21 Dec Zerobot malware now spreads by exploiting Apache vulnerabilities The Zerobot botnet has been upgraded to infect new devices by exploiting security vulnerabilities affecting Internet-exposed and unpatched Apache servers. […]
21 Dec FCC proposes record-breaking $300 million fine against robocaller The U.S. Federal Communications Commission proposed today a record-breaking $300 million fine against an auto warranty robocall operation that made billions of calls to more than 550 million phones across the United States. […]
21 Dec Russians hacked JFK airport’s taxi dispatch system for profit Two U.S. citizens were arrested for allegedly conspiring with Russian hackers to hack the John F. Kennedy International Airport (JFK) taxi dispatch system to move specific taxis to the front of the queue in exchange for a $10 fee. […]
21 Dec Okta says its GitHub account hacked, source code stolen In a ‘confidential’ email notification sent by Okta and seen by BleepingComputer, the company states that attackers gained access to its GitHub repositories this month and stole the company’s source code. […]
20 Dec Microsoft pushes emergency fix for Windows Server Hyper-V VM issues Microsoft has released emergency out-of-band (OOB) Windows Server updates to address a known issue breaking virtual machine (VM) creation on Hyper-V hosts after installing this month’s Patch Tuesday updates. […]
20 Dec Ransomware gang uses new Microsoft Exchange exploit to breach servers Play ransomware threat actors are using a new exploit chain that bypasses ProxyNotShell URL rewrite mitigations to gain remote code execution (RCE) on vulnerable servers through Outlook Web Access (OWA). […]
20 Dec VirusTotal cheat sheet makes it easy to search for specific results VirusTotal has published a cheat sheet to help researchers create queries leading to more specific results from the malware intelligence platform. […]
20 Dec Microsoft will turn off Exchange Online basic auth in January Microsoft warned today that it will permanently turn off Exchange Online basic authentication starting early January 2023 to improve security. […]
19 Dec Play ransomware claims attack on German hotel chain H-Hotels The Play ransomware gang has claimed responsibility for a cyber attack on H-Hotels (h-hotels.com) that has resulted in communication outages for the company. […]
19 Dec Microsoft finds macOS bug that lets malware bypass security checks Apple has fixed a vulnerability that could be leveraged to deploy malware on vulnerable macOS devices via untrusted applications capable of bypassing Gatekeeper application execution restrictions. […]