• Skip to primary navigation
  • Skip to main content
GreyKeep Security logo

GreyKeep Security

Expert security for an evolving digital age

  • Services
  • Our Approach
  • Blog
  • About
  • Contact Us
  • Show Search
Hide Search

Cybersecurity Daily: August 9, 2023

greykeep · August 9, 2023 ·

GreyKeep Cybersecurity Daily News

Your daily dose of relevant cybersecurity advisories, industry news, and product updates for Wednesday, August 9, 2023.

Advisories

  • EvilProxy phishing campaign targets 120,000 Microsoft 365 users
  • Microsoft Releases Patches for 74 New Vulnerabilities in August Update
  • Microsoft Visual Studio Code flaw lets extensions steal passwords
  • Microsoft Patch Tuesday, August 2023 Edition
  • Intel Addresses 80 Firmware, Software Vulnerabilities
  • 40 Vulnerabilities Patched in Android With August 2023 Security Updates
  • 16 Zero-Day Vulnerabilities Discovered in CODESYS Affect Millions of Industrial Devices
  • Beware of New Malware Attack Disguised As Google Bard Ads On Facebook
  • Western Digital, Synology NAS Vulnerabilities Exposed Millions of Users’ Files
  • SAP Patches Critical Vulnerability in PowerDesigner Product
[Read more…] about Cybersecurity Daily: August 9, 2023

Security Researchers Repurpose Amazon SSM Agent as a Remote Access Trojan

greykeep · August 4, 2023 ·

Laptop computer displaying AWS logo

Security researchers at Mitiga have discovered a technique for using AWS Systems Manager (SSM) Agent as a remote access trojan (RAT). The technique allows for persistent command and control of a compromised host by an attacker from within another AWS account.

SSM Agent is software that allows administrators to configure, manage, and update AWS resources through the Systems Manager service. It can be installed on a various systems, including Amazon Elastic Compute Cloud (EC2) instances, edge devices, on-premises servers, and virtual machines.

[Read more…] about Security Researchers Repurpose Amazon SSM Agent as a Remote Access Trojan

Cybersecurity Daily: August 3, 2023

greykeep · August 3, 2023 ·

GreyKeep Cybersecurity Daily News

Your dose of relevant cybersecurity advisories, industry news, and product updates for Thursday, August 3, 2023.

Advisories

  • Over 640 Citrix Servers Compromised Using RCE Vulnerability
  • Zero-day in Salesforce email services exploited in targeted Facebook phishing campaign
  • Microsoft Catches Russian Government Hackers Phishing with Teams Chat App
  • It’s a hot 0-day summer for Apple, Google, and Microsoft security fixes
  • Researchers Uncover AWS SSM Agent Misuse as a Covert Remote Access Trojan
  • New hVNC macOS Malware Advertised on Hacker Forum
[Read more…] about Cybersecurity Daily: August 3, 2023

Over 640 Citrix Servers Compromised Using RCE Vulnerability

greykeep · August 2, 2023 ·

Citrix logo

Attackers are actively exploiting a code injection vulnerability in Citrix Netscaler ADC and Gateway servers to gain remote access and exfiltrate data. The remote code execution (RCE) vulnerability is being tracked under CVE-2023-3519.

Security researchers from the non-profit Shadowserver Foundation estimate attackers have used the vulnerability to deploy web shells on at least 640 Citrix servers, with thousands of unpatched servers potentially impacted.

[Read more…] about Over 640 Citrix Servers Compromised Using RCE Vulnerability

GameOver(lay) Vulnerabilities in Ubuntu May Affect 40% of Cloud Users

greykeep · August 1, 2023 ·

Ubuntu Linux command line prompt
Photo by Gabriel Heinzer

Two privilege escalation vulnerabilities, collectively called GameOver(lay), may affect 40% of cloud workloads running on Ubuntu. The GameOver(lay) vulnerabilities were discovered by security firm Wiz and jointly reported by The Hacker News.

The vulnerabilities were reported under CVE-2023-32629 and CVE-2023-2640 and only affect Ubuntu kernels.

[Read more…] about GameOver(lay) Vulnerabilities in Ubuntu May Affect 40% of Cloud Users
  • « Go to Previous Page
  • Page 1
  • Interim pages omitted …
  • Page 6
  • Page 7
  • Page 8
  • Page 9
  • Go to Next Page »

How can we help you become more secure? Contact Us

GreyKeep Security

© 2025 GreyKeep Security LLC · All Rights Reserved

  • Services
  • Our Approach
  • GreyKeep Security Blog
  • About Us
  • Contact Us