📰 Pulse Secure News
Page 12 - Pulse Secure News Today
Fast, Ad-Free News Updates
Stay updated with breaking news from Pulse Secure. Real-time updates on events, politics, business and more.
May 7, 2021
On top of all that the SVR is also posing as legitimate red-team pentesters: looking for easy camouflage, the spies hopped onto GitHub and downloaded the free open-source Sliver red-teaming platform, in what the NCSC described as "an attempt to maintain their accesses." There are more vulns being abused by the Russians and the full NCSC advisory on what these are can be read on the NCSC website. The advisory includes YARA and Snort rules. The self-preservation society Separately, the NCSC iss...
May 7, 2021
The FBI, National Security Agency, and the Department of Homeland Securitys Cybersecurity and Infrastructure Security Agency (CISA) joined the United Kingdoms National Cyber Security Centre (NCSC) to provide more details on SVR activity, including the exploitation that followed the SolarWinds Orion software compromise, CISA officials write in an alert. CISA today also released a fact sheet on Russian SVR activities. "The group uses a variety of tools and techniques to predominantly target ...
May 7, 2021
NCSC, CISA publish new information on Russia’s Cozy Bear New intelligence from UK and US cyber agencies suggests that APT29, or Cozy Bear, has been switching up its tactics Share this item with your network: By Published: 07 May 2021 15:15 The UK’s National Cyber Security Centre (NCSC), alongside partners at the US’s Cybersecurity and Infrastructure Security Agency (CISA) and the FBI have published a new advisory detailing techniques, tactics and procedures (TTPs) being used by the R...
May 6, 2021
minute read Share this article: The student opted for “free” software packed with a keylogger that grabbed credentials later used by “Totoro” to get into a biomolecular institute. A European biomolecular research institute involved in COVID-19 research lost a week’s worth of research data, all thanks to a Ryuk ransomware attack traced back to a student trying to save money by buying unlicensed software. Security researchers at Sophos described the attack in a report pub...
May 5, 2021
iTWire Thursday, 06 May 2021 00:31 SolarWinds announces three new executive appointments Featured SolarWinds has announced the extension of its executive team with three new appointments, including Chief Product Officer, Chief Information Security Officer (CISO), and Chief Customer Officer. SolarWinds has appointed Rohini Kasturi as executive vice president and chief product officer, Tim Brown as chief information security officer (CISO), and Andrea Webb as senior Vice Pre...
May 4, 2021
The Pentagon with the Washington Monument and National Mall in the background. Pulse Secure on Monday released a patch for the zero-day vulnerability that hackers used to access the networks of U.S. defense contractors and other government agencies worldwide. (U.S. Air Force Photo by Senior Airman Perry Aston) Pulse Secure on Monday released a patch for the zero-day vulnerability that hackers used to access the networks of U.S. defense contractors and other government agencies worldwide. In a ...
May 4, 2021
Pulse Secure Patches Critical Zero-Day Flaw. CVSS 10.0 bug was exploited by multiple APT groups
May 4, 2021
minute read Share this article: The security flaw tracked as CVE-2021-22893 is being used by at least two APTs likely linked to China, to attack U.S. defense targets among others. Pulse Secure has rushed a fix for a critical zero-day security vulnerability in its Connect Secure VPN devices, which has been exploited by nation-state actors to launch cyberattacks against U.S. defense, finance and government targets, as well as victims in Europe. Pulse Secure also patched three other ...
May 4, 2021
Critical Patch Out for Critical Pulse Secure VPN 0-Day Under Attack Ivanti, the company behind Pulse Secure VPN appliances, has released a security patch to remediate a critical security vulnerability that was found being actively exploited in the wild by at least two different threat actors. Tracked as CVE-2021-22893 (CVSS score 10), the flaw concerns "multiple use after free" issues in Pulse Connect Secure that could allow a remote unauthenticated attacker to execute arbitrary code and take c...
May 3, 2021
Share Two weeks after researchers warned that attackers in China were exploiting a newly discovered vulnerability in the Pulse Connect Secure VPN appliance, the company has released a patch for that flaw, along with several others that can be used for remote code execution. The vulnerability that surfaced in April (CVE-2021-22893) is in fact a collection of several use-after-free bugs in Pulse Connect Secure. Attackers have been exploiting the flaws for some time, perhaps as long as several y...