Monday 7th October 2024

Monday 7th October 2024

Good morning! A very happy Monday and thank you for joining me for today's edition of Cyber Daily. Apple’s is working hard fixing bugs faster than we can say “CVE,” Comcast is dealing with a ransomware mess that even their debt collectors couldn’t see coming. And if you run a WordPress site, now’s a great time to double-check your LiteSpeed Cache plugin settings, or you might give hackers a VIP pass to your admin account. Enjoy!


Apple’s quick patch for security bugs

Apple just rolled out iOS and iPadOS updates to fix two serious security flaws. One of the vulnerabilities, CVE-2024-44204, involved a logic issue in the Passwords app that allowed the VoiceOver assistive technology to read users’ saved passwords aloud. Apple credits security researcher Bistrit Daha for catching the bug, which affected a range of iPhones and iPads. Fortunately, the glitch has been squashed with improved validation.

The second issue (CVE-2024-44207) was specific to the new iPhone 16 models, where audio could be captured for a few seconds before the microphone indicator turned on. The flaw was found in the Media Session component and was reported by Michael Jimenez and an anonymous source. Apple has since applied more stringent checks to fix the problem.

To stay protected, users should update to iOS 18.0.1 and iPadOS 18.0.1 ASAP.

Comcast’s customer data stolen in debt collector breach

Comcast is alerting nearly 238,000 customers that their personal data was stolen in a February cyberattack on Financial Business and Consumer Solutions (FBCS), a debt collection agency. This comes after initial assurances from FBCS that Comcast's data was safe. The breach was later confirmed in July, revealing that sensitive information such as names, addresses, Social Security numbers, and Comcast account details had been compromised.

FBCS was hit by a ransomware attack where the intruders both downloaded data and encrypted parts of its systems. Despite the breach happening on FBCS's end, Comcast is covering identity protection services, as FBCS claimed it couldn’t afford to do so.

This isn’t the first high-profile breach for Comcast, but the company has clarified that its own systems, including Xfinity, were not affected. Users impacted are advised to monitor their accounts for suspicious activity.

To date, over 4 million people have been affected by FBCS’s data breach.

WordPress LiteSpeed Cache plugin hit by severe security flaw

A high-severity vulnerability (CVE-2024-47374) has been discovered in the LiteSpeed Cache plugin for WordPress, which could allow attackers to execute arbitrary JavaScript code. The plugin, with over six million active installations, is a popular tool for site acceleration and optimization, making this a critical issue for WordPress admins.

The flaw is a stored cross-site scripting (XSS) vulnerability impacting versions up to 6.5.0.2 and was discovered by TaiYou through Patchstack's bug bounty program. It arises from improper sanitization of the “X-LSCACHE-VARY-VALUE” HTTP header, which could allow attackers to inject scripts if the “CSS Combine” and “Generate UCSS” settings are enabled.

An attacker could exploit this to hijack the account of a site administrator, gaining full control over the website. The issue was patched in version 6.5.1, released on September 25, 2024.

Admins should update immediately to avoid potential site takeovers.



Jan Kübler

CEO of WORLDFIELD REAL ESTATE and WORLDFIELD INVESTMENT?HOLDING Dubai, UAE ???? multiple IRONMAN Finisher

5 个月

That's important! It's good to see Apple addressing these security vulnerabilities.

Nitin Dhiman

CEO @ NextPage IT Solutions ? Scaling Businesses Using Tailored IT Services in 90 Days ? $20M in Client Revenue ? Business Automation

5 个月

Apple is also launching some amazing products in October. It'd be great to see what innovation Apple will bring to the table :) Aidan Dickenson

要查看或添加评论,请登录

Aidan Dickenson的更多文章

  • Monday 24th March 2025

    Monday 24th March 2025

    Good morning and happy Monday. You know things are getting spicy in cybersecurity when GitHub Actions turn malicious…

  • Saturday 22nd March 2025

    Saturday 22nd March 2025

    Good morning. If you’ve ever dreamed of going back to a paper-only workday, just ask the Virginia Attorney General’s…

    1 条评论
  • Friday 21st March 2025

    Friday 21st March 2025

    Morning everyone and a happy Friday to you all! Today we're looking at hackers who are now deploying Betruger, a…

  • Thursday 20th February 2025

    Thursday 20th February 2025

    Good morning. If you thought your VPN was keeping you safe, your gaming accounts were secure, and WhatsApp was just for…

  • Wednesday 19th March 2025

    Wednesday 19th March 2025

    Good morning everyone and a very happy Wednesday to you all. Hackers are getting creative—and potentially desperate.

  • Friday 14th March 2025

    Friday 14th March 2025

    Good morning, happy Friday! If your cybersecurity team is looking extra stressed today, blame AI and ransomware gangs…

  • Thursday 13th March 2025

    Thursday 13th March 2025

    Good morning thank you for joining me for the latest instalment of Cyber Daily. If you thought your biggest tech…

  • Wednesday 12th March 2025

    Wednesday 12th March 2025

    Good morning everyone, happy Hump Day! Today we're focusing on a new botnet called Ballista that is running wild on…

  • Tuesday 11th March 2025

    Tuesday 11th March 2025

    Good morning! If you’ve ever wished you could report cybersecurity incidents as easily as you report bad drivers on the…

    2 条评论
  • Monday 10th March 2025

    Monday 10th March 2025

    Good morning everyone and a very happy Monday to you all. Today's edition is looking in to: ESP32 chips used in…

社区洞察

其他会员也浏览了