FBI confirms Barracuda patch is not effective for exploited ESG appliances

Categories: Exploits and vulnerabilities

Categories: News

Tags: Barracuda ESG

Tags: CVE-2023-2868

Tags: SEASPY

Tags: SUBMARINE

Tags: WHIRLPOOL

The FBI repeats the warning by Barracuda that all ESG appliances should immediately be replaced because the patch was ineffective.

(Read more…)

The post FBI confirms Barracuda patch is not effective for exploited ESG appliances appeared first on Malwarebytes Labs.

Read more

Cisco VPNs without MFA are under attack by ransomware operator

Categories: Business

Categories: News

Tags: Cisco

Tags: VPN

Tags: Akira

Tags: ransomware

Tags: brute-force

Tags: credential stuffing

Tags: password spraying

Several researchers are seeing ransomware attacks targetting Cisco VPNs without MFA

(Read more…)

The post Cisco VPNs without MFA are under attack by ransomware operator appeared first on Malwarebytes Labs.

Read more

[updated] Ivanti Sentry critical vulnerability—don’t play dice, patch

Categories: Exploits and vulnerabilities

Categories: News

Tags: Ivanti

Tags: Sentry

Tags: MobileIron

Tags: CVE-2023-38035

Tags: MICS

Tags: port 8443

There is some uncertainty about whether a vulnerability in Ivanti Sentry is being exploited in the wild, but why take the risk when you can patch?

(Read more…)

The post [updated] Ivanti Sentry critical vulnerability—don’t play dice, patch appeared first on Malwarebytes Labs.

Read more

Ivanti Sentry critical vulnerability—don’t play dice, patch

Categories: Exploits and vulnerabilities

Categories: News

Tags: Ivanti

Tags: Sentry

Tags: MobileIron

Tags: CVE-2023-38035

Tags: MICS

Tags: port 8443

There is some uncertainty about whether a vulnerability in Ivanti Sentry is being exploited in the wild, but why take the risk when you can patch?

(Read more…)

The post Ivanti Sentry critical vulnerability—don’t play dice, patch appeared first on Malwarebytes Labs.

Read more

Adobe ColdFusion vulnerability exploited in the wild

Categories: Exploits and vulnerabilities

Categories: News

Tags: Adobe

Tags: ColdFusion

Tags: CVE-2023-26359

Tags: CVE-2023-26360

Tags: critical

Tags: known exploited

Tags: deserialization

A second Adobe ColdFusion vulnerability that was patched in April has been added to CISA’s known exploited vulnerabilities catalog.

(Read more…)

The post Adobe ColdFusion vulnerability exploited in the wild appeared first on Malwarebytes Labs.

Read more

Update now! WinRAR files can be abused to run malware

Categories: Exploits and vulnerabilities

Categories: News

Tags: WinRAR

Tags: CVE-2023-40477

Tags: RCE

Tags: Windows 11

A new version of WinRAR is available that patches two vulnerabilities attackers could use for remote code execution.

(Read more…)

The post Update now! WinRAR files can be abused to run malware appeared first on Malwarebytes Labs.

Read more

QR codes used to phish for Microsoft credentials

Categories: News

Tags: QR codes

Tags: attachment

Tags: phishing

Tags: Bing

Tags: Microsoft

Tags: credentials

Researchers have been monitoring a phishing campaign that uses QR codes and Bing redirects to lead targets to phishing sites.

(Read more…)

The post QR codes used to phish for Microsoft credentials appeared first on Malwarebytes Labs.

Read more