Category: Information Security

PGA ransomware

Ohio Lottery Struck by Devastating Cyberattack

On the eve of the Christmas festivities, the Ohio Lottery fell victim to a cyberattack, disrupting several internal information systems. Hackers infiltrated the corporate network, encrypting data and causing disruptions in customer service. Despite...

USPS Site Exposed Data

LoanCare Breach Exposes Sensitive Real Estate Data

Fidelity National Financial, a major player in the real estate insurance sector, encountered a cybersecurity incident. Its subsidiary, LoanCare, a leading provider of loan servicing solutions, reported the data breach of 1,316,938 individuals following...

CVE-2023-7102

CVE-2023-7102 Zero-Day: Barracuda ESG Struck Again, Update Urgently

A new zero-day vulnerability in Barracuda Networks’ Email Security Gateway (ESG) has been disclosed. The vulnerability, identified as CVE-2023-7102, stems from the open-source third-party library, Spreadsheet::ParseExcel, used in ESG’s malware protection features. This issue...

RetSpill exploitation

RetSpill: A Linux kernel exploitation technique

In the complex domain of cybersecurity, the emergence of RetSpill marks a significant shift in the landscape of Linux kernel exploitation. This ingenious technique exploits the kernel’s design to escalate privileges, bypassing multiple layers...

SMTP Smuggling attack

SMTP Smuggling: The New Threat to Email Security

In the ever-evolving landscape of cybersecurity, a new attack technique named “SMTP Smuggling” has emerged, posing a significant threat to the integrity of email communications. Discovered by Timo Longin, in collaboration with SEC Consult,...

CVE-2023-51385

CVE-2023-51385: OpenSSH OS command injection vulnerability

Details have emerged about a now-patched security vulnerability in OpenSSH that could be potentially exploited to run arbitrary commands remotely on compromised hosts under specific conditions. The vulnerability is tracked under the CVE identifier...

CVE-2023-48291

Apache Airflow Breached: 4 Vulnerabilities Threaten Your Workflows

Apache Airflow, the backbone of countless workflow pipelines, has encountered unwelcome turbulence. Four security vulnerabilities, collectively known as CVE-2023-47265, CVE-2023-49920, CVE-2023-50783, and CVE-2023-48291, have landed in the Airflow ecosystem, putting your workflows and data...