<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Data Breach &#8211; DEVOQ Technology</title>
	<atom:link href="https://www.devoq.gr/tag/data-breach/feed/" rel="self" type="application/rss+xml" />
	<link>https://www.devoq.gr</link>
	<description></description>
	<lastBuildDate>Sat, 21 Jun 2025 12:33:39 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=7.0</generator>

<image>
	<url>https://i0.wp.com/www.devoq.gr/wp-content/uploads/2018/07/cropped-logo_ico.png?fit=32%2C32&#038;ssl=1</url>
	<title>Data Breach &#8211; DEVOQ Technology</title>
	<link>https://www.devoq.gr</link>
	<width>32</width>
	<height>32</height>
</image> 
<site xmlns="com-wordpress:feed-additions:1">192885280</site>	<item>
		<title>Threat Advisory – November 22-28</title>
		<link>https://www.devoq.gr/2022/02/24/threat-advisory-november-22-28/</link>
					<comments>https://www.devoq.gr/2022/02/24/threat-advisory-november-22-28/#respond</comments>
		
		<dc:creator><![CDATA[DEVOQ Technology]]></dc:creator>
		<pubDate>Thu, 24 Feb 2022 14:04:56 +0000</pubDate>
				<category><![CDATA[News]]></category>
		<category><![CDATA[CYSEC NEWS]]></category>
		<category><![CDATA[Data Breach]]></category>
		<category><![CDATA[DEVOQ Technology]]></category>
		<category><![CDATA[devoq.gr]]></category>
		<category><![CDATA[DoS]]></category>
		<category><![CDATA[KB5007205]]></category>
		<category><![CDATA[security vulnerabilities]]></category>
		<category><![CDATA[Threat Advisory]]></category>
		<category><![CDATA[vulnerability]]></category>
		<category><![CDATA[zero-day vulnerability]]></category>
		<guid isPermaLink="false">https://devoq.gr/?p=11114849</guid>

					<description><![CDATA[CYSEC NEWS Tracked as CVE-2021-41379 and discovered by security researcher Abdelhamid Naceri, the elevation of privilege flaw affecting the Windows Installer software component was originally resolved as part of Microsoft&#8217;s Patch Tuesday updates for November 2021 However, in what&#8217;s a case of an insufficient patch, Naceri found that it was not only possible to bypass[...]]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph"></p>



<p class="wp-block-paragraph"><strong>CYSEC NEWS</strong></p>



<p class="wp-block-paragraph"></p>



<figure class="wp-block-image size-large"><img data-recalc-dims="1" fetchpriority="high" decoding="async" width="1020" height="652" src="https://i0.wp.com/devoq.gr/wp-content/uploads/2022/02/Screenshot_4-1024x655.png?resize=1020%2C652&#038;ssl=1" alt="" class="wp-image-11114837" srcset="https://i0.wp.com/www.devoq.gr/wp-content/uploads/2022/02/Screenshot_4.png?resize=1024%2C655&amp;ssl=1 1024w, https://i0.wp.com/www.devoq.gr/wp-content/uploads/2022/02/Screenshot_4.png?resize=300%2C192&amp;ssl=1 300w, https://i0.wp.com/www.devoq.gr/wp-content/uploads/2022/02/Screenshot_4.png?resize=768%2C491&amp;ssl=1 768w, https://i0.wp.com/www.devoq.gr/wp-content/uploads/2022/02/Screenshot_4.png?resize=1%2C1&amp;ssl=1 1w, https://i0.wp.com/www.devoq.gr/wp-content/uploads/2022/02/Screenshot_4.png?resize=10%2C6&amp;ssl=1 10w, https://i0.wp.com/www.devoq.gr/wp-content/uploads/2022/02/Screenshot_4.png?w=1228&amp;ssl=1 1228w" sizes="(max-width: 1020px) 100vw, 1020px" /></figure>



<p class="has-black-color has-text-color has-link-color wp-elements-02ca254bf35c25190275ad0f75689dc1 wp-block-paragraph"><br>Tracked as CVE-2021-41379 and discovered by security researcher Abdelhamid Naceri, the elevation of privilege flaw affecting the Windows Installer software component was originally resolved as part of Microsoft&#8217;s Patch Tuesday updates for November 2021 However, in what&#8217;s a case of an insufficient patch, Naceri found that it was not only possible to bypass the fix implemented by Microsoft but also achieve local privilege escalation via a newly discovered zero-day bug.</p>



<p class="wp-block-paragraph"><br><strong>Reference</strong>: <a href="https://thehackernews.com/2021/11/warning-hackers-exploiting-new-windows.html" target="_blank" rel="noreferrer noopener">https://thehackernews.com/2021/11/warning-hackers-exploiting-new-windows.html</a></p>



<hr class="wp-block-separator has-css-opacity is-style-dots"/>



<p class="wp-block-paragraph">Web hosting giant <strong>GoDaddy </strong>on Monday disclosed a data breach that resulted in the unauthorized access of data belonging to a total of 1.2 million active and inactive customers, making it the third security incident to come to light since 2018.</p>



<p class="wp-block-paragraph"><br><strong>Reference</strong>: <a href="https://thehackernews.com/2021/11/godaddy-data-breach-exposes-over-1.html" target="_blank" rel="noreferrer noopener">https://thehackernews.com/2021/11/godaddy-data-breach-exposes-over-1.html</a></p>



<hr class="wp-block-separator has-css-opacity is-style-dots"/>



<p class="wp-block-paragraph">VMware has shipped updates to address two security vulnerabilities in vCenter Server and Cloud Foundation that could be abused by a remote attacker to gain access to sensitive information. The more severe of the issues concerns an arbitrary file read vulnerability in the vSphere Web Client. Tracked as CVE-2021-21980, the bug has been rated 7.5 out of a maximum of 10 on the CVSS scoring system, and impacts vCenter Server versions 6.5 and 6.7 &#8220;A malicious actor with network access to port 443 on vCenter Server may exploit this issue to gain access to sensitive information,&#8221; the company noted in an advisory published on November 23, crediting ch0wn of Orz lab for reporting the flaw.</p>



<p class="wp-block-paragraph"><br><strong>Reference</strong>: <a href="https://thehackernews.com/2021/11/vmware-warns-of-newly-discovered.html" target="_blank" rel="noreferrer noopener">https://thehackernews.com/2021/11/vmware-warns-of-newly-discovered.html</a></p>



<hr class="wp-block-separator has-css-opacity is-style-dots"/>



<p class="wp-block-paragraph">At least 9.3 million Android devices have been infected by a new class of malware that disguises itself as dozens of arcade, shooter, and strategy games on <strong>Huawei&#8217;s AppGallery</strong> marketplace to steal device information and victims&#8217; mobile phone numbers.</p>



<p class="wp-block-paragraph"><br><strong>Reference</strong>: <a href="https://thehackernews.com/2021/11/over-9-million-android-phones-running.html" target="_blank" rel="noreferrer noopener">https://thehackernews.com/2021/11/over-9-million-android-phones-running.html</a></p>



<hr class="wp-block-separator has-css-opacity is-style-dots"/>



<p class="wp-block-paragraph">A now-patched vulnerability affecting <strong>Oracle VM VirtualBox</strong> could be potentially exploited by an adversary to compromise the hypervisor and cause a denial-of-service (DoS) condition.</p>



<p class="wp-block-paragraph"><br><strong>Reference</strong>: <a href="https://thehackernews.com/2021/11/researchers-detail-privilege-escalation.html" target="_blank" rel="noreferrer noopener">https://thehackernews.com/2021/11/researchers-detail-privilege-escalation.html</a></p>



<hr class="wp-block-separator has-css-opacity is-style-dots"/>



<p class="wp-block-paragraph">Security researchers have discovered a new remote access trojan (RAT) for Linux that keeps an almost invisible profile by hiding in tasks scheduled for execution on a non-existent day, February 31st. “The CronRAT adds a number of tasks to crontab with a curious date specification: 52 23 31 2 3. These lines are syntactically valid, but would generate a run time error when executed. However, this will never happen as they are scheduled to run on February 31st,” Sansec Researchers explain.</p>



<p class="wp-block-paragraph"><strong>Reference</strong>: <a href="https://www.bleepingcomputer.com/news/security/new-linux-malware-hides-in-cron-jobs-with-invalid-dates/" target="_blank" rel="noreferrer noopener">https://www.bleepingcomputer.com/news/security/new-linux-malware-hides-in-cron-jobs-with-invalid-dates/</a></p>



<hr class="wp-block-separator has-css-opacity is-style-dots"/>



<p class="wp-block-paragraph">Threat actors have recently begun to compromise internal Microsoft Exchange servers using the <strong>ProxyShell </strong>and <strong>ProxyLogin</strong> vulnerabilities to perform phishing attacks. Once they gain access to a server, they use the internal Microsoft Exchange servers to perform reply-chain attacks against employees using stolen corporate emails.</p>



<p class="wp-block-paragraph"><br><strong>Reference</strong>: <a href="https://www.bleepingcomputer.com/news/security/ikea-email-systems-hit-by-ongoing-cyberattack/" target="_blank" rel="noreferrer noopener">https://www.bleepingcomputer.com/news/security/ikea-email-systems-hit-by-ongoing-cyberattack/</a></p>



<hr class="wp-block-separator has-css-opacity is-style-dots"/>



<p class="wp-block-paragraph">Free unofficial patches have been released to protect Windows users from a local privilege escalation (LPE) zero-day vulnerability in the Mobile Device Management Service impacting Windows 10, version 1809 and later. The security flaw resides under the &#8220;Access work or school&#8221; settings, and it bypasses a patch released by Microsoft in February to address an information disclosure bug tracked as CVE-2021-24084.</p>



<p class="wp-block-paragraph"><br><strong>Reference</strong>: <a href="https://www.bleepingcomputer.com/news/security/new-windows-10-zero-day-gives-admin-rights-gets-unofficial-patch/" target="_blank" rel="noreferrer noopener">https://www.bleepingcomputer.com/news/security/new-windows-10-zero-day-gives-admin-rights-gets-unofficial-patch/</a></p>



<hr class="wp-block-separator has-css-opacity is-style-dots"/>



<p class="wp-block-paragraph">Microsoft has confirmed a new issue impacting Windows Server devices preventing the Microsoft Defender for Endpoint security solution from launching on some systems. The enterprise endpoint security platform (previously known as Microsoft Defender Advanced Threat Protection or Defender ATP) might fail to start or run on devices with a Windows Server Core installation. The known issue only impacts devices where customers have installed KB5007206 or later updates on Windows Server 2019 and KB5007205 or later updates on Windows Server 2022.</p>



<p class="wp-block-paragraph"><br><strong>Reference</strong>: <a href="https://www.bleepingcomputer.com/news/microsoft/microsoft-defender-for-endpoint-fails-to-start-on-windows-server/" target="_blank" rel="noreferrer noopener">https://www.bleepingcomputer.com/news/microsoft/microsoft-defender-for-endpoint-fails-to-start-on-windows-server/</a></p>



<hr class="wp-block-separator has-css-opacity is-style-dots"/>



<p class="wp-block-paragraph">Microsoft describes Super Duper Secure Mode as &#8220;a browsing mode in Microsoft Edge where the security of your browser takes priority, providing you an extra layer of protection when browsing the web.&#8221; &#8220;We quietly released Super Duper Secure Mode to stable (96.0.1054.29),&#8221; said Johnathan Norman, Microsoft Edge Vulnerability Research Lead.</p>



<p class="wp-block-paragraph"><br><strong>Reference</strong>: <a href="https://www.bleepingcomputer.com/news/microsoft/microsoft-edge-adds-super-duper-secure-mode-to-stable-channel/" target="_blank" rel="noreferrer noopener">https://www.bleepingcomputer.com/news/microsoft/microsoft-edge-adds-super-duper-secure-mode-to-stable-channel/</a></p>



<hr class="wp-block-separator has-css-opacity is-style-dots"/>



<p class="wp-block-paragraph"><strong>HAVE ANY QUESTIONS?</strong><br>Do not hesitate to contact us!</p>



<p class="wp-block-paragraph">Address: Mesogeion Ave. 41, 11524 Athens, Greece<br>Phone: (+30) 211 800 5 800<br>Email: info@devoq.gr<br>Website: <a rel="noreferrer noopener" href="http://www.devoq.gr" target="_blank">www.devoq.gr</a></p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.devoq.gr/2022/02/24/threat-advisory-november-22-28/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">11114849</post-id>	</item>
	</channel>
</rss>
