ransomware

Tags: Clop

Tags: Clop ransomware

Tags: ransomware

Tags: GoAnywhere

Tags: managed file transfer

Tags: MFT

Tags: Fortra

Tags: CISA

Tags: Known Exploited Vulnerabilities Catalog

The Clop ransomware gang has claimed responsibility for a wave of attacks that exploited a zero-day in GoAnywhere MFT admin consoles.

(Read more…)

The post GoAnywhere zero-day opened door to Clop ransomware appeared first on Malwarebytes Labs.

Read more

A week in security (February 13 – 19)

Categories: News

Tags: Josh Saxe

Tags: Lock and Code S04E04

Tags: AI

Tags: artificial intelligence

Tags: endpoint security leader

Tags: CISA

Tags: DPRK

Tags: ChatGPT

Tags: informed consent

Tags: valentine’s day

Tags: password sharing

Tags: Android

Tags: data leaks

Tags: ESXiArgs

Tags: TrickBot

Tags: Wordpress

Tags: fake Hogwarts Legacy

Tags: Arris router

Tags: ransomware

Tags: Mortal Kombat

Tags: Section 230

Tags: iPhone calendar spam

The most interesting security related news from the week of February 13 to 19.

(Read more…)

The post A week in security (February 13 – 19) appeared first on Malwarebytes Labs.

Read more

CISA issues alert with South Korean government about DPRK’s ransomware antics

Categories: News

Categories: Ransomware

Tags: CISA

Tags: ransomware

Tags: Democratic People’s Republic of Korea

Tags: DPRK

Tags: North Korea

Tags: WannaCry

Tags: EternalBlue

Tags: Lazarus Group

Tags: APT

Tags: Magniber

Tags: Magnitude exploit kit

Tags: exploit kit

Tags: EK

Tags: Andariel

Tags: Silent Chollima

Tags: Stonefly

Tags: Maui

Tags: H0lyGh0st

Tags: PLUTONIUM

Tags: Conti

The tactics of North Korean-sponsored ransomware cyberattacks against the healthcare sector and other vital infrastructure are highlighted in the latest #StopRansomware alert.

(Read more…)

The post CISA issues alert with South Korean government about DPRK’s ransomware antics appeared first on Malwarebytes Labs.

Read more

A week in security (January 30 – February 5)

Categories: News

Tags: week in security

Tags: blog roundup

Tags: Roomba

Tags: Facebook

Tags: Eileen Gun

Tags: Lock and Code

Tags: data wiper

Tags: LearnPress

Tags: Riot Games

Tags: League of Legends

Tags: malvertising

Tags: dark patterns

Tags: supply chain attacks

Tags: GitHub

Tags: ransomware monthly

Tags: ransomware

Tags: AV-TEST top product

Tags: multi-threat ransomware

Tags: CISA

Tags: BEC

Tags: business email compromise

The most interesting security related news from the week of January 30 – February 5.

(Read more…)

The post A week in security (January 30 – February 5) appeared first on Malwarebytes Labs.

Read more