More MOVEit vulnerabilities found while the first one still resonates

Categories: Exploits and vulnerabilities

Categories: News

Categories: Ransomware

Tags: MOVEit

Tags: Progress

Tags: Cl0p

Tags: ransomware

Tags: CVE-2023-34362

A security audit of the MOVEit code has revealed more SQL injection vulnerabilities, while victims of the first vulnerability are coming to the surface.

(Read more…)

The post More MOVEit vulnerabilities found while the first one still resonates appeared first on Malwarebytes Labs.

Read more

Former TikTok exec: Chinese Communist Party had “God mode” entry to US data

Categories: News

Categories: Privacy

Tags: Yu

Tags: TikTok

Tags: ByteDance

Tags: CCP

Tags: influence

Tags: data access

Tags: loaded gun

A former executive at TikTok’s parent company ByteDance has claimed in court documents that the Chinese Community Party (CCP) had access to TikTok data, despite the data being stored in the US.

(Read more…)

The post Former TikTok exec: Chinese Communist Party had “God mode” entry to US data appeared first on Malwarebytes Labs.

Read more

Update your Cisco System Secure Client now to fix this AnyConnect bug

Categories: Exploits and vulnerabilities

Categories: News

Tags: Cisco

Tags: anyconnect

Tags: system secure client

Tags: VPN

Tags: bug

Tags: patch

Tags: update

Tags: vulnerability

Tags: SYSTEM

We take a look at a recent update for Cisco Secure System Client and why you should apply the update as soon as possible.

(Read more…)

The post Update your Cisco System Secure Client now to fix this AnyConnect bug appeared first on Malwarebytes Labs.

Read more

VMware patches critical vulnerabilities in Aria Operations for Networks

Categories: Exploits and vulnerabilities

Categories: News

Tags: cve-2023-20887

Tags: cve-2023-20888

Tags: cve-2023-20889

Tags: vmware

Tags: Aria Operations for Networks

Tags: RCE

Tags: information disclosure

Tags: deserialization

Tags: command injection

VMware has released security updates to fix a trio of flaws in Aria Operations for Networks that could result in information disclosure and remote code execution

(Read more…)

The post VMware patches critical vulnerabilities in Aria Operations for Networks appeared first on Malwarebytes Labs.

Read more

Update Chrome now! Google patches actively exploited zero-day

Categories: Exploits and vulnerabilities

Categories: News

Tags: Google

Tags: Chrome

Tags: V8

Tags: heap corruption

Tags: type confusion

Tags: CVE-2023-3079

Google has released a Chrome update for a zero-day for which an exploit is actively being used in the wild.

(Read more…)

The post Update Chrome now! Google patches actively exploited zero-day appeared first on Malwarebytes Labs.

Read more

Cl0p ransomware gang claims first victims of the MOVEit vulnerability

Categories: Exploits and vulnerabilities

Categories: News

Categories: Ransomware

Tags: Progress

Tags: MOVEit

Tags: Transfer

Tags: CVE-2023-34362

Tags: BBC

Tags: Zellis

Tags: BA

The first victims of the ongoing attacks on vulnerable MOVEit Transfer instances are coming forward. The Cl0p ransomware gang claims it is behind the attacks.

(Read more…)

The post Cl0p ransomware gang claims first victims of the MOVEit vulnerability appeared first on Malwarebytes Labs.

Read more

Vice Society: The #1 cyberthreat to schools, colleges, and universities

Categories: News

Categories: Ransomware

In the last 12 months, the Vice Society ransomware gang has conducted more known attacks against education targets globally, and in the USA and the UK individually, than any other ransomware group.

(Read more…)

The post Vice Society: The #1 cyberthreat to schools, colleges, and universities appeared first on Malwarebytes Labs.

Read more