27 Mar New Android malware spies on you while posing as a System Update New malware with extensive spyware capabilities steals data from infected Android devices and is designed to automatically trigger whenever new info is read to be exfiltrated. […]
26 Mar The Week in Ransomware – March 26th 2021 – Attacks increase Ransomware attacks against the enterprise continue in the form of Accellion data leaks, full-fledged ransomware attacks, and more ransomware gangs targeting Microsoft Exchange. […]
26 Mar German Parliament targeted again by Russian state hackers Email accounts of multiple German Parliament members were targeted in a spearphishing attack. It is not yet known if any data was stolen during the incident. […]
26 Mar Apple fixes iOS zero-day vulnerability exploited in the wild Apple has released security updates today to address an iOS zero-day bug actively exploited in the wild and affecting iPhone, iPad, iPod, and Apple Watch devices. […]
26 Mar Microsoft: Black Kingdom ransomware hacked 1.5K Exchange servers Microsoft has discovered web shells deployed by Black Kingdom operators on approximately 1,500 Exchange servers vulnerable to ProxyLogon attacks. […]
26 Mar Microsoft releases Windows 10 SSU to fix security update issue Microsoft has released the Windows 10 1909 KB5000850 cumulative update preview and a new KB5001205 Servicing Stack Update that resolves a Secure Boot vulnerability. […]
26 Mar SolarWinds patches critical code execution bug in Orion Platform SolarWinds has released security updates to address four vulnerabilities impacting the company’s Orion IT monitoring platform, two o them allowing remote attackers to execute arbitrary code following exploitation. […]
25 Mar Insurance giant CNA hit by new Phoenix CryptoLocker ransomware Insurance giant CNA has suffered a ransomware attack using a new variant called Phoenix CryptoLocker that is possibly linked to the Evil Corp hacking group. […]
25 Mar Evil Corp switches to Hades ransomware to evade sanctions Hades ransomware has been linked to the Evil Corp cybercrime gang who uses it to evade sanctions imposed by the Treasury Department’s Office of Foreign Assets Control (OFAC). […]
25 Mar OpenSSL fixes severe DoS, certificate validation vulnerabilities OpenSSL has patched two high severity vulnerabilities. These include a Denial of Service (DoS) vulnerability (CVE-2021-3449) and an improper CA certificate validation issue (CVE-2021-3450). […]