MITRE discloses security breach via Ivanti zero-days
The organization said that an unnamed foreign state-sponsored threat actor was behind the attack.
The organization said that an unnamed foreign state-sponsored threat actor was behind the attack.
The flaw is being exploited in attacks targeting CrushFTP servers at multiple US entities.
CERT-UA said it confirmed the compromise of at least three supply chains.
In brief: the LabHost PhaaS platform shut down, Russian military hackers attacked critical infrastructure in the US and Europe, and more.
The threat actor employs a range of software in their malicious activities, including both commercial programs and open-source tools.
This marks the first time Russian nation-state hackers have posed a direct threat to critical infrastructure in Western countries.
The investigation found over 40 000 phishing domains linked to LabHost, which had some 10 000 users worldwide.
The attackers attempted to introduce suspicious updates or asked to be made maintainers of the targeted software.
Cybersecurity researchers have observed a surge in attacks targeting CVE-2023-1389.
The consequences of a successful attack can range from unauthorized network access and account lockouts to denial-of-service conditions.
Showing elements 1471 - 1480