Capita Confirms Data Breach After Ransomware Group Offers to Sell Stolen Information

Capita finally confirmed that hackers stole data after the Black Basta ransomware group offered to sell information allegedly stolen from the company.
The post Capita Confirms Data Breach After Ransomware Group Offers to Sell Stolen Information appeare… Continue reading Capita Confirms Data Breach After Ransomware Group Offers to Sell Stolen Information

Cascading Supply Chain Attack: 3CX Hacked After Employee Downloaded Trojanized App

3CX hack is the first known cascading supply chain attack, with the breach starting after an employee downloaded compromised software from a different firm.
The post Cascading Supply Chain Attack: 3CX Hacked After Employee Downloaded Trojanized App app… Continue reading Cascading Supply Chain Attack: 3CX Hacked After Employee Downloaded Trojanized App

Fortra Completes Investigation Into GoAnywhere Zero-Day Incident

Fortra has shared a summary of its investigation into the GoAnywhere zero-day incident that hit dozens of the company’s customers earlier this year.
The post Fortra Completes Investigation Into GoAnywhere Zero-Day Incident appeared first on SecurityWe… Continue reading Fortra Completes Investigation Into GoAnywhere Zero-Day Incident

US, UK: Russia Exploiting Old Vulnerability to Hack Cisco Routers

US and UK government agencies have issued a joint warning for Russian group APT28 targeting Cisco routers by exploiting an old vulnerability.
The post US, UK: Russia Exploiting Old Vulnerability to Hack Cisco Routers appeared first on SecurityWeek.
Continue reading US, UK: Russia Exploiting Old Vulnerability to Hack Cisco Routers

NSO Group Used at Least 3 iOS Zero-Click Exploits in 2022: Citizen Lab

NSO Group used at least three iOS zero-click exploits in Pegasus attacks in 2022: FindMyPwn, PwnYourHome, and LatentImage.
The post NSO Group Used at Least 3 iOS Zero-Click Exploits in 2022: Citizen Lab appeared first on SecurityWeek.
Continue reading NSO Group Used at Least 3 iOS Zero-Click Exploits in 2022: Citizen Lab

CISA Adds Chrome, macOS Bugs to Known Exploited Vulnerabilities Catalog

CISA has added two vulnerabilities to its ‘must patch’ list, including a recently fixed Chrome flaw and a macOS flaw exploited by the DazzleSpy malware.
The post CISA Adds Chrome, macOS Bugs to Known Exploited Vulnerabilities Catalog appeared first on … Continue reading CISA Adds Chrome, macOS Bugs to Known Exploited Vulnerabilities Catalog