CVE-2021-27461
A vulnerability has been found in multiple revisions of Emerson Rosemount X-STREAM Gas Analyzer. The affected webserver applications allow access to stored data that can be obtained by using specially crafted URLs.
3rd Party Risk Management , Breach Notification , Critical Infrastructure Security Microsoft, FireEye Find Additional Payloads Used During Supply Chain Attack Scott Ferguson (Ferguson_Writes) • March 4, 2021 Researchers with Microsoft and FireEye are disclosing additional malware used by the hacking group that targeted SolarWinds in December 2020, according to a pair of…
Governance & Risk Management , Incident & Breach Response , Legislation & Litigation Judge Says Users Agreed With Arbitration When Accepting Terms and Conditions Mathew J. Schwartz (euroinfosec) • August 3, 2021 Zynga develops mobile games such as Words With Friends 2 (Photo: Zynga) Yet another lawsuit filed in the wake of a…
Critical Infrastructure Security , Cybercrime , Cybercrime as-a-service Report: Cooperation Is Required to Protect US Critical Infrastructure Scott Ferguson (Ferguson_Writes) • July 16, 2021 The Pentagon (Photo: Political Office via Flickr/CC) A greater level of cooperation is needed between the Department of Defense and the Department of Homeland Security to ensure that U.S….
The malware can also intercept text messages regardless of the fact that SMS-based two-factor authentication may be in use. A Trojan malware dubbed “BlackRock” is disguising as an Android version of the invite-only audio chat app called Clubhouse. It is worth noting that the app has no Android version at this moment. The cybersecurity researchers…
Critical Infrastructure Security , Cybercrime , Cybercrime as-a-service Costs So Far Total Nearly $113 Million, Including $91.6 Million in Lost Revenue Marianne Kolbasuk McGee (HealthInfoSec) • August 13, 2021 Scripps Health reports that a recent ransomware incident has already cost the entity nearly $113 million The recent ransomware attack that disrupted Scripps Health’s…
Fraud Management & Cybercrime , Fraud Risk Management Financial Institutions Support Initiative to Target Cybercrime Prajeet Nair (@prajeetspeaks) • June 21, 2021 The Indian government has set up the Citizen Financial Cyber Fraud Reporting and Management System to report, track – and ultimately freeze – the proceeds of cyberattack-induced financial theft. See Also:…