Tag: Cyber Attack news

Exploits released for Linux flaw giving root on major distros
News

Exploits released for Linux flaw giving root on major distros

On the majority of Linux distributions, proof-of-concept attacks for a high-severity vulnerability in the dynamic loader of the GNU C Library have previously been made public online. This security flaw, dubbed "Looney Tunables," is listed as CVE-2023-4911 and affects Fedora 37 and 38, Ubuntu 22.04 and 23.04, and Debian 12 and 13. It is caused by a buffer overflow problem. Attackers can use it to start programs with SUID permission and get root privileges by exploiting the GLIBC_TUNABLES environment variable that is processed by the ld.so dynamic loader. Several security researchers have already released proof-of-concept (PoC) exploit code that is functional for various system configurations since Qualys read more Exploits released for Linux flaw giving root on major distros. ...
Norway government ministries hit by cyber attack
News

Norway government ministries hit by cyber attack

The Norwegian government announced on Monday that 12 government ministries had been the target of a cyberattack, the most recent to target the public sector of Europe's largest gas supplier and NATO's northernmost member. "We discovered a flaw in one of our vendors' platform. Erik Hope, the head of the government organisation in charge of providing services to ministries, announced during a press conference that this weakness has now been closed. The supplier's platform's "unusual" traffic led to the identification of the assault, according to Hope, who declined to disclose more details. It was discovered on July 12 and the police were looking into it read more Norway government ministries hit by cyber attack.
U.S. Government Agencies Emails Compromised in China Backed Cyber Attack
News

U.S. Government Agencies Emails Compromised in China Backed Cyber Attack

Midway through June 2023, an unnamed Federal Civilian Executive Branch (FCEB) organization in the U.S. saw unusual email activity, which led Microsoft to learn about a fresh espionage operation related to China that was targeting two dozen organizations. The information comes from a joint cybersecurity advice issued by the Federal Bureau of Investigation (FBI) and the U.S. Cybersecurity and Infrastructure Security Agency (CISA) on July 12, 2023. In its Microsoft 365 (M365) cloud environment, a Federal Civilian Executive Branch (FCEB) agency "identified suspicious activity in June 2023," according to the authorities. Advanced persistent threat (APT) attackers accessed and stole unclassified Exchange Online Outlook data read more U.S. Government Agencies Emails Compromised in China Ba...