"Xfinity Customer Data Compromised in Attack Exploiting CitrixBleed Vulnerability"

"Xfinity Customer Data Compromised in Attack Exploiting CitrixBleed Vulnerability"

Comcast’s Xfinity recently announced that customer information had been compromised in a cyberattack that involved exploitation of the vulnerability known as CitrixBleed.  CitrixBleed, officially tracked as CVE-2023-4966, is a critical vulnerability affecting Citrix’s Netscaler ADC and Gateway appliances. Malicious actors can exploit the flaw to hijack existing sessions, which can give them access to the targeted organization’s systems. Patches were announced by Citrix on October 10, but the vulnerability had been exploited as a zero-day since August.

Submitted by Adam Ekwall on

"A Computer Scientist Explains How QR Codes Work and What Makes Them Dangerous"

"A Computer Scientist Explains How QR Codes Work and What Makes Them Dangerous"

There are security risks associated with QR codes, which are graphical representations of digital data that can be printed and later scanned by a smartphone or other device. In December 2023, the Federal Trade Commission (FTC) gave another warning about the dangers of scanning a code from an unknown source. Scott Ruoti, assistant professor of computer science at the University of Tennessee, explains why visiting URLs stored in QR codes can be dangerous in various ways.

Submitted by Gregory Rigby on

"Researchers Find Zero-Victim Method to Block Scammers' Websites"

"Researchers Find Zero-Victim Method to Block Scammers' Websites"

Researchers at Palo Alto Networks' Unit 42 developed a Machine Learning (ML) model that feeds on "crumbs of information" left by malicious actors and detects tens of thousands of malicious domains each week before they are used for illegal activities. Malicious actors often register many domain names in bulk to ensure redundancy and uptime for phishing campaigns, malware distribution, adversarial Search Engine Optimization (SEO), or other illegal content. Domains are held in reserve until they are needed for specific campaigns.

Submitted by Gregory Rigby on

"Novel SMTP Smuggling Technique Slips Past DMARC, Email Protections"

"Novel SMTP Smuggling Technique Slips Past DMARC, Email Protections"

A novel way to exploit a decades-old protocol that has been used to send emails allows attackers to bypass Domain-based Message Authentication, Reporting, and Conformance (DMARC) and other email security mechanisms, putting organizations and individuals at risk for targeted phishing attacks.

Submitted by Gregory Rigby on

"Enabling Threat-Informed Cybersecurity: Evolving CISA's Approach to Cyber Threat Information Sharing"

"Enabling Threat-Informed Cybersecurity: Evolving CISA's Approach to Cyber Threat Information Sharing"

The US Cybersecurity and Infrastructure Security Agency (CISA) will launch a strategic effort to modernize its approach to enterprise cyber threat information-sharing in 2024. This effort will propel three key areas of progress: simplification, partner-centered design, and experience-based learning. CISA, for example, will refocus and consolidate its customer-facing cyber threat intelligence offerings under a new initiative called Threat Intelligence Enterprise Services (TIES) to simplify things.

Submitted by Gregory Rigby on

"CISA Urges Manufacturers Eliminate Default Passwords to Thwart Cyber Threats"

"CISA Urges Manufacturers Eliminate Default Passwords to Thwart Cyber Threats"

The US Cybersecurity and Infrastructure Security Agency (CISA) urges manufacturers to eliminate default passwords on Internet-connected systems, citing serious risks that malicious actors could exploit to gain initial access to and move laterally within organizations. In a recent alert, the agency said Iranian threat actors affiliated with the Islamic Revolutionary Guard Corps (IRGC) have gained access to critical infrastructure systems in the US by exploiting Operational Technology (OT) devices with default passwords.

Submitted by Gregory Rigby on

"Mortgage Giant Mr. Cooper Data Breach Affects 14.7 Million People"

"Mortgage Giant Mr. Cooper Data Breach Affects 14.7 Million People"

Mr. Cooper is sending data breach notifications warning that a recent cyberattack has exposed the data of 14.7 million customers who have, or previously had, mortgages with the company.  Mr. Cooper is a Dallas-based mortgage lending firm that employs approximately 9,000 people and has millions of customers.  The lender is one of the largest servicers in the United States, servicing loans of $937 billion.  In early November 2023, the company announced that it had been breached in a cyberattack on October 30, 2023, which it discovered the following day.

Submitted by Adam Ekwall on

"Air France-KLM Data Leak Left Customer Information Vulnerable to Scrapers"

"Air France-KLM Data Leak Left Customer Information Vulnerable to Scrapers"

According to the Dutch public news organization NOS, together with security researcher Benjamin Broersma, some of the private data belonging to KLM and Air France passengers was easy to obtain. Hyperlinks to flight information were not long or varied enough, enabling large-scale data collection from other customers. NOS and Broersma tested whether private data could be obtained by modifying a hyperlink sent by KLM via text message. Anyone who wanted to receive flight information from KLM via text message was given a six-character link.

Submitted by Gregory Rigby on

"InfectedSlurs Botnet Targets QNAP VioStor NVR Vulnerability"

"InfectedSlurs Botnet Targets QNAP VioStor NVR Vulnerability"

InfectedSlurs, a Mirai-based botnet, was discovered targeting QNAP VioStor Network Video Recorder (NVR) devices. Akamai released a warning in November about a new Mirai-based Distributed Denial-of-Service (DDoS) botnet called InfectedSlurs, which was actively exploiting two zero-day vulnerabilities to infect routers and NVR devices. The botnet was discovered in October 2023, but the researchers believe it has been active since at least 2022. The experts notified the vendors of the two vulnerabilities, but they plan to release fixes in December 2023.

Submitted by Gregory Rigby on

"VF Corp Disrupted by Cyberattack, Online Operations Impacted"

"VF Corp Disrupted by Cyberattack, Online Operations Impacted"

VF Corporation, a company that owns and operates some of the biggest apparel and footwear brands, has recently been hit by a ransomware attack that included the theft of sensitive corporate and personal data.  VF Corp said the hackers disrupted business operations, including its ability to fulfill e-commerce orders, and hijacked data from the company, including personal data.  The company did not provide additional details on the stolen data or whether third-party customer data was exposed.

Submitted by Adam Ekwall on
Subscribe to