Not ‘Above the Law’ – Feds Target ICO Cryptocurrency Scams

Not ‘Above the Law’ – Feds Target ICO Cryptocurrency Scams

Cryptocurrency Fraud , Fraud Management & Cybercrime , Legislation & Litigation $70 Million Allegedly Lost to Schemes Such as Bitcoiin2Gen Touted by Steven Seagal Mathew J. Schwartz (euroinfosec) • February 25, 2021     Bitcoiin2Gen in 2018 said “Zen Master Steven Seagal” had become its “brand ambassador.” If there’s anything to put the final nail…

Critical VMware vCenter Server Flaw Can Expose Organizations to Remote Attacks

Critical VMware vCenter Server Flaw Can Expose Organizations to Remote Attacks

Critical VMware vCenter Server Flaw Can Expose Organizations to Remote Attacks | IT Security News 24. February 2021 VMware on Tuesday informed customers that its vCenter Server product is affected by a critical vulnerability that can be exploited by an attacker to execute commands with elevated privileges. read more Like this: Like Loading… Related Tags:…

Myanmar coup: Rudd backs Asean talks with the military

Myanmar coup: Rudd backs Asean talks with the military

The former Australian prime minister Kevin Rudd has backed talks between Myanmar’s military and Indonesia’s foreign minister Retno Marsudi. The meeting agreed by the Association of Southeast Asian Nations (Asean) was criticised by some in Myanmar, also known as Burma, because it was seen to give legitimacy to the military regime. But Mr Rudd told…

Gavi: ‘Safety not squeezed in Covid vaccine development’

Gavi: ‘Safety not squeezed in Covid vaccine development’

The timeline for developing coronavirus vaccines has been rapid, but safety was never compromised the head of the Global Vaccine Alliance (Gavi) has said. Speaking to BBC Hardtalk Dr Seth Berkley described the progress as “extraordinary”, explaining that he thought the development of Covid vaccines would take around 18 months to two years. “We squeezed…

Heimdal Security Blog | Accellion Data Breach Show Ties to Clop Ransomware and FIN11

Heimdal Security Blog | Accellion Data Breach Show Ties to Clop Ransomware and FIN11

On Monday, cybersecurity researchers connected a series of attacks targeting Accellion File Transfer Appliance (FTA) servers over the past two months to a data breach and extortion campaign orchestrated by the UNC2546 cybercrime group. Threat actors targeted up to 100 companies using Accellion’s FTA and stole sensitive files by combining multiple zero-day vulnerabilities and a…

Federal Reserve’s Money Transfer Services Suffer Outage

Federal Reserve’s Money Transfer Services Suffer Outage

Business Continuity Management / Disaster Recovery , Critical Infrastructure Security , Finance & Banking Operational Error Blamed for Nationwide System Crash Doug Olenick (DougOlenick) • February 24, 2021     The Federal Reserve’s online money transfer system, including Fedwire Funds and Fedcash, suffered an outage for more than three hours Wednesday afternoon, citing technical issues…

Senators Grill Cybersecurity Execs on SolarWinds Attack

Senators Grill Cybersecurity Execs on SolarWinds Attack

3rd Party Risk Management , Breach Notification , Critical Infrastructure Security FireEye, Microsoft, CrowdStrike Offer New Details and Recommendations Doug Olenick (DougOlenick) • February 23, 2021     (From the left) Microsoft President Brad Smith, SolarWinds CEO Sudhakar Ramakrishna and FireEye CEO Kevin Mandia The CEOs of SolarWinds, Microsoft, FireEye and CrowdStrike rolled out a…

Senate SolarWinds Hearing: 4 Key Issues Raised

Senate SolarWinds Hearing: 4 Key Issues Raised

Cyberwarfare / Nation-State Attacks , Forensics , Fraud Management & Cybercrime Issues Include Attackers’ Use of Amazon’s Infrastructure Scott Ferguson (Ferguson_Writes) • February 24, 2021     (Source: Jarek Tuszyński via Wikipedia) The Senate Intelligence Committee’s hearing Tuesday about the supply chain attack that affected SolarWinds and dozens of other companies and federal agencies answered…

CVE-2021-21973

CVE-2021-21973

The vSphere Client (HTML5) contains an SSRF (Server Side Request Forgery) vulnerability due to improper validation of URLs in a vCenter Server plugin. A malicious actor with network access to port 443 may exploit this issue by sending a POST request to vCenter Server plugin leading to information disclosure.