BleepingComputer.com

"Automattic blocks WP Engie's access to WordPress resources."

Views expressed in this cybersecurity, cyber crime update are those of the reporters and correspondents.  Accessed on 26 September 2024, 1425 UTC.

Content and Source:   https://www.bleepingcomputer.com/

Please check link or scroll down to read your selections.  Thanks for joining us today.

Russ Roberts (https://www.hawaiicybersecurityjournal.net).

Automattic blocks WP Engine’s access to WordPress resources

  • WordPress.org has banned WP Engine from accessing its resources and stopped delivering plugin updates to websites hosted on the platform, urging impacted users to choose other hosting providers.

  • Android
     

Fake WalletConnect app on Google Play steals Android users’ crypto

  • A crypto draining app mimicking the legitimate 'WalletConnect' project has been distributed over Google Play for five months getting more than 10,000 downloads.

  • Aruba Networks
     

HPE Aruba Networking fixes critical flaws impacting Access Points

  • HPE Aruba Networking has fixed three critical vulnerabilities in the Command Line Interface (CLI) service of its Aruba Access Points, which could let unauthenticated attackers gain remote code execution on vulnerable devices.

  • Microsoft Office
     

Buy a Microsoft Office for Windows license for $35 in this deal

  • Microsoft 365 may not feel expensive at first, but those monthly payments can add up over time. You could opt for one of the free alternatives, but Google Sheets doesn't quite have the same hold on the professional world that Excel does.

    • BleepingComputer Deals
    •  
    • September 26, 2024
    •  
    • 07:16 AM
    •  
    • Comment Count 0
  • Mozilla
     

Mozilla accused of tracking users in Firefox without consent

  • European digital rights group NOYB (None Of Your Business) has filed a privacy complaint with the Austrian data protection watchdog (DSB) against Mozilla, alleging the company uses a Firefox privacy feature (enabled without consent) to track users' online behavior.

  • Facebook
     

Meta halts routing via Deutsche Telekom over €20M peering fee

  • Meta announced that it's ending its direct peering relationship with Deutsche Telekom following a court's ruling earlier this year that would oblige the tech firm to pay the telecom €20,000,000 to continue using its network.

  • CompTia
     

This $50 bundle helps you prepare for your CompTIA exams on a budget

  • Study for all your CompTIA certifications in one place.  Get the Complete 2024 CompTIA Course Super Bundle while it's on sale for $49.99. 

    • BleepingComputer Deals
    •  
    • September 25, 2024
    •  
    • 02:07 PM
    •  
    • Comment Count 0
  • Android
     

Google sees 68% drop in Android memory safety flaws over 5 years

  • The percentage of Android vulnerabilities caused by memory safety issues has dropped from 76% in 2019 to only 24% in 2024, representing a massive decrease of over 68% in five years.

  • CISA
     

CISA: Hackers target industrial systems using “unsophisticated methods”

  • ​CISA warned today of threat actors trying to breach critical infrastructure networks by targeting Internet-exposed industrial devices using "unsophisticated" methods like brute force attacks and default credentials.

  • Winamp
     

Winamp releases source code, asks for help modernizing the player

  • The iconic Winamp media player has fulfilled a promise made in May to go open-source and has now published its complete source code on GitHub.

  • Use this DeskSense AI assistant for more than ChatGPT in this deal
     

Use this DeskSense AI assistant for more than ChatGPT in this deal

  • DeskSense is like having a personal assistant that helps you stay productive and creative, and it's pretty cheap, too. A DeskSense lifetime license is only $49 (reg. $179).

    • BleepingComputer Deals
    •  
    • September 25, 2024
    •  
    • 07:19 AM
    •  
    • Comment Count 0
  • Windows
     

Windows 10 KB5043131 update released with 9 changes and fixes

  • ​​Microsoft has released the September 2024 non-security preview update for Windows 10, version 22H2, with fixes for bugs causing Edge web browser freezes and media playback issues.

  • Canada cars
     

AutoCanada says ransomware attack "may" impact employee data

  • AutoCanada is warning that employee data may have been exposed in an August cyberattack claimed by the Hunters International ransomware gang.

  • Water plant hacker
     

Kansas water plant cyberattack forces switch to manual operations

  • Arkansas City, a small city in Cowley County, Kansas, was forced to switch its water treatment facility to manual operations over the weekend to contain a cyberattack detected on Sunday morning.

  • Microsoft Project
     

This Microsoft Project deal helps if your work projects are piling up

  • Microsoft Project simplifies the coordination of tasks and timelines, enabling users to navigate complex projects with greater confidence, and it's on sale for $19.97 (down from $249).

    • BleepingComputer Deals
    •  
    • September 24, 2024
    •  
    • 02:11 PM
    •  
    • Comment Count 0
  • Healthcare
     

U.S. govt agency CMS says data breach impacted 3.1 million people

  • The Centers for Medicare & Medicaid Services (CMS) federal agency announced earlier this month that health and personal information of more than three million health plan beneficiaries was exposed in the MOVEit attacks Cl0p ransomware conducted last year.

  • Google Chrome
     

Infostealer malware bypasses Chrome’s new cookie-theft defenses

  • Infostealer malware developers released updates claiming to bypass Google Chrome's recently introduced feature App-Bound Encryption to protect sensitive data such as cookies.

  • Ivanti
     

Critical Ivanti vTM auth bypass bug now exploited in attacks

  • CISA has tagged another critical Ivanti security vulnerability, which can let threat actors create rogue admin users on vulnerable Virtual Traffic Manager (vTM) appliances, as actively exploited in attacks.

  • Robot Programmer
     

Hackers deploy AI-written malware in targeted attacks

  • While cybercriminals have used generative AI technology to create convincing emails, government agencies have warned about the potential abuse of AI tools to creating malicious software, despite the safeguards and restrictions that vendors implemented.

  • Generative AI Security: Getting ready for Salesforce Einstein Copilot
     
    Security· Sponsored Content

Generative AI Security: Getting ready for Salesforce Einstein Copilot

  • Salesforce's Einstein Copilot can provide insights and perform tasks help streamline daily processes. However, it also comes with risks that you should takes steps to mitigate. Learn more from Varonis on how to prepare for Salesforce Einstein Copilot,

    • Sponsored by Varonis
    •  
    • September 24, 2024
    •  
    • 10:02 AM
    •  
    • Comment Count 0



 


Comments

Popular posts from this blog

Cyber War News Today.

BleepingComputer.com

The Cyberwire Daily Briefing