MikroTik RouterOS has a critical vulnerability (CVE-2026-14227) that allows attackers to extract the router's WireGuard private key using low-privilege API access. This could enable them to impersonate the VPN and decrypt all associated traffic. The flaw affects all versions of MikroTik RouterOS where the API is enabled, posing a significant risk to users globally. The issue arises from an insufficient session expiration, which means users may retain access even after their permissions have been downgraded. MikroTik advises that administrators log out affected users to enforce new permission policies effectively.
Articles tagged "Phishing"
Found 415 articles
A vulnerability has been identified in Watchfire Controller Software that could allow attackers to deliver malicious firmware and gain full control of affected devices. The flaw, designated as CVE-2026-5846, impacts several versions of the software, including BC550 12.30, BC750 11.33 and 12.35, BC760 12.38 and 13.00, and BC760DC 12.39. This issue arises from the use of hard-coded cryptographic keys within the firmware, which are stored in plaintext, posing a significant security risk. Users of the affected software, primarily in sectors such as healthcare and financial services, are urged to apply security patches provided by Watchfire to mitigate the risk. While no public exploitation of this vulnerability has been reported yet, organizations are advised to take proactive measures to secure their systems against potential attacks.
Johnson Controls has identified multiple vulnerabilities in their OpenBlue Employee software, specifically versions up to V2025.3.1. These flaws could allow attackers to upload malicious files, execute cross-site scripting (XSS) attacks, or inject harmful HTML content, posing significant risks to users. The vulnerabilities are particularly concerning as they affect critical infrastructure sectors, including manufacturing, transportation, and energy. Johnson Controls advises users to apply the latest updates and implement strong access controls to mitigate potential risks. The company has outlined specific defensive measures to help secure the application and protect users from exploitation.
MZ Automation GmbH's libiec61850 library, used in critical infrastructure like energy systems, has several vulnerabilities that could lead to denial-of-service attacks. Versions prior to 1.6.2 are affected by multiple issues, including improper validation of timestamps and flaws in the GOOSE and MMS message processing. Attackers could exploit these weaknesses by sending specially crafted messages, causing the affected services to crash. This poses a significant risk to operational reliability in systems relying on this library. Users are urged to update to version 1.6.2 to mitigate these risks.
Rockwell Automation has identified a vulnerability in several of its communications modules, including the CompactLogix 5380 and ControlLogix 5580 models. This flaw could allow attackers to trigger a denial-of-service condition, disrupting the operation of affected devices. The vulnerable versions include ControlLogix 5580 from V36 to V37 and the 1756-EN4TR communications module versions V6.001 and V7.001. To mitigate this risk, users are advised to update to ControlLogix 5580, CompactLogix 5380, GuardLogix 5580, Compact GuardLogix 5380, and 1756-EN4TR versions V38.011 and V8.001, respectively. While no public exploitation has been reported yet, organizations are encouraged to take proactive measures to secure their systems, including minimizing network exposure and utilizing VPNs for remote access.
The article discusses a new component of the Astaroth spambot, which has been observed in recent attacks. This spambot is primarily used to distribute malware and steal sensitive information from victims. Researchers indicate that the latest version has enhanced capabilities, allowing it to evade detection more effectively than its predecessors. Astaroth targets a range of users, particularly those in sectors that handle confidential data, making it a significant threat. Its ongoing evolution raises concerns for cybersecurity professionals as they work to protect their networks from such sophisticated attacks.
Recent research suggests that the perceived decline in ransomware attacks may not be as straightforward as it seems. Instead of a decrease, there has been a shift in tactics used by attackers, indicating that businesses need to stay alert. The study emphasizes that companies should not let their guard down, as ransomware remains a significant threat. Experts recommend several defenses, including regular data backups, employee training on phishing, and implementing robust security measures. This ongoing risk underscores the need for organizations to continuously evaluate and improve their cybersecurity strategies to protect against evolving threats.
BleepingComputer
The article discusses the risks associated with single sign-on (SSO) systems, particularly when attackers gain access to compromised SSO logins. This type of breach can allow unauthorized individuals to access multiple enterprise applications, posing significant security risks for organizations. To combat these threats, the article suggests implementing stronger password policies, using phishing-resistant multi-factor authentication (MFA), and enhancing identity hardening measures. These strategies are crucial in securing SSO environments and protecting sensitive data across various applications. Companies must prioritize these security measures to prevent potential breaches and safeguard their operations.
Infosecurity Magazine
Recent analysis by Cisco Talos reveals that phishing remains a leading method for cyber attackers to gain initial access to target systems. The report highlights that even as hackers refine their techniques to bypass security measures, phishing continues to be effective due to its deceptive nature. Companies and organizations remain at risk, as many users still fall victim to these scams, which can lead to data breaches and significant financial loss. This situation calls for heightened awareness and better training for employees to recognize and avoid phishing attempts. As phishing attacks evolve, it’s crucial for businesses to improve their defenses and response strategies to mitigate these risks.
A vulnerability in the igloohome Smart Lock Mobile Application has been discovered, affecting version 3.2.3 and earlier. This flaw, identified as CVE-2026-16581, allows unauthorized access to backend services due to sensitive information being included in the application's source code. As a result, attackers could exploit this weakness to access functionality that should be protected by authentication measures. igloohome has addressed the issue by enhancing access controls to prevent unauthorized requests. Users are advised to ensure they are using the latest version of the app to mitigate risks.
Security Affairs
Researchers at Proofpoint have identified a new crypter-as-a-service called Cruciferra, which is being used by cybercriminals to facilitate malware attacks. This service allows hackers to bypass antivirus protections and has been linked to a series of campaigns that target Indian taxpayers, tax professionals, and corporate finance teams. The income-tax-themed lures are being delivered through this shared infrastructure, indicating a collaborative approach among various unrelated criminal groups. This development raises concerns about the growing sophistication of malware delivery methods and the potential for increased financial fraud, especially in regions where tax-related scams are prevalent. Organizations and individuals need to be vigilant against these types of attacks and ensure their cybersecurity measures are up to date.
SCM feed for Latest
Phishing attacks targeting insurance companies have shifted from simply stealing login credentials to real-time account hijacking. This new tactic allows attackers to take control of victims' accounts while they are actively using them, increasing the potential for fraud. Insurance companies are particularly vulnerable due to the sensitive nature of the data they hold and the financial transactions they process. The rise of this method suggests that cybercriminals are becoming more sophisticated and are willing to exploit users in real-time. As these attacks evolve, it is crucial for both companies and individuals to be vigilant and enhance their security measures to protect against such threats.
SCM feed for Latest
OnTrac, a parcel delivery service, has reported a data breach that may have exposed sensitive personal information of its customers. The breach occurred due to a cyberattack on the company's corporate network. Although specific details about the types of data compromised have not been released, customers are urged to stay vigilant about potential identity theft or phishing attempts. This incident raises concerns about the security measures in place at logistics companies and the protection of customer data. As the investigation unfolds, affected individuals should monitor their accounts and consider taking steps to secure their information.
Latest news
A recent study by CDW reveals that 43% of companies have already faced cybersecurity attacks powered by artificial intelligence, particularly in the form of sophisticated phishing and malware threats. This shift in tactics indicates that cybercriminals are increasingly using AI to enhance their attacks, making them more effective and harder to detect. Despite the growing threat, the research raises concerns about whether enough organizations are adopting AI-driven defenses to counter these emerging risks. As companies grapple with these new challenges, they must prioritize integrating AI into their cybersecurity strategies to protect sensitive data and systems. The findings serve as a wake-up call for businesses to reassess their security measures and ensure they are equipped to handle AI-enhanced threats.
A cybercrime group linked to China has been using a sophisticated crypter service named Cruciferra to hide malware in attacks targeting Indian taxpayers, tax professionals, and corporate finance teams. Recent analysis from Proofpoint reveals that this service allows various cybercriminals to deliver different forms of remote access malware while evading detection. Cruciferra employs techniques such as Bring Your Own Vulnerable Driver (BYOVD) and process ghosting, which help the malware operate stealthily on victim systems. The implications of these tactics are significant, as they enable attackers to compromise sensitive financial data and potentially cause substantial financial harm to individuals and organizations. This development is a reminder for users and companies to remain vigilant against evolving cyber threats and to implement strong security measures.