Nearly 400,000 internet-exposed devices were susceptible to attacks involving the abuse of the 15 most exploited security flaws in 2023, almost half of which were Fortinet FortiOS appliances.
Aside from containing full names, other personal information, and product design details, the leaked emails also included sensitive data from high-ranking U.S. military personnel, who have ordered coins, medals, and battalion emblems, according to Cybernews researchers.
Data within the unsecured database included military personnel and their supporters' full names, images, mailing addresses, locations, images, Social Security numbers, and National Insurance numbers, a report by cybersecurity researcher Jeremy Fowler published on vpnMentor showed.
MITRE has regarded cross-site scripting flaws as the most common and severe software vulnerabilities this year, followed by out-of-bounds write, SQL injection, cross-site request forgery, and path traversal issues.
After implementing server updates, threat actors proceeded to download and execute the FFmpeg tool from MediaFire to capture Qatari beIN Sports network's live sports events, which are then redirected to the attacker-controlled stream[.]tv server.
Fast Five
Selected by the SC Media Editorial team every Tuesday.
Sign up now for the top five issues cybersecurity pros need to know this week.