Threat actors have been actively exploiting an already addressed critical vulnerability impacting the Cacti device monitoring tool, tracked as CVE-2022-46169, to deliver the Mirai malware and PERL-based IRC botnet that resulted in the opening of a host-based reverse shell, according to BleepingComputer.
BleepingComputer reports that Microsoft Exchange servers are being targeted by the Cuba ransomware operation with the zero-day OWASSRF exploit, tracked as CVE-2022-41080, which has also been exploited by the Play ransomware gang to evade ProxyNotShell URL rewrite mitigations.
Government organizations and other government-related targets had their networks targeted in attacks exploiting an already patched FortiOS SSL-VPN zero-day flaw, tracked as CVE-2022-42475, reports BleepingComputer.
More than 100 models of Siemens SIMATIC and SIPLUS S7-1500 programmable logic controllers were found by Red Balloon Security to contain several architectural flaws that could be leveraged to facilitate device compromise, The Hacker News reports.
Security researchers say the strong response by Juniper shows that the tech company is taking security seriously, and the hope is that other vendors will follow suit.
The Scattered Spider threat operation has been engaging in a Bring Your Own Vulnerable Driver attack exploiting an old high-severity Intel Ethernet diagnostics driver flaw to bypass endpoint detection and response systems, according to BleepingComputer.
Cisco has warned that some of its end-of-life small business routers including the Cisco Small Business RV016, RV042, RV042G, and RV082 routers are being impacted by two critical flaws within their web-based management interface, which could be leveraged to obtain unauthorized access, according to SiliconAngle.
Fast Five
Selected by the SC Media Editorial team every Tuesday.
Sign up now for the top five issues cybersecurity pros need to know this week.