===================== = End-of-Day report = =====================
Timeframe: Montag 26-05-2025 18:00 − Dienstag 27-05-2025 18:00 Handler: Felician Fuchs Co-Handler: n/a
===================== = News = =====================
∗∗∗ MATLAB dev confirms ransomware attack behind service outage ∗∗∗ --------------------------------------------- MathWorks, a leading developer of mathematical computing and simulation software, has revealed that a recent ransomware attack is behind an ongoing service outage. --------------------------------------------- https://www.bleepingcomputer.com/news/security/mathworks-blames-ransomware-a...
∗∗∗ Not Every CVE Deserves a Fire Drill: Focus on What’s Exploitable ∗∗∗ --------------------------------------------- Not every "critical" vulnerability is a critical risk. Picus Exposure Validation cuts through the noise by testing whats actually exploitable in your environment — so you can patch what matters. --------------------------------------------- https://www.bleepingcomputer.com/news/security/not-every-cve-deserves-a-fire...
∗∗∗ Chinese-Owned VPNs ∗∗∗ --------------------------------------------- One one my biggest worries about VPNs is the amount of trust users need to place in them, and how opaque most of them are about who owns them and what sorts of data they retain. A new study found that many commercials VPNS are (often surreptitiously) owned by Chinese companies. It would be hard for U.S. users to avoid the Chinese VPNs. The ownership of many appeared deliberately opaque, with several concealing their structure behind layers of offshore shell companies. --------------------------------------------- https://www.schneier.com/blog/archives/2025/05/chinese-owned-vpns.html
∗∗∗ Cyber Security Operations Center: ESA will mehr IT-Sicherheit ∗∗∗ --------------------------------------------- Die Raumfahrtagentur ESA verstärkt ihre IT-Sicherheitsbemühungen. Dazu eröffnete sie nun das Cyber Security Operations Center. --------------------------------------------- https://www.heise.de/news/Cyber-Security-Operations-Center-ESA-will-mehr-IT-...
∗∗∗ Dutch intelligence unmasks previously unknown Russian hacking group Laundry Bear ∗∗∗ --------------------------------------------- Recent attacks on institutions in the Netherlands were the work of a previously unknown Russian hacking group that Dutch intelligence agencies are labeling Laundry Bear. Microsoft also reported on the group, naming it Void Blizzard. --------------------------------------------- https://therecord.media/laundry-bear-void-blizzard-russia-hackers-netherland...
∗∗∗ Text-to-Malware: How Cybercriminals Weaponize Fake AI-Themed Websites ∗∗∗ --------------------------------------------- Mandiant Threat Defense has been investigating an UNC6032 campaign that weaponizes the interest around AI tools, in particular those tools which can be used to generate videos based on user prompts. UNC6032 utilizes fake “AI video generator” websites to distribute malware leading to the deployment of payloads such as Python-based infostealers and several backdoors. --------------------------------------------- https://cloud.google.com/blog/topics/threat-intelligence/cybercriminals-weap...
===================== = Vulnerabilities = =====================
∗∗∗ GitHub MCP Exploited: Accessing private repositories via MCP ∗∗∗ --------------------------------------------- We showcase a critical vulnerability with the official GitHub MCP server, allowing attackers to access private repository data. The vulnerability is among the first discovered by Invariants security analyzer for detecting toxic agent flows. --------------------------------------------- https://invariantlabs.ai/blog/mcp-github-vulnerability
∗∗∗ Update für ManageEngine ADAudit Plus stopft hochriskante Sicherheitslücken ∗∗∗ --------------------------------------------- In ManageEngine ADAudit Plus hat Hersteller Zoho zwei als hohes Risiko eingestufte Schwachstellen ausgebessert. --------------------------------------------- https://www.heise.de/news/Update-fuer-ManageEngine-ADAudit-Plus-stopft-hochr...
∗∗∗ Security updates for Tuesday ∗∗∗ --------------------------------------------- Security updates have been issued by AlmaLinux (gstreamer1-plugins-bad-free, libsoup, and python-tornado), Debian (libavif and pgbouncer), Red Hat (gstreamer1-plugins-bad-free, mingw-freetype and spice-client-win, and webkit2gtk3), SUSE (firefox, govulncheck-vulndb, and python310-setuptools), and Ubuntu (flask, intel-microcode, openjdk-17-crac, tika, and Tomcat). --------------------------------------------- https://lwn.net/Articles/1022703/
∗∗∗ Security Vulnerabilities fixed in Firefox ESR 128.11 ∗∗∗ --------------------------------------------- https://www.mozilla.org/en-US/security/advisories/mfsa2025-44/
∗∗∗ Security Vulnerabilities fixed in Firefox ESR 115.24 ∗∗∗ --------------------------------------------- https://www.mozilla.org/en-US/security/advisories/mfsa2025-43/
∗∗∗ Security Vulnerabilities fixed in Firefox 139 ∗∗∗ --------------------------------------------- https://www.mozilla.org/en-US/security/advisories/mfsa2025-42/