23 Dec AvosLocker ransomware reboots in Safe Mode to bypass security tools Recent AvosLocker ransomware attacks are characterized by a focus on disabling endpoint security solutions that stand in the way of threat actors. […]
23 Dec Pro Wrestling Tees discloses data breach after credit cards stolen Popular wrestling t-shirt site Pro Wrestling Tees has disclosed a data breach incident that has resulted in the compromise of the financial details of tens of thousands of its customers. […]
23 Dec VK introduces 2FA and plans to make it mandatory in 2022 VK, Russia’s most popular social media platform with 650 million users, is finally introducing two-factor authentication on all its services and plans to make it mandatory in February 2022 for administrators of large communities. […]
22 Dec Honeypot experiment reveals what hackers want from IoT devices A three-year-long honeypot experiment featuring simulated low-interaction IoT devices of various types and locations gives a clear idea of why actors target specific devices. […]
22 Dec ‘Hack DHS’ bug bounty program expands to Log4j security flaws The Department of Homeland Security (DHS) has announced that the ‘Hack DHS’ program is now also open to bug bounty hunters willing to track down DHS systems impacted by Log4j vulnerabilities. […]
22 Dec Rideshare account hacker faces up to 22 years in prison A man pleaded guilty to fraudulently opening rideshare and delivery service accounts using stolen identity information sold on dark web marketplaces. […]
22 Dec Microsoft Azure App Service flaw exposed customer source code A security flaw found in Azure App Service, a Microsoft-managed platform for building and hosting web apps, led to the exposure of PHP, Node, Python, Ruby, or Java customer source code for at least four years, since 2017. […]
22 Dec Opera browser working on clipboard anti-hijacking feature The Opera browser team is working on a new clipboard monitoring and protection system called Paste Protection, which aims to prevent content hijacking and snooping. […]
22 Dec Microsoft Teams bug allowing phishing unpatched since March Microsoft said it won’t fix or is delaying patches for several security flaws impacting Microsoft Teams’ link preview feature reported since March 2021. […]
21 Dec 2easy now a significant dark web marketplace for stolen data A dark web marketplace named ‘2easy’ is becoming a significant player in the sale of stolen data “Logs” harvested from roughly 600,000 devices infected with information-stealing malware. […]