16 Jan GitHub rotates keys to mitigate impact of credential-exposing flaw GitHub rotated keys potentially exposed by a vulnerability patched in December that could let attackers access credentials within production containers via environment variables. […]
16 Jan MacOS info-stealers quickly evolve to evade XProtect detection Multiple information stealers for the macOS platform have demonstrated the capability to evade detection even when security companies follow and report about new variants frequently. […]
16 Jan Citrix warns of new Netscaler zero-days exploited in attacks Citrix urged customers on Tuesday to immediately patch Netscaler ADC and Gateway appliances exposed online against two actively exploited zero-day vulnerabilities. […]
16 Jan Google fixes first actively exploited Chrome zero-day of 2024 Google has released security updates to fix the first Chrome zero-day vulnerability exploited in the wild since the start of the year. […]
16 Jan Majorca city Calvià extorted for $11M in ransomware attack The Calvià City Council in Majorca announced it was targeted by a ransomware attack on Saturday, which impacted municipal services. […]
15 Jan Ivanti Connect Secure zero-days now under mass exploitation Two zero-day vulnerabilities affecting Ivanti’s Connect Secure VPN and Policy Secure network access control (NAC) appliances are now under mass exploitation. […]
15 Jan Windows Copilot autostart tests limited to 27″ displays or larger Microsoft says that tests of a controversial new Windows 11 feature that automatically opens the AI-powered Copilot assistant after Windows starts are limited to systems with 27-inch displays. […]
15 Jan US court docs expose fake antivirus renewal phishing tactics In a seizure warrant application, the U.S. Secret Service sheds light on how threat actors stole $34,000 using fake antivirus renewal subscription emails. […]
15 Jan Microsoft working on a fix for Windows 10 0x80070643 errors Microsoft is working to fix a known issue causing 0x80070643 errors when installing the KB5034441 security update that patches the CVE-2024-20666 BitLocker vulnerability. […]
15 Jan Windows SmartScreen flaw exploited to drop Phemedrone malware A Phemedrone information-stealing malware campaign exploits a Microsoft Defender SmartScreen vulnerability (CVE-2023-36025) to bypass Windows security prompts when opening URL files. […]