03 Nov Google Play adds security audit badges for Android VPN apps Google Play, Android’s official app store, is now tagging VPN apps with an ‘independent security reviews’ badge if they conducted an independent security audit of their software and platform. […]
03 Nov New Microsoft Exchange zero-days allow RCE, data theft attacks Microsoft Exchange is impacted by four zero-day vulnerabilities that attackers can exploit remotely to execute arbitrary code or disclose sensitive information on affected installations. […]
03 Nov Okta breach: 134 customers exposed in October support system hack Okta says attackers who breached its customer support system last month gained access to files belonging to 134 customers, five of them later being targeted in session hijacking attacks with the help of stolen session tokens. […]
02 Nov Atlassian warns of exploit for Confluence data wiping bug, get patching Atlassian warned admins that a public exploit is now available for a critical Confluence security flaw that can be used in data destruction attacks targeting Internet-exposed and unpatched instances. […]
02 Nov Ace Hardware says 1,202 devices were hit during cyberattack Ace Hardware confirmed that a cyberattack is preventing local stores and customers from placing orders as the company works to restore 196 servers. […]
02 Nov New macOS ‘KandyKorn’ malware targets cryptocurrency engineers A new macOS malware dubbed ‘KandyKorn’ has been spotted in a campaign attributed to the North Korean Lazarus hacking group, targeting blockchain engineers of a cryptocurrency exchange platform. […]
02 Nov Mortgage lender giant Mr. Cooper hit by cyberattack impacting IT systems U.S. mortgage lending giant Mr. Cooper was breached in a cyberattack that caused the company to shut down IT systems, including access to their online payment portal. […]
02 Nov HelloKitty ransomware now exploiting Apache ActiveMQ flaw in attacks A remote code execution (RCE) flaw impacting Apache ActiveMQ has been under active exploitation by threat actors who use HelloKitty ransomware payloads. […]
02 Nov Cloudflare Dashboard and APIs down after data center power outage An ongoing Cloudflare outage has taken down many of its products, including the company’s dashboard and related application programming interfaces (APIs) customers use to manage and read service configurations. […]
02 Nov Boeing confirms cyberattack amid LockBit ransomware claims Aerospace giant Boeing is investigating a cyberattack that impacted its parts and distribution business after the LockBit ransomware gang claimed that they breached the company’s network and stole data. […]