ScanForge Security Digest 2617-02

ScanForge Security Digest 2617-02

200 items
0 critical0 high10 news

This week presented a favorable threat landscape with no actively exploited vulnerabilities or critical CVEs reported, though elevated activity levels warrant attention. Key concerns include a new BlackFile extortion group orchestrating vishing campaigns, a critical Linux privilege escalation flaw (Pack2TheRoot), and a sophisticated FIRESTARTER backdoor targeting Cisco Firepower devices that persists through patching. Organizations should prioritize deploying available patches for the Pack2TheRoot vulnerability and implementing enhanced email and voice authentication controls to counter the vishing threat. Microsoft's upcoming passkey support in Windows offers a strategic opportunity to strengthen credential security across enterprise environments. Continue monitoring for indicators of compromise related to FIRESTARTER and maintain heightened vigilance around social engineering vectors targeting your user base.

Security News

10
New BlackFile extortion group linked to surge of vishing attacks Bleeping Computer

A new financially motivated hacking group tracked as BlackFile has been linked to a wave of data theft and extortion att

Microsoft to roll out Entra passkeys on Windows in late April Bleeping Computer

Microsoft will roll out passkey support for phishing-resistant passwordless authentication to Microsoft Entra‑protected

New ‘Pack2TheRoot’ flaw gives hackers root Linux access Bleeping Computer

A new vulnerability dubbed Pack2TheRoot could be exploited in the PackageKit daemon to allow local Linux users to instal

FIRESTARTER Backdoor Hit Federal Cisco Firepower Device, Survives Security Patches The Hacker News

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has revealed that an unnamed federal civilian agency's

US Busts Myanmar Ring Targeting US Citizens in Financial Fraud Dark Reading

Some 29 people were charged, including a Cambodian senator, and authorities seized more than 500 Web domains tied to fak

Glasswing Secured the Code. The Rest of Your Stack Is Still on You Dark Reading

Forgotten integrations, shadow IT, SaaS, and now shadow AI and agents are everywhere, and attackers don't need sophistic

Pre-Stuxnet Sabotage Malware ‘Fast16’ Linked to US-Iran Cyber Tensions SecurityWeek

It targeted high-precision calculation software to tamper with results and packed a self-propagation mechanism. The post

In Other News: Unauthorized Mythos Access, Plankey CISA Nomination Ends, New Display Security Device SecurityWeek

Other noteworthy stories that might have slipped under the radar: Supreme Court hacker sentenced, Lovable exposed user d

Exploits & Threats

3

Content aggregated from NIST/NVD, CISA, CERT/CC, and public security news sources. External articles are linked to their original source.