15-year-old Python bug puts 350,000 open-source projects at risk
Researchers at Trellix said they have patched nearly 62,000 open-source projects susceptible to a 15-year-old path traversal vulnerability in the Python ecosystem.
The bug, tracked under CVE-2007-4559, was discovered by Trellix's team in Python’s tarfile module late last year. It was first rep... Read more
Microsoft “strongly urges” admins to update their Exchange Servers
Unpatched servers make a tantalizing target for hackers, according to Microsoft.
This week Microsoft urged customers to keep their on-premises Exchange servers patched by applying the latest supported Cumulative Update (CU) to have them always ready to deploy an emergency security update.
Th... Read more
‘FBI and Europol take down ransomware group Hive’
Hive's infrastructure is down. Europol claims the ransomware group was tackled by a partnership of Dutch, German and US authorities.
"The FBI seized this site as part of a coordinated law enforcement action", reads the banner referred to by Hive's website since Thursday. The statement is signed ... Read more
‘Dutch hacker steals personal data of millions of Austrian citizens’
The Amsterdam Prosecutor's Office disclosed that a 25-year-old Dutch man was arrested in late November on suspicion of stealing personal data from tens of millions of people worldwide, including most of Austria's population.
The data was allegedly offered for sale. The cybercriminal landed on t... Read more
ServiceNow invests $25 million in Snyk
ServiceNow announced a strategic investment in Snyk. The startup focuses on helping developers detect and fix code vulnerabilities. The Wall Street Journal reported that the investment is worth $25 million.
ServiceNow's investment isn't just about the money. The company also built an integration... Read more
Researchers warn of increase in SSRF attacks on Microsoft Exchange
Bitdefender warns of an increase in cyberattacks on on-premises deployments of Microsoft Exchange Server 2013, 2016 and 2019.
The security company witnessed a recent rise in ProxyNotShell and OWASSRF, two tactics for attacks on Microsoft Exchange Server.
The tactics exploit two known vulnera... Read more
‘Most firms find hybrid work more productive, but security is lacking’
Research by Okta suggests that six in ten European companies find employees more productive when they balance working remotely and working from the office. Systems need to be secured for both internal and external staff, but Okta indicates that many organizations struggle with the necessary measure... Read more
Lansweeper acquires security startup RankedRight
Lansweeper announced the acquisition of RankedRight. The startup's software prioritizes system vulnerabilities. Lansweeper, a Belgium-based provider of monitoring solutions, wants to use the acquisition to expand its offering with security features.
RankedRight was founded in 2020. The startup ... Read more
Cybercriminals use Microsoft OneNote attachments to spread malware
Security researchers warn that cybercriminals have started using OneNote attachments in phishing emails to infect victims with remote access malware, allowing attackers to steal passwords and even cryptocurrency wallets.
The tactic isn't new, as attackers have been sending malware through malici... Read more
Cybercriminal steals data of 37 million T-Mobile customers
The US branch of T-Mobile has been hit by a cyberattack. The personal data of 37 million customers was stolen.
According to an official statement, a cybercriminal managed to break into T-Mobile's systems via an API. In August 2021, a prior incident leaked the data of 48 million customers.
Th... Read more