CISA Order Highlights Persistent Risk at Network Edge

Credit to Author: BrianKrebs| Date: Thu, 15 Jun 2023 15:40:09 +0000

The U.S. government agency in charge of improving the nation’s cybersecurity posture is ordering all federal civilian agencies to take new measures to restrict access to Internet-exposed networking equipment. The directive comes amid a surge in attacks targeting previously unknown vulnerabilities in widely used security and networking appliances.

Read more

Clop ransomware is victimizing GoAnywhere MFT customers

Categories: Exploits and vulnerabilities

Categories: News

Categories: Ransomware

Tags: Clop

Tags: ransomware

Tags: GoAnywhere

Tags: CVE-2023-0669

The Clop ransomware gang has claimed responsibility for attacking several GoAnywhere MFT customers by exploiting a vulnerability in the managed file transfer software’s administrative interface.

(Read more…)

The post Clop ransomware is victimizing GoAnywhere MFT customers appeared first on Malwarebytes Labs.

Read more

GoAnywhere zero-day opened door to Clop ransomware

Categories: News

Categories: Ransomware

Tags: Clop

Tags: Clop ransomware

Tags: ransomware

Tags: GoAnywhere

Tags: managed file transfer

Tags: MFT

Tags: Fortra

Tags: CISA

Tags: Known Exploited Vulnerabilities Catalog

The Clop ransomware gang has claimed responsibility for a wave of attacks that exploited a zero-day in GoAnywhere MFT admin consoles.

(Read more…)

The post GoAnywhere zero-day opened door to Clop ransomware appeared first on Malwarebytes Labs.

Read more

Update now! February’s Patch Tuesday tackles three zero-days

Categories: Exploits and vulnerabilities

Categories: News

Tags: patch Tuesday

Tags: Microsoft

Tags: Apple

Tags: Adobe

Tags: SAP

Tags: Citrix

Tags: Cisco

Tags: Atlassian

Tags: Google

Tags: Mozilla

Tags: Forta

Tags: OpenSSH

Tags: CVE-2023-21823

Tags: CVE-2023-21715

Tags: OneNote

Tags: CVE-2023-23376

Tags: CVE-2023-21706

Tags: CVE-2023-21707

Tags: CVE-2023-21529

Tags: CVE-2023-21716

Tags: CVE-2023-23378

Tags: CVE-2023-22501

Tags: CVE-2023-24486

Tags: CVE-2023-24484

Tags: CVE-2023-24484

Tags: CVE-2023-24483

Tags: CVE-2023-25136

Tags: GoAnywhere

Microsoft has released updates to patch three zero-days and lots of other vulnerabilities and so have several other vendors

(Read more…)

The post Update now! February’s Patch Tuesday tackles three zero-days appeared first on Malwarebytes Labs.

Read more

A week in security (February 6 – 12)

Categories: News

Tags: VMware ESXi

Tags: Safer Internet Day

Tags: Malwarebytes Mobile Security

Tags: ION

Tags: LockBit ransomware

Tags: ransomware

Tags: GoAnywhere

Tags: Ryuk

Tags: Malwarebytes Application Block

Tags: BEC

Tags: business email compromise

Tags: fake Facebook

Tags: Facebook

Tags: Reddit breach

Tags: Killnet

Tags: DDoS attack

The most interesting security related news from the week of February 6 to 12.

(Read more…)

The post A week in security (February 6 – 12) appeared first on Malwarebytes Labs.

Read more