Cyberthreats for the week of 2019-04-08 to 2019-04-15

High Risk Vulnerabilities

Published Summary CVE Number
2019-04-08 18:29

In Apache HTTP Server 2.4 releases 2.4.17 to 2.4.38, with MPM event, worker or prefork, code executing in less-privileged child processes or threads (including scripts executed by an in-process scripting interpreter) could execute arbitrary code with the privileges of the parent process (usually root) by manipulating the scoreboard. Non-Unix systems are not affected.

Risk Score: 7.2

2019-04-09 17:29

An elevation of privilege vulnerability exists when Windows AppX Deployment Service (AppXSVC) improperly handles hard links, aka 'Windows Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-0730, CVE-2019-0731, CVE-2019-0796, CVE-2019-0805, CVE-2019-0836.

Risk Score: 7.2

2019-04-09 18:29

GlobalProtect Agent 4.1.0 for Windows and GlobalProtect Agent 4.1.10 and earlier for macOS may allow an attacker to access authentication and/or session tokens and replay them to spoof the VPN session and gain access as the user.

Risk Score: 7.5


Cybersecurity Breaches

Published Organization Details
2019-04-08 Knuddels

In September 2018, the German social media website [Knuddels suffered a data breach][1]. The incident exposed 808k unique email addresses alongside usernames, real names, the city of the person and their password in plain text. Knuddels was [subsequently fined €20k for the breach][2]. [1]:… [2]:… Data Leaked: Email addresses, Geographic locations, Names, Passwords, Usernames Domain:

Source: Have I Been Pwned?

2019-04-09 DataCamp

In December 2018, the data science website [DataCamp suffered a data breach][1] of records dating back to January 2017. The incident exposed 760k unique email and IP addresses along with names and passwords stored as bcrypt hashes. In 2019, [the data appeared listed for sale on a dark web marketplace][2] (along with several other large breaches) and subsequently began circulating more broadly. The data was provided to HIBP by a source who requested it to be attributed to "". [1]:… [2]:… Data Leaked: Email addresses, Geographic locations, IP addresses, Names, Passwords Domain:

Important Cybersecurity News

The Hacker News1 day ago by (Swati Khandelwal)

Hackers Compromise Microsoft Support Agent to Access Outlook Email Accounts

If you have an account with Microsoft Outlook email service, there is a possibility that your account information has been compromised by an unknown hacker or group of hackers, Microsoft confirmed The Hacker News. Earlier this year, hackers managed to breach Microsoft's customer support portal and ...

The Hacker News3 days ago by (Mohit Kumar)

WikiLeaks Founder Julian Assange Arrested After Ecuador Withdraws Asylum

WikiLeaks founder Julian Assange has been arrested at the Ecuadorian Embassy in London—that's almost seven years after he took refuge in the embassy to avoid extradition to Sweden over a sexual assault case. According to a short note released by London's Metropolitan Police Service, Assange was arr...