
The U.S. National Security Agency is warning that Chinese government-backed hackers are exploiting a zero-day vulnerability in two widely used Citrix networking products to gain access to targeted networks.
"We are aware of a small number of targeted attacks in the wild using this vulnerability," Peter Lefkowitz, chief security and trust officer at Citrix, said in a blog post . "Limited exploits of this vulnerability have been reported.
Hackers Score Nearly $1M at Device-Focused Pwn2Own Contest

Security researchers and hackers demonstrated 63 zero-day vulnerabilities in popular devices at the latest Pwn2Own, exploiting printers from Canon, HP, and Lexmark, and routers and network-attached storage device from Synology and Netgear.
The Samsung exploit highlighted that significant vulnerabilities are out there to find, says Dustin Child, head of threat awareness at Trend Micro's Zero Day Initiative.
Hackers Actively Exploiting Citrix ADC and Gateway Zero-Day Vulnerability

The U.S. National Security Agency (NSA) on Tuesday said a threat actor tracked as APT5 has been actively exploiting a zero-day flaw in Citrix Application Delivery Controller (ADC) and Gateway to take over affected systems.
The critical remote code execution vulnerability, identified as CVE-2022-27518 , could allow an unauthenticated attacker to execute commands remotely on vulnerable devices and seize control.
Ethical hackers flex their muscles in 2022 | TechTarget

Ethical hackers working through HackerOne programmes discovered more than 65,000 software vulnerabilities in 2022 – 21% up on 2021 – and over 120,000 customer vulnerabilities, with reports for vulnerability types introduced by digital transformation projects skyrocketing as misconfiguration ...
Chinese Hackers Believed To Be Behind Security Breach at Amnesty International - CPO Magazine

Canada’s branch of Amnesty International is reporting that an early October security breach of the organization’s IT infrastructure has been traced back to state-sponsored Chinese hackers after an investigation by a third party forensics firm.
The organization was hacked on October 5 and engaged cybersecurity firm Secureworks to audit and do forensics work after the fact, with the ultimate conclusion being that state-sponsored Chinese hackers penetrated the system for espionage purposes.
MML# 4 – Hackers Hitting Clarkston in 2018 Serves as Training Example for Other Cities - Oakland ...

Clarkston, MI – Back in Sept 2018, the City of the Village of Clarkston got hacked. Their computer system was frozen by a malware program and held hostage until a ransom was paid. That very stressful day is one that City Manager Jonathan Smith will never forget.
Clarkson is a small community – just a half a mile square with 420 homes, a municipal operating budget of $900,000, and a team of just five employees. "For years we used a local IT person," he said. "We're a small community with a small, limited budget."
HR platform Sequoia says hackers accessed customer SSNs and COVID-19 data • TechCrunch

Benefits and payroll management company Sequoia says hackers accessed sensitive customer information, including their Social Security numbers and COVID-19 test results.
According to Wired, which first broke the news of Sequoia’s breach last week, the incident impacted customers of Sequoia One, a professional employer organization (or PEO) that provides outsourced human resources and payroll services. The service is popular with U.S.
When Companies Compensate the Hackers, We All Foot the Bill

Companies are always absorbing costs that are seen as par for the course of budget planning: maintenance, upgrades, office supplies, wastage, shrinkage, etc. These costs ratchet up the price of a company's products and are then passed on to the consumer.
If a company estimates the recovery costs from a ransomware attack to exceed the requested payment from the hacker, then it feels like a no-brainer — they're better off just cutting their losses and giving in to the cybercriminal's demands.
Hackers copied Mango Markets attacker's methods to exploit Lodestar — CertiK

Blockchain security company CertiK has shared a post-mortem analysis of the $5.8 million Lodestar Finance exploit that occurred on Dec. 10:
5. The hacker burned a little over 3 million in GLP, their profit on this exploit was the stolen funds on Lodestar - minus the GLP they burned.
6. 2.8 Million of the GLP is recoverable, which is worth about $2.4 million. We are going to reach out to the hacker and...
NSA says Chinese hackers are exploiting a zero-day bug in widely used Citrix networking gear https://t.co/aOc7KhVb67 by @carlypage_ TechCrunch (from San Francisco, CA) Wed Dec 14 14:22:24 +0000 2022
A Concert Like No Other
Hop aboard a shuttle to Kepler-1649c. Be there to welcome new lifeforms into the universe. All passengers must have a verified event ticket. There are 10,000 tickets in circulation so no need to panic. Limited seating available per trip. There will be multiple flights each hour shipping off from the NORAD Space Port in Iceland.
Event tickets are non refundable & non transferable (except on the black market. Call Sal with questions.) An event ticket can be reused for up to 9900 yearly transactions.
No sandals allowed on flight. Adults only. Kittens must show a custodian's ID at the gate. You are not allowed to get married while aboard the shuttle. Please arrive early if you are wearing jeans.
NB: EVENT TICKETS CONTAIN A PRIVATE ANONYMOUS DIGITAL IMPRINT.
Reserve your spot. Click here.

No comments:
Post a Comment