article thumbnail

Oracle critical patch advisory addresses 284 flaws, 33 critical

Security Affairs

The advisory fixed the CVE-2016-1000031 flaw, a remote code execution (RCE) bug in the Apache Commons FileUpload, disclosed in November last year. The Commons FileUpload library is the default file upload mechanism in Struts 2, the CVE-2016-1000031 was discovered two years ago by experts at Tenable.

article thumbnail

Experts found a new TrickBot module (rdpScanDll) built for RDP bruteforcing operations

Security Affairs

TrickBot is a popular banking Trojan that has been around since October 2016, its authors have continuously upgraded it by implementing new features. Security experts from Bitdefender recently discovered a new TrickBot variant that is targeting telecommunications organizations in the United States and Hong Kong.

Insiders

Sign Up for our Newsletter

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

article thumbnail

U.S. Indicts North Korean Hackers in Theft of $200 Million

Krebs on Security

Confirmed thefts attributed to the group include the 2016 hacking of the SWIFT payment system for Bangladesh Bank, which netted thieves $81 million; $6.1 million in August 2020 from a financial services company based in New York. The group is thought to be responsible for the attempted theft of approximately $1.2

article thumbnail

TA505 Group adds new ServHelper Backdoor and FlawedGrace RAT to its arsenal

Security Affairs

“On December 13, 2018, we observed another large ServHelper “downloader” campaign targeting retail and financial services customers.” ” The attacks leveraging the two malware were not targeted in nature attackers aimed at financial services organizations worldwide. . ” concluded Proofpoint.

IT 279
article thumbnail

Microsoft partnered with other security firms to takedown TrickBot botnet

Security Affairs

Trickbot has been active since 2016, at the time the authors of the author designed it to steal banking credentials. Over the years, the threat evolved and its operators implemented a modular structure that allowed them to offer the threat as malware-as-a-service. ” concludes Microsoft.

Security 246
article thumbnail

Profiles in Leadership: Vlad Brodsky

Data Breach Today

OTC Markets CISO on Ransomware, Regulations Affecting the Financial Services Space OTC Markets Group in recent years has gone from having almost sector-specific cybersecurity regulations to highly robust ones, said CISO Vlad Brodsky.

article thumbnail

Emissary Panda updated its weapons for attacks in the past 2 years

Security Affairs

This morning I wrote about a large-scale cyber attack that hit the I nternational Civil Aviation Organization (ICAO) in November 2016, Emissary Panda was suspected to be the culprit. defense contractors , financial services firms, and a national data center in Central Asia.

IT 234