27 Jul Zimbra patches zero-day vulnerability exploited in XSS attacks Two weeks after the initial disclosure, Zimbra has released security updates that patch a zero-day vulnerability exploited in attacks targeting Zimbra Collaboration Suite (ZCS) email servers. […]
27 Jul SSNDOB cybercrime market admin faces 15 years after pleading guilty A Ukrainian man, Vitalii Chychasov, has pleaded guilty in the United States to conspiracy to commit access device fraud and trafficking in unauthorized access devices through the now-shutdown SSNDOB Marketplace. […]
27 Jul WordPress Ninja Forms plugin flaw lets hackers steal submitted data Popular WordPress form-building plugin Ninja Forms contains three vulnerabilities that could allow attackers to achieve privilege escalation and steal user data. […]
26 Jul Microsoft previews Defender for IoT firmware analysis service Microsoft announced the public preview of a new Defender for IoT feature that helps analyze the firmware of embedded Linux devices like routers for security vulnerabilities and common weaknesses. […]
26 Jul Lazarus hackers linked to $60 million Alphapo cryptocurrency heist Blockchain analysts blame the North Korean Lazarus hacking group for a recent attack on payment processing platform Alphapo where the attackers stole almost $60 million in crypto. […]
26 Jul Almost 40% of Ubuntu users vulnerable to new privilege elevation flaws Two Linux vulnerabilities introduced recently into the Ubuntu kernel create the potential for unprivileged local users to gain elevated privileges on a massive number of devices. […]
26 Jul SEC now requires companies to disclose cyberattacks in 4 days The U.S. Securities and Exchange Commission has adopted new rules requiring publicly traded companies to disclose cyberattacks within four business days after determining they’re material incidents. […]
26 Jul Windows 11 KB5028254 update fixes VPN performance issues, 27 bugs Microsoft has released the July 2023 optional cumulative update for Windows 11, version 22H2, with fixes for 27 issues, including ones affecting VPN performance and display or audio devices. […]
25 Jul Super Admin elevation bug puts 900,000 MikroTik devices at risk A critical severity ‘Super Admin’ privilege elevation flaw puts over 900,000 MikroTik RouterOS routers at risk, potentially enabling attackers to take full control over a device and remain undetected. […]
25 Jul Google Chrome to offer ‘Link Previews’ when hovering over links Google is set to improve Chrome by introducing a new “Link Preview” feature. This feature, currently in development for desktop use, could significantly change how users interact with web content. […]