THE Security Affairs newsletter Round 586, authored by Pierluigi Paganini, highlights notable cybersecurity issues and updates from the past week. Key points include:
- OpenSSL fixed a memory exhaustion bug.
- A longstanding malware, Daxin, linked to China, was discovered still active on a manufacturer's network.
- U.S. CISA added multiple flaws from Fortinet and Microsoft to its Known Exploited Vulnerabilities catalog.
- Ernst & Young is investigating a data breach involving third-party support tickets.
- A cyberattack affected Nichirei, a major Japanese food company.
- New Russian cyber campaigns are employing fake software installers to deploy malware.
- Two members of the Scattered Spider group received prison sentences for a significant cyberattack in the UK.
- The newsletter also covers various other cyber incidents, including ransomware attacks and ongoing exploits targeting content management systems.