Assetnote researchers discovered that popular open-source content management system dotCMS, which has more than 10,000 users across over 70 countries, is being impacted by a critical pre-authenticated remote code execution flaw, which could be exploited to facilitate arbitrary command execution.
Russian state-sponsored threat group Nobelium, which was behind the widespread SolarWinds hack, has been leveraging over four dozen domains impersonating real brands in new phishing attacks.
The California resident Sercan Oyuntur has been convicted for his involvement in a phishing scam targeted at the U.S. Department of Defense that resulted in nearly $23.5 million in damages.
The Hacker News reports the reemergence of the Chinese state-backed threat group Override Panda, also known as Hellsing, Bronze Geneva, and Naikon, in a new phishing attack aimed at data exfiltration.
Russian state-sponsored hacking group APT29, also known as Cozy Bear or Nobelium, has launched spear-phishing campaigns aimed at government and diplomatic organizations in the Americas, Europe, and Asia since January, The Hacker News reports.
The Satellite Cybersecurity Act aims to develop voluntary cybersecurity standards and recommendations for protecting commercial U.S. satellite networks.
Fast Five
Selected by the SC Media Editorial team every Tuesday.
Sign up now for the top five issues cybersecurity pros need to know this week.