Claroty discovers severe flaw in Siemens PLCs

Claroty discovers severe flaw in Siemens PLCs

Industrial cybersecurity company Claroty has discovered a severe memory protection bypass vulnerability in Siemens programmable logic controllers (PLC) that could enable attackers to remain undetected while running code of their choice. Claroty has been able to achieve native code execution on the Siemens SIMATIC S7-1200 and S7-1500 PLC CPUs by bypassing the PLC sandbox within…

US Govt sets aside US$750m for SolarWinds response – Security

US Govt sets aside US$750m for SolarWinds response – Security

US President Joe Biden’s proposed budget includes US$750 million for the government agencies hit by the SolarWinds hack to pay for cybersecurity improvements to prevent another attack. The money comes on top of a US$500 million fund for federal cybersecurity as the U.S. government recovers from the cyber attack that hit nine agencies including the…

Hackers Exploited Fortinet Bugs to Gain Access of a U.S. Gov Servers

Hackers Exploited Fortinet Bugs to Gain Access of a U.S. Gov Servers

Recently, APT group or the state-sponsored hackers have exploited the vulnerabilities in an unpatched Fortinet VPN to compromise the webserver of a U.S. municipal government web server, as reported by the FBI (Federal Bureau of Investigation). The APT (Advanced Persistent Threat) hackers created new servers, domain controllers, and workstation user accounts just after gaining access…

Researchers Demonstrate 2 New Hacks to Modify Certified PDF Documents

Researchers Demonstrate 2 New Hacks to Modify Certified PDF Documents

Researchers Demonstrate 2 New Hacks to Modify Certified PDF Documents | IT Security News 29. May 2021 This article has been indexed from The Hacker News Cybersecurity researchers have disclosed two new attack techniques on certified PDF documents that could potentially enable an attacker to alter a document’s visible content by displaying malicious content over…

Europe demands answers after US-Danish spying claims

Europe demands answers after US-Danish spying claims

German Chancellor Angela Merkel is one of the top politicians reportedly spied on by the US. (AP pic) PARIS: France, Germany and other European countries demanded answers Monday following reports the US spied on its allies using Danish underwater cables, as questions mounted over whether Denmark knew about the operation. In an investigative report on Sunday,…

US Spied on Top European Politicians, Danish Intelligence Helped

US Spied on Top European Politicians, Danish Intelligence Helped

The US spied on top politicians in Europe, including German Chancellor Angela Merkel, from 2012 to 2014 with the help of Danish intelligence, AFP reported, quoting Danish and European media on Sunday. Danish public broadcaster Danmarks Radio (DR) said the US National Security Agency (NSA) had eavesdropped on Danish internet cables to spy on top…

Cyber attack shuts down global meat processing giant JBS

Cyber attack shuts down global meat processing giant JBS

The world’s largest meat processing company, JBS Foods, has fallen victim to cyber attacks that have shut down production around the world, including in Australia. Key points: The federal government confirms it is aware of the hack and is working to get JBS back online Industry experts say domestic market forces will adapt if JBS is offline long-term A union spokesperson…

Interpol Thwarts Online Fraud Intercepting $83 Million Illicit Funds in the Asia-Pacific Region – HOTforSecurity

Interpol Thwarts Online Fraud Intercepting $83 Million Illicit Funds in the Asia-Pacific Region – HOTforSecurity

Amid increasing cyber-enabled financial crimes, Interpol announced its latest successful operation, which intercepted a whopping $83 million in illicit funds. According to a press release, law enforcement agencies in the Asia Pacific region opened more than 1,400 investigations between September 2020 and March 2021 Over six months, the Interpol-coordinated operation, codenamed HAECHI-I l, led to…

SonicWall Patches Command Injection Flaw in Firewall Management Application

SonicWall Patches Command Injection Flaw in Firewall Management Application

SonicWall last week announced the availability of patches for a severe vulnerability in its Network Security Manager (NSM) product. NSM is a firewall management application that provides the ability to monitor and manage all network security services from a single interface, as well as to automate tasks to improve security operations. SonicWall’s platform is available…