Curated news, CVE analysis, and threat reports from the world's top cybersecurity sources.
This article explores the detection gap for MITRE ATT&CK technique T1053.005, which involves scheduled tasks. It provides guidance on identifying and mitigating abuse of scheduled tasks for persistence and privilege escalation.
Google Threat Intelligence Group reveals UNC6671 has not disbanded but diversified into brands like Redact, Pink, Helix, and Falcon. They continue using vishing to target enterprises, especially financial services, by stealing credentials and exfiltrating data from cloud environments.
A Belarusian national with decades of cybercriminal activity was sentenced to 16 years in U.S. prison for running the Ransom Cartel ransomware operation. The case underscores ongoing international judicial actions against ransomware perpetrators.
Forescout's research reveals over 4,400 internet-facing Rockwell PLCs, with 22 in US cities recently attacked. These exposures allow attackers to change settings and disrupt operations without needing vulnerabilities.
A recent Forescout report revealed over 4,400 Rockwell Automation programmable logic controllers (PLCs) exposed online globally, including 2,844 in the U.S. and 22 in cities targeted by recent cyberattacks on water utilities. Nineteen of these exposed controllers were connected via the same mobile carrier network and ran firmware vulnerable to CVE-2017-16740, a critical Modbus TCP buffer overflow flaw (CVSS 8.6) affecting Rockwell’s MicroLogix 1400 Series B and C. While no confirmed compromises were found, attackers could exploit weak configurations—such as default passwords or public internet exposure—to disrupt operations, as seen in incidents across at least seven states since late July.
View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to access sensitive information on the device. The following versions of Johnson Controls Inc.