Fixes have been issued by Taiwanese networking device manufacturer Zyxel to address five security vulnerabilities impacting its NAS326 and NAS542 network-attached storage devices that have not been supported since the end of 2023, including three critical flaws that could be exploited to facilitate remote code execution and command injection attacks, according to The Register.
CyberScoop reports that NSO Group's Pegasus spyware targeted five journalists and two activists in Europe, most of whom were in exile, from August 2020 to June 2023.
Millions of modems by U.S. broadband provider Cox could have been hacked through the exploitation of several authentication bypass vulnerabilities that could enable privilege escalation and data exfiltration activities, reports The Hacker News.
More than 600,000 internet routers across several Midwest states have been taken offline by a widespread cyberattack against an unnamed U.S. telecommunications firm last October that involved the distribution of a malicious firmware update, Reuters reports.
Cybernews reports that updates have been introduced to the LightSpy surveillance tool to expand its targeting to systems running on older iterations of macOS after initially only targeting iOS devices.
Vulnerable Palo Alto Networks PAN-OS firewalls impacted by the flaw, tracked as CVE-2024-3400, have been targeted by suspected Lazarus Group-linked threat actors to distribute an updated version of the RedTail cryptocurrency mining malware since late April, according to Security Boulevard.