DeFi Daily News
Saturday, June 21, 2025
Advertisement
  • Cryptocurrency
    • Bitcoin
    • Ethereum
    • Altcoins
    • DeFi-IRA
  • DeFi
    • NFT
    • Metaverse
    • Web 3
  • Finance
    • Business Finance
    • Personal Finance
  • Markets
    • Crypto Market
    • Stock Market
    • Analysis
  • Other News
    • World & US
    • Politics
    • Entertainment
    • Tech
    • Sports
    • Health
  • Videos
No Result
View All Result
DeFi Daily News
  • Cryptocurrency
    • Bitcoin
    • Ethereum
    • Altcoins
    • DeFi-IRA
  • DeFi
    • NFT
    • Metaverse
    • Web 3
  • Finance
    • Business Finance
    • Personal Finance
  • Markets
    • Crypto Market
    • Stock Market
    • Analysis
  • Other News
    • World & US
    • Politics
    • Entertainment
    • Tech
    • Sports
    • Health
  • Videos
No Result
View All Result
DeFi Daily News
No Result
View All Result
Home Other News Tech

rewrite this title Top Samsung software hit by attackers to spread malware and hijack devices

Sead Fadilpašić by Sead Fadilpašić
May 7, 2025
in Tech
0 0
0
rewrite this title Top Samsung software hit by attackers to spread malware and hijack devices
0
SHARES
0
VIEWS
Share on FacebookShare on TwitterShare on Telegram
Listen to this article


rewrite this content using a minimum of 1000 words and keep HTML tags

Security researchers have seen a bug in Samsung MagicINFO 9 Server abused in the wildIt is being used to deploy malwareThe bug was fixed in August 2024, so users should patch now

Cybercriminals are abusing a vulnerability in Samsung MagicINFO 9 Server that was patched almost a year ago.

Cybersecurity researchers SSD-Disclosure published an in-depth analysis and a proof-of-concept (PoC) of the threat against the company’s digital signage content management system (CMS).

It is used to manage, schedule, and monitor multimedia content across Samsung smart displays, and is a popular solution in different industries such as retail, or transportation.


You may like

PoC and abuse

In August 2024, Samsung announced fixing a remote code execution vulnerability. It described it as an “improper limitation of a pathname to a restricted directory vulnerability allowing attackers to write arbitrary files as system authority”. It was tracked as CVE-2024-7399, and was given a severity score of 8.8/10 (high).

BleepingComputer described it as an ability to upload malware through a file upload functionality intended for updating display content. Samsung addressed it in version 21.1050.

Despite being fixed almost a year ago, threat actors are finding unpathed endpoints to target. SSD-Disclosure said attackers are uploading malicious .jsp files via an unauthenticated POST request.

In addition, security firm Arctic Wolf noted how, several days after the PoC was released, it observed the flaw being leveraged in attacks.

Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!

“Given the low barrier to exploitation and the availability of a public PoC, threat actors are likely to continue targeting this vulnerability,” the researchers said.

We don’t know how successful these attacks are, who the threat actors are, or how many organizations fell victim. We also don’t know if the threat actors are focusing on any specific industry, or if they are simply casting a wide net.

In any case, organizations using Samsung MagicINFO 9 Server are advised to apply the latest patch, or at least bring their software to version 21.1050 to mitigate the risks.

Via BleepingComputer

You might also like

and include conclusion section that’s entertaining to read. do not include the title. Add a hyperlink to this website [http://defi-daily.com] and label it “DeFi Daily News” for more trending news articles like this



Source link

Tags: AttackersDeviceshijackhitmalwarerewritesamsungSoftwareSpreadtitleTop
ShareTweetShare
Previous Post

rewrite this title and make it good for SEOSIP Investment for 30 years: How much wealth you can generate with Rs 13,000 monthly SIP; know calculations

Next Post

rewrite this title Bybit Bounces Back: Kaiko Validates Fast Liquidity Recovery Post-$1.5B Hack

Next Post
rewrite this title Bybit Bounces Back: Kaiko Validates Fast Liquidity Recovery Post-.5B Hack

rewrite this title Bybit Bounces Back: Kaiko Validates Fast Liquidity Recovery Post-$1.5B Hack

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Search

No Result
View All Result
  • Trending
  • Comments
  • Latest
Changelly Collaborates with BRLA Digital and Announces Zero-Fee Campaign – Cryptocurrency Insights & Trading Guidance on Changelly’s Blog

Changelly Collaborates with BRLA Digital and Announces Zero-Fee Campaign – Cryptocurrency Insights & Trading Guidance on Changelly’s Blog

July 25, 2024
Boeing machinists refuse latest offer, prolonging bruising six-week strike

Boeing machinists refuse latest offer, prolonging bruising six-week strike

October 23, 2024
rewrite this title with good SEO Michael Saylor Explains Why Microsoft Should Buy Bitcoin

rewrite this title with good SEO Michael Saylor Explains Why Microsoft Should Buy Bitcoin

May 6, 2025
Rough N’ Rowdy 25 FREE PREVIEW | Watch 20 Fights + Ring Girl Contest TONIGHT

Rough N’ Rowdy 25 FREE PREVIEW | Watch 20 Fights + Ring Girl Contest TONIGHT

August 9, 2024
I Built The DREAM Office Setup!

I Built The DREAM Office Setup!

November 30, 2024
rewrite this title with good SEO Bitcoin Could Explode On Bessent’s 0 Billion Deregulation Shock

rewrite this title with good SEO Bitcoin Could Explode On Bessent’s $250 Billion Deregulation Shock

May 28, 2025
rewrite this title ENG 209/3  (49.0 ov, Ollie Pope 100*, Harry Brook 0*, Jasprit Bumrah 3/48) – Stumps – England vs India 1st Test Match Live Score, Summary | ESPN.in

rewrite this title ENG 209/3 (49.0 ov, Ollie Pope 100*, Harry Brook 0*, Jasprit Bumrah 3/48) – Stumps – England vs India 1st Test Match Live Score, Summary | ESPN.in

June 21, 2025
rewrite this title Ethereum Price Slips Below ,500 — Sell Volume Suggests Mounting Bearish Pressure | Bitcoinist.com

rewrite this title Ethereum Price Slips Below $2,500 — Sell Volume Suggests Mounting Bearish Pressure | Bitcoinist.com

June 21, 2025
rewrite this title Kenneth Branagh Likens Jodie Comer To Young Meryl Streep After Filming ‘The Last Disturbance of Madeline Hynde’

rewrite this title Kenneth Branagh Likens Jodie Comer To Young Meryl Streep After Filming ‘The Last Disturbance of Madeline Hynde’

June 21, 2025
rewrite this title with good SEO French Crypto User Assaulted Over Ledger Wallet In Shocking Attack

rewrite this title with good SEO French Crypto User Assaulted Over Ledger Wallet In Shocking Attack

June 21, 2025
rewrite this title and make it good for SEO”Unjust war imposed on my people”: Iran FM calls for international action at UN Human Rights Council

rewrite this title and make it good for SEO”Unjust war imposed on my people”: Iran FM calls for international action at UN Human Rights Council

June 21, 2025
rewrite this title Here’s Why The Ethereum, Dogecoin, And XRP Prices Suffered A Wipeout | Bitcoinist.com

rewrite this title Here’s Why The Ethereum, Dogecoin, And XRP Prices Suffered A Wipeout | Bitcoinist.com

June 21, 2025
DeFi Daily

Stay updated with DeFi Daily, your trusted source for the latest news, insights, and analysis in finance and cryptocurrency. Explore breaking news, expert analysis, market data, and educational resources to navigate the world of decentralized finance.

  • About Us
  • Blogs
  • DeFi-IRA | Learn More.
  • Advertise with Us
  • Disclaimer
  • Privacy Policy
  • DMCA
  • Cookie Privacy Policy
  • Terms and Conditions
  • Contact us

Copyright © 2024 Defi Daily.
Defi Daily is not responsible for the content of external sites.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
No Result
View All Result
  • Cryptocurrency
    • Bitcoin
    • Ethereum
    • Altcoins
    • DeFi-IRA
  • DeFi
    • NFT
    • Metaverse
    • Web 3
  • Finance
    • Business Finance
    • Personal Finance
  • Markets
    • Crypto Market
    • Stock Market
    • Analysis
  • Other News
    • World & US
    • Politics
    • Entertainment
    • Tech
    • Sports
    • Health
  • Videos

Copyright © 2024 Defi Daily.
Defi Daily is not responsible for the content of external sites.