News

Latest news on the subject of B2B cyber security >>> PR agencies: Add us to your mailing list - see contact! >>> Book an exclusive PartnerChannel for your news!

SAP patches close serious security gaps
B2B Cyber ​​Security ShortNews

On its patch day, SAP published a list of 19 new security gaps and related updates. This is also necessary because the list contains two critical vulnerabilities with CVSS scores of 9.9 out of 10 and three other critical vulnerabilities with CVSS 9.6 to 9.0. As almost every month, it is worth taking a look at the SAP Patch Day Blog. The month of March 2023 again shows a large list of security gaps. According to the Common Vulnerability Scoring System - CVSS - 19 of the 5 security gaps listed and the corresponding updates are...

Read more

Lazarus: New backdoor against targets in Europe 
Eset_News

The APT group Lazarus, known for many attacks, is also using a new backdoor malware against targets in Europe. According to ESET researchers, the intended uses are espionage and data manipulation. The malware researchers at the IT security manufacturer ESET have uncovered a new dangerous malware from the notorious APT group Lazarus (Advanced Persistent Threat). The increased occurrence in South Korea, the code and the behavior of the backdoor "WinorDLL64" suggest that it is the hacker gang allied with North Korea. However, the backdoor is also used for targeted attacks in the Middle East and Europe. At ESET research facilities…

Read more

Critical vulnerabilities in Lexmark printers
B2B Cyber ​​Security ShortNews

The manufacturer of corporate printers Lexmark has once again warned its users of critical vulnerabilities. In dozens of its models there are four vulnerabilities in the firmware with a CVSSv3 score of 9.0, one 8.5 and one 8.0 out of 10. Users should update the firmware accordingly. A few weeks ago, Lexmark had to ask many of its users to update the firmware for many of its printers. Now there is already a large number of dangerous vulnerabilities. The update is recommended for companies and administrators, as the CVSSv3 values ​​​​are 9.0 out of 10 in four cases and are classified as critical…

Read more

ALPHV claims to have hacked camera manufacturer Ring
B2B Cyber ​​Security ShortNews

In addition to many private users, the provider Ring also supplies small companies with cameras, surveillance systems and video doorbells. Now the Amazon subsidiary Ring can be found as a victim on the ALPHV or BlackCat leak page. As soon as the APT group ALPHV or BlackCat has hacked a company, it is publicly exposed on its leak page. Normally, it always says when and how much data was stolen. Because the goal of the group is always multiple blackmail. First the company is hacked and then the data is encrypted using ransomware. But before that, the group still transports a…

Read more

BSI warns: exploitation of a vulnerability in MS Outlook
B2B Cyber ​​Security ShortNews

The BSI warns of a vulnerability in Outlook that is apparently already being actively exploited. The CVSS value of the vulnerability is 9.8 and is therefore considered critical. Microsoft is already providing an update that should be installed immediately if it didn't happen automatically. On March 14, 2023, Microsoft released updates for numerous vulnerabilities as part of its monthly Patch Days - including several patches for security vulnerabilities that are classified as "critical" according to the Common Vulnerability Scoring System (CVSS) with values ​​of 9.0 and higher. Important patch ready In the…

Read more

Backdoor: Chinese hacker group attacks Europe
B2B Cyber ​​Security ShortNews

The Chinese hacker group Mustang Panda is stepping up its attacks on targets in Europe, Australia and Taiwan. Researchers at the IT security manufacturer ESET uncovered a campaign that is currently still running, in which the newly developed backdoor MQsTTang is used. This allows attackers to execute any command on the victim's computer. The focus is on political and state organizations, above all a government institution in Taiwan. Mustang Panda has significantly increased its activities since Russia invaded Ukraine. MQsTTang: Evidence of Rapid Development Cycle MQsTTang is a simple backdoor that allows attackers to…

Read more

Improved security solution for Mac computers
B2B Cyber ​​Security ShortNews

The IT security manufacturer ESET has presented its latest version of ESET Cyber ​​Security for macOS. The security solution for Mac computers has numerous new and improved functions. In addition to protection against the latest cyber threats, ESET Cyber ​​Security for macOS now also offers native support for ARM. ARM processors have become increasingly popular as chipsets in recent years due to their high performance and low energy consumption. This has resulted in the ARM-based mobile computing market now surpassing the traditional x86-based market in both revenue and unit count…

Read more

AV-TEST gives 27 awards to the best security products
AV TEST News

The Magdeburg institute AV-TEST gives 27 awards to 14 companies in the security industry for particularly good products for private users and companies. All test values ​​from 2022 serve as a basis. There are a few surprises at the awards. For many security manufacturers, it's time for a little drum roll: The AV-TEST laboratory has evaluated all test data for 2022 and determined the best products in their test category. Now it's time to award these software products with the internationally recognized award for IT security, the AV-Test Award. Motto “AV-TEST Award 2022:…

Read more

Cybergangsters: Telegram bots bypass ChatGPT restrictions
B2B Cyber ​​Security ShortNews

Check Point Research (CPR) security researchers found that cyber criminals use Telegram bots to bypass ChatGPT restrictions on underground forums. The bots use OpenAI's API to create malicious emails or code. Chat bot makers currently give up to 20 free queries, but then charge $5,50 for every 100 queries. CPR therefore warns of ongoing efforts by cybercriminals to circumvent ChatGPT's restrictions in order to use OpenAI for malicious purposes. Telegram ChatGPT Bot-as-a-Service CPR found advertisements for Telegram bots on underground forums. The bots use the API…

Read more

Critical vulnerabilities in Android 11, 12 and 13
B2B Cyber ​​Security ShortNews

Google shares on its Android Security Bulletin that there are two critical vulnerabilities in Android 11, 12, 12L and 13. If you have an Android device with current support, you should trigger the system update manually to check whether the March security update is already available for your device. In its Android Security Bulletin March 2023, Google informed about the critical vulnerabilities CVE-2023-20951 and CVE-2023-20954. Both serious vulnerabilities can lead to remote code execution without requiring additional execution permissions. No user interaction is required for use. If you have a device with current support, you should therefore check the system update to see if it…

Read more