Boston Scientific says cyberattack disrupted operations globally

Boston Scientific Fights to Recover from Global Cyberattack Disruption Medical technology giant Boston Scientific is reeling from a devastating cyberattack that has crippled its IT systems worldwide. The attack, which was detected on August 25, has caused operational disruptions globally, including the inability to process and ship customer orders. The company’s systems are used in … Read more

Unpatched Kaltura mwEmbed Flaws Could Let Remote Attackers Read Files and Run Code

A newly discovered vulnerability in Kaltura’s mwEmbed plugin has left hundreds of thousands of websites vulnerable to remote attacks, allowing attackers to read sensitive files and execute arbitrary code. The unpatched flaw, disclosed on Wednesday, affects all versions of the plugin, making it a pressing concern for organizations that rely on the popular video management … Read more

CISA Red Team Compromised Two Critical Infrastructure Orgs, One Detected Nothing

Cybersecurity’s Dark Mirror: CISA Red Team Compromises Two Critical Infrastructure Orgs, Exposing Deep Vulnerabilities The US Cybersecurity and Infrastructure Security Agency (CISA) has revealed a disturbing incident that highlights the vulnerabilities of even the most secure systems. In an internal exercise, the CISA Red Team successfully compromised two critical infrastructure organizations, with one organization remaining … Read more

NovaCookies Campaigns Abuse Genuine Docusign Notifications to Steal Microsoft 365 Sessions

A sophisticated cyber campaign, dubbed “NovaCookies,” has been uncovered, leveraging genuine DocuSign notifications to steal Microsoft 365 session credentials. The attacks, which have been ongoing for months, target organizations with a high volume of DocuSign usage, allowing hackers to phish employees and gain unauthorized access to sensitive data. At the heart of the NovaCookies campaign … Read more

Hackers target Microsoft SharePoint RCE chain with PoC exploit

Cybersecurity Threats Rampant as Hackers Target Microsoft SharePoint Servers Threat actors are exploiting a pair of vulnerabilities in Microsoft’s SharePoint platform, allowing them to execute arbitrary code on unpatched servers. The chain of attacks involves a vulnerability in the JWT token validation pipeline, which can be exploited by attackers without privileges, and a subsequent remote … Read more

Boston Scientific says cyberattack disrupted operations globally

Boston Scientific Hit by Global Cyberattack, Disrupting Operations and Customer Orders Medical technology giant Boston Scientific has been caught in a global cyberattack that has caused operational disruptions and impacted access to critical systems. The company, which develops and manufactures devices used in minimally invasive procedures, detected the incident on August 25 and is still … Read more

Unpatched Kaltura mwEmbed Flaws Could Let Remote Attackers Read Files and Run Code

A critical vulnerability in Kaltura’s mwEmbed software has been discovered, allowing remote attackers to read sensitive files and execute malicious code on affected systems. The unpatched flaw affects various industries, including media, education, and healthcare, where Kaltura’s video streaming platform is widely used. Kaltura’s mwEmbed is a JavaScript library that enables cross-domain communication between web … Read more

CISA Red Team Compromised Two Critical Infrastructure Orgs, One Detected Nothing

Critical Infrastructure Orgs Left Exposed After CISA Red Team Simulation Breaches The Cybersecurity and Infrastructure Security Agency (CISA) has revealed that its red team, a group tasked with testing an organization’s defenses, successfully breached two critical infrastructure organizations in recent simulations. What’s more alarming is that one of the companies failed to detect the intrusion … Read more

NovaCookies Campaigns Abuse Genuine Docusign Notifications to Steal Microsoft 365 Sessions

A sophisticated cyber campaign, dubbed NovaCookies, has been exploiting genuine DocuSign notifications to hijack Microsoft 365 sessions and steal sensitive user data. The attack’s clever use of phishing tactics and exploitation of legitimate authentication mechanisms has left security experts sounding alarm bells. At its core, the NovaCookies campaign relies on social engineering, where attackers send … Read more