03 Oct Google to bolster phishing and malware delivery defenses in 2024 Google will introduce new sender guidelines in February to bolster email security against phishing and malware delivery by mandating bulk senders to authenticate their emails and adhere to stricter spam thresholds […]
03 Oct Android October security update fixes zero-days exploited in attacks Google has released the October 2023 security updates for Android, addressing 54 unique vulnerabilities, including two known to be actively exploited. […]
02 Oct Microsoft Defender no longer flags Tor Browser as malware For Windows users who frequently use the TorBrowser, there’s been a pressing concern. Recent versions of the TorBrowser, specifically because of the tor.exe file it contained, were being flagged as potential threats by Windows Defender. […]
02 Oct Exim patches three of six zero-day bugs disclosed last week Exim developers have released patches for three of the zero-days disclosed last week through Trend Micro’s Zero Day Initiative (ZDI), one of them allowing unauthenticated attackers to gain remote code execution. […]
02 Oct New BunnyLoader threat emerges as a feature-rich malware-as-a-service Security researchers discovered a new malware-as-a-service (MaaS) named ‘BunnyLoader’ advertised on multiple hacker forums as a fileless loader that can steal and replace the contents of the system clipboard. […]
02 Oct Ransomware gangs now exploiting critical TeamCity RCE flaw Ransomware gangs are now targeting a recently patched critical vulnerability in JetBrains’ TeamCity continuous integration and deployment server. […]
02 Oct Exploit available for critical WS_FTP bug exploited in attacks Over the weekend, security researchers released a proof-of-concept (PoC) exploit for a maximum severity remote code execution vulnerability in Progress Software’s WS_FTP Server file sharing platform. […]
01 Oct Amazon sends Mastercard, Google Play gift card order emails by mistake Amazon mistakenly sent out purchase confirmation emails for Hotels.com, Google Play, and Mastercard gift cards to customers, making many worried their accounts were compromised. […]
01 Oct Meet LostTrust ransomware — A likely rebrand of the MetaEncryptor gang The LostTrust ransomware operation is believed to be a rebrand of MetaEncryptor, utilizing almost identical data leak sites and encryptors. […]
01 Oct New Marvin attack revives 25-year-old decryption flaw in RSA A flaw related to the PKCS #1 v1.5 padding in SSL servers discovered in 1998 and believed to have been resolved still impacts several widely-used projects today. […]