Five nations issue global alert on vulnerabilities in Accellion FTA application

Five nations issue global alert on vulnerabilities in Accellion FTA application

Cybersecurity agencies across five countries have issued a global alert to organizations using the Accellion FTA file transfer application after a number of organizations in the past six weeks admitted to being hacked through vulnerabilities in the software. Organizations should temporarily isolate or block internet access to and from systems hosting Accellion FTA, says the…

Nasa: ‘Why we hid a message in the Perseverance parachute’

Nasa: ‘Why we hid a message in the Perseverance parachute’

After a journey of about seven months Nasa’s Perseverance rover landed on Mars last Thursday. Designed to look for signs of past microbial life, the rover has been sending back stunning images of the Red planet. But those who watched the rover’s descent onto the Martian surface may have spotted a coded message on the…

Lazarus Hits Defense Firms with ThreatNeedle Malware

Lazarus Hits Defense Firms with ThreatNeedle Malware

Critical Infrastructure Security , Cybercrime as-a-service , Cyberwarfare / Nation-State Attacks Kaspersky Ties Latest Hacking Campaign and Backdoor to Lazarus Group Doug Olenick (DougOlenick) • February 25, 2021     Lazarus, the North Korean-backed advanced persistent threat group, has been conducting a campaign striking defense industry targets in more than a dozen countries using a…

North Korean hackers target defense industry with custom malware

North Korean hackers target defense industry with custom malware

A North Korean-backed hacking group has targeted the defense industry with custom backdoor malware dubbed ThreatNeedle since early 2020 with the end goal of collecting highly sensitive information. This espionage campaign affected organizations from more than a dozen countries and was coordinated by DPRK-backed state hackers tracked as Lazarus Group. The attackers used COVID19-themed spear-phishing…

6,000 VMware vCenter Devices Vulnerable to Remote Attacks

6,000 VMware vCenter Devices Vulnerable to Remote Attacks

Governance & Risk Management , IT Risk Management , Patch Management Flaw Allows Unauthorized Users to Send Specially Crafted Requests Prajeet Nair (@prajeetspeaks) • February 25, 2021     Security firm Positive Technologies says more than 6,000 VMware vCenter devices worldwide that are accessible via the internet contain a critical remote code execution vulnerability. VMware…