BOD 23-01: Improving asset visibility and vulnerability detection on federal networks

Categories: News

Tags: BOD 23-01

Tags: asset visibility

Tags: vulnerability detection

Tags: federal networks

Tags: CISA

Tags: CDM

Tags:

CISA has issued BOD 23-10 which requires all FCEB entities to maintain an inventory of all IPv4- and IPv6-networked assets, perform regular, periodic scans of these devices, and provide this information to CISA.

(Read more…)

The post BOD 23-01: Improving asset visibility and vulnerability detection on federal networks appeared first on Malwarebytes Labs.

Read more

Admin from hell facing 10 years for sabotaging ex-employer’s network

Categories: News

Tags: hire

Tags: hiring

Tags: rehire

Tags: insider threat

Tags: ex-employee

Tags: logins

Tags: network

Tags: FBI

Failing to keep a tight reign on ex-employees’ credentials can lead to all manner of chaos.

(Read more…)

The post Admin from hell facing 10 years for sabotaging ex-employer’s network appeared first on Malwarebytes Labs.

Read more

Bogus job offers hide trojanised open-source software

Categories: News

Tags: malware

Tags: ZINC

Tags: microsoft

Tags: infection

Tags: C&C

Tags: open source

Tags: job offer

Tags: fake

Tags: LinkedIn

A North Korean ZINC group is accused of creating compromised versions of KiTTY, PuTTY, TightVNC, and other popular open-source software apps

(Read more…)

The post Bogus job offers hide trojanised open-source software appeared first on Malwarebytes Labs.

Read more

Ransomware-affected school district refuses to pay, gets stolen data released

Categories: News

Tags: compromise

Tags: ransomware

Tags: leak

Tags: extortion

Tags: LAUSD

Data stolen from Los Angeles Unified School District has been leaked online, after staff refused to pay the ransom related to a ransomware attack.

(Read more…)

The post Ransomware-affected school district refuses to pay, gets stolen data released appeared first on Malwarebytes Labs.

Read more

[updated]Two new Exchange Server zero-days in the wild

Categories: Exploits and vulnerabilities

Categories: News

Tags: Exchange

Tags: ProxyShell

Tags: remote PowerShell

Tags: web shell

Tags: CVE-2022-41040

Tags: CVE-2022-41082

Tags: SSRF

Tags: RCE

Two ProxyShell-like vulnerabilities are being used to exploit Microsoft Exchange Servers

(Read more…)

The post [updated]Two new Exchange Server zero-days in the wild appeared first on Malwarebytes Labs.

Read more

Actively exploited vulnerability in Bitbucket Server and Data Center

Categories: Exploits and vulnerabilities

Categories: News

Tags: Atlassian

Tags: Bitbucket

Tags: git

Tags: CVE-2022-36804

Tags: RCE

Tags: read permission

International cybersecurity authorities are warning about the active exploitation of a vulnerability in Bitbucket Server and Data Center

(Read more…)

The post Actively exploited vulnerability in Bitbucket Server and Data Center appeared first on Malwarebytes Labs.

Read more

Romance scammer deepfakes Mark Ruffalo to con elderly artist

Categories: News

Tags: romance scam

Tags: deepfake

Tags: mark ruffalo

Tags: manga

Tags: theft

Tags: online

Tags: social media

We take a look at a romance scammer getting ahead of the game and using deepfakes to steal a huge amount of money from a victim.

(Read more…)

The post Romance scammer deepfakes Mark Ruffalo to con elderly artist appeared first on Malwarebytes Labs.

Read more