Skip to content

Category: Beveiligingsnieuws

FortiSIEM Basic XSS: What to Know

FortiSIEM is affected by a Basic XSS vulnerability related to improper neutralization of script-related HTML tags. In certain cases, a privileged administrator could execute unauthorized commands.

FortiOS buffer over-read vulnerability: what to do

FortiGuard Labs disclosed a FortiOS buffer over-read issue affecting FortiOS, FortiProxy, and FortiSASE. Authenticated attackers may obtain a portion of device memory via a crafted redirect request.

Analog Devices Data Breach: What’s Known

Analog Devices reports an unauthorized party accessed some systems and exfiltrated files. The company says it hasn’t found evidence of stolen data being leaked or impacting operations.

Focus Keyphrase: Vishing via Microsoft Teams

Attackers used vishing via Microsoft Teams to impersonate IT support staff, trick employees into granting remote access, and then deploy Chaos ransomware. Sophos observed fast intrusions, sometimes within 17 hours.

ShinyHunters Brinks Home Breach Claims: What We Know

Brinks Home says it detected an intrusion in late July and launched an incident response. Meanwhile, ShinyHunters claims it stole millions of Salesforce and support-chat records and threatens to leak them.

Amazon Links NPM Supply-Chain Attacks

Amazon connected several high-profile NPM supply-chain attacks to North Korean hackers. The report also describes how malicious updates spread and why detection is getting harder.

Anti Phishing Shield: 2M phishing attempts blocked

The Anti Phishing Shield pilot blocked more than two million attempts to access phishing and fraudulent sites. Over 200,000 users opted in to the protection via participating internet providers.