Cyber Defense Advisors

Month: November 2022

  • by
  • November 11, 2022

Multiple High-Severity Flaw Affect Widely Used OpenLiteSpeed Web Server Software

Multiple high-severity flaws have been uncovered in the open source OpenLiteSpeed Web Server as well as its enterprise variant that could be weaponized to achieve remote code execution. “By chaining and exploiting the vulnerabilities, adversaries could compromise the web server and gain fully privileged remote code execution,” Palo Alto Networks Unit 42 said in a Thursday report.

Cyber News, Cyber Threat Trends

Qatar World Cup Firms Urged to Upgrade Cyber-Threat Model

Digital Shadows warns of elevated risk from scammers and threat actors

Cyber News, Cyber Threat Trends
  • by
  • November 11, 2022

Microsoft Blames Russian Hackers for Prestige Ransomware Attacks on Ukraine and Poland

Microsoft on Thursday attributed the recent spate of ransomware incidents targeting transportation and logistics sectors in Ukraine and Poland to a threat cluster that shares overlaps with the Russian state-sponsored Sandworm group. The attacks, which were disclosed by the tech giant last month, involved a strain of previously undocumented malware called Prestige and is said to have taken […]

Cyber News, Cyber Threat Trends
  • by
  • November 11, 2022

CVE-2019-8561: A Hard-to-Banish PackageKit Framework Vulnerability in macOS

This blog entry details our investigation of CVE-2019-8561, a vulnerability that exists in the macOS PackageKit framework, a component used to install software installer packages (PKG files).

Cyber News, Cyber Threat Trends
  • by
  • November 10, 2022

Lacework releases cloud-native application security service

Cloud security vendor Lacework this week announced the availability of a cloud-native application protection platform (CNAPP) for its broader Polygraph Data Platform offering, providing an agentless, low-touch option for organizations looking to improve their application security posture. There are two main components to the CNAPP release, according to Lacework, both of which require only that […]

Cyber News, Cyber Threat Trends
  • by
  • November 10, 2022

S3 Ep108: You hid THREE BILLION dollars in a popcorn tin?

Patches, busts, leaks and why even low-likelihood exploits can be high-severity risks – listen now!

Cyber News, Cyber Threat Trends
  • by
  • November 10, 2022

Lawsuit Seeks Food Benefits Stolen By Skimmers

A nonprofit organization is suing the state of Massachusetts on behalf of thousands of low-income families who were collectively robbed of more than a $1 million in food assistance benefits by card skimming devices secretly installed at cash machines and grocery store checkout lanes across the state. Federal law bars states from replacing these benefits […]

Cyber News, Cyber Threat Trends

#IRISSCON: Police Officer Urges More Reporting and Engagement to Tackle Cybercrime

Ireland’s National Cyber Crime Bureau outlines cybercrime trends being observed in law enforcement

Cyber News, Cyber Threat Trends

New Lenovo Notebook Models Affected By UEFI Firmware Vulnerabilities

The flaws affect various Lenovo Yoga, IdeaPad and ThinkBook devices

Cyber News, Cyber Threat Trends