• Skip to primary navigation
  • Skip to main content
GreyKeep Security logo

GreyKeep Security

Expert security for an evolving digital age

  • Services
  • Our Approach
  • Blog
  • About
  • Contact Us
  • Show Search
Hide Search

Breaches

Cybersecurity Daily: August 30, 2023

greykeep · August 30, 2023 ·

GreyKeep Security Cybersecurity Daily News

Your daily dose of relevant cybersecurity advisories, industry news, and product updates for August 30, 2023.

Advisories

  • VMware Aria vulnerable to critical SSH authentication bypass flaw
  • Threat actors started exploiting Juniper flaws shortly after PoC release
  • Hacking campaign bruteforces Cisco VPNs to breach networks
  • High-Severity Memory Corruption Vulnerabilities Patched in Firefox, Chrome
  • Unpatched Citrix NetScaler Devices Targeted by Ransomware Group FIN8
  • DreamBus malware exploits RocketMQ flaw to infect servers
  • Roblox and Rust Developers Targeted With Malicious Packages
  • China-Linked BadBazaar Android Spyware Targeting Signal and Telegram Users
  • Threat Actors Abuse Google Groups to Send Fake order Notifications
  • Attackers can discover IP address by sending a link over the Skype mobile app
  • BGP Flaw Can Be Exploited for Prolonged Internet Outages
[Read more…] about Cybersecurity Daily: August 30, 2023

Ransomware Campaign Targeting MOVEit Impacts 60 Million People

greykeep · August 28, 2023 ·

Progress MOVEit logo
Background by Peter Gargiulo

As reported by security research firms Emsisoft and Resecurity, as many as 1,000 organizations and 60 million individuals have been affected by the recent ransomware campaign targeting a SQL injection vulnerability (CVE-2023-34362) in the MOVEit Transfer web application. An attacker can exploit the vulnerability to access file transfers without authentication.

[Read more…] about Ransomware Campaign Targeting MOVEit Impacts 60 Million People

Cybersecurity Daily: August 24, 2023

greykeep · August 24, 2023 ·

GreyKeep Security Cybersecurity Daily News

Your daily dose of relevant cybersecurity advisories, industry news, and product updates for August 24, 2023.

For the latest news on malware and ransomware, check out our weekly Malware Roundup.

Advisories

  • More than 3,000 Openfire servers exposed to attacks using a new exploit
  • Hackers use public ManageEngine exploit to breach internet org
  • New stealthy techniques let hackers gain Windows SYSTEM privileges
  • New Variant of XLoader macOS Malware Disguised as ‘OfficeNote’ Productivity App
  • Ivanti Issues Fix for Critical Vuln in Its Sentry Gateway Technology
  • Adobe Patches Critical Deserialization Vulnerability, but Exploits Persist
  • New Juniper Junos OS Flaws Expose Devices to Remote Attacks – Patch Now
  • Akira ransomware gang spotted targeting Cisco VPN products to hack organizations
  • FBI: Patches for Recent Barracuda ESG Zero-Day Ineffective
  • Traders Targeted by Cybercriminals in Attack Exploiting WinRAR Zero-Day
  • Rockwell ThinManager Vulnerabilities Could Expose Industrial HMIs to Attacks
  • New Telegram Bot “Telekopye” Powering Large-scale Phishing Scams from Russia
  • TP-Link Tapo L530E smart bulb flaws allow hackers to steal user passwords
  • Apache XML Graphics Batik Flaw Exposes Sensitive Information
  • FBI Warns of Cryptocurrency Heists by North Korea’s Lazarus Group
  • Attackers Dangle AI-Based Facebook Ad Lures to Hijack Business Accounts
[Read more…] about Cybersecurity Daily: August 24, 2023

Cybersecurity Daily: August 17, 2023

greykeep · August 17, 2023 ·

GreyKeep Security Cybersecurity Daily News

Your daily dose of relevant cybersecurity advisories, industry news, and product updates for August 17, 2023.

Advisories

  • Exploitation of Citrix ShareFile Vulnerability Spikes as CISA Issues Warning
  • Two unauthenticated stack buffer overflows found in Ivanti Avalanche EMM
  • Citrix ADC, Gateways Still Backdoored, Even After Being Patched
  • Cisco Unified Communications Manager Flaw Let Attacker Launch SQL Injection Attacks
  • New Apple iOS 16 Exploit Enables Stealthy Cellular Access Under Fake Airplane Mode
  • Patch Now: OpenNMS Bug Steals Data, Triggers Denial of Service
  • Report: PowerShell Gallery susceptible to typosquatting and other package-management attacks
  • Kubernetes clusters face widespread attacks across numerous organizations
  • New LABRAT Campaign Exploits GitLab Flaw for Cryptojacking and Proxyjacking Activities
  • Gigabud RAT Attacking Android Users to Steal Banking Credentials
  • Thousands of Android APKs use compression trick to thwart analysis
[Read more…] about Cybersecurity Daily: August 17, 2023

Discord.io Temporarily Shuts Down Following Data Breach

greykeep · August 16, 2023 ·

Discord.io data breach
Photo by Alexander Shatov

The Discord.io custom invite service has temporarily shut down following a data breach that exposed information for 760K users. While not an official Discord site, the third-party service allowed visitors to search for Discord servers based on content and for server owners to create custom invites to their channels.

On August 13, a hacker known as ‘Akhirah’ began selling the Discord.io database on the Breached hacking forums. According to the hacker, the database contains information for 760,000 members, including usernames, Discord IDs, email addresses, and billing addresses among other details.

The breach is believed to have been caused by a vulnerability in the Discord.io website that provided access to the database. The site recommends that users who joined before 2018 update their password if shared with other websites.

  • « Go to Previous Page
  • Page 1
  • Page 2
  • Page 3
  • Page 4
  • Page 5
  • Go to Next Page »

How can we help you become more secure? Contact Us

GreyKeep Security

© 2025 GreyKeep Security LLC ยท All Rights Reserved

  • Services
  • Our Approach
  • GreyKeep Security Blog
  • About Us
  • Contact Us