09 Jan Auth0 fixes RCE flaw in JsonWebToken library used by 22,000 projects Auth0 fixed a remote code execution vulnerability in the immensely popular ‘JsonWebToken’ open-source library used by over 22,000 projects and downloaded over 36 million times per month on NPM. […]
09 Jan Fake OnlyFans dating sites abuse UK Environment Agency open redirect Threat actors abused an open redirect on the official website of the United Kingdom’s Department for Environment, Food & Rural Affairs (DEFRA) to direct visitors to fake OnlyFans adult dating sites. […]
08 Jan Microsoft ends Windows 7 extended security updates on Tuesday Windows 7 Professional and Enterprise editions will no longer receive extended security updates for critical and important vulnerabilities starting Tuesday, January 10, 2023. […]
08 Jan Hackers push fake Pokemon NFT game to take over Windows devices Threat actors are using a well-crafted Pokemon NFT card game website to distribute the NetSupport remote access tool and take control over victims’ devices. […]
07 Jan Malicious PyPi packages create CloudFlare Tunnels to bypass firewalls Six malicious packages on PyPI, the Python Package Index, were found installing information-stealing and RAT (remote access trojan) malware while using Cloudflare Tunnel to bypass firewall restrictions for remote access. […]
06 Jan The Week in Ransomware – January 6th 2023 – Targeting Healthcare This week saw a lot of ransomware news, ranging from new extortion tactics, to a ransomware gang giving away a free decryptor after attacking a children’s hospital. […]
06 Jan Chick-fil-A investigates reports of hacked customer accounts American fast-food restaurant chain Chick-fil-A is investigating what it described as “suspicious activity” linked to some of its customers’ accounts. […]
06 Jan Air France and KLM notify customers of account hacks Air France and KLM have informed Flying Blue customers that some of their personal information was exposed after their accounts were breached. […]
06 Jan VSCode Marketplace can be abused to host malicious extensions Threat analysts at AquaSec have experimented with the security of VSCode Marketplace and found that it’s surprisingly easy to upload malicious extensions from accounts that appear verified on the platform. […]
06 Jan FCC wants telecom carriers to report data breaches faster The U.S. Federal Communications Commission wants to strengthen federal law enforcement and modernize breach notification requirements for telecommunications companies so that they notify customers of security breaches faster. […]