02 Dec New malware hides as legit nginx process on e-commerce servers eCommerce servers are being targeted with remote access malware that hides on Nginx servers in a way that makes it virtually invisible to security solutions. […]
02 Dec Planned Parenthood LA discloses data breach after ransomware attack Planned Parenthood Los Angeles has disclosed a data breach after suffering a ransomware attack in October that exposed the personal information of approximately 400,000 patients. […]
01 Dec Malicious Android app steals Malaysian bank credentials, MFA codes A fake Android app is masquerading as a housekeeping service to steal online banking credentials from the customers of eight Malaysian banks. […]
01 Dec Mozilla fixes critical bug in cross-platform cryptography library Mozilla has addressed a critical memory corruption vulnerability affecting its cross-platform Network Security Services (NSS) set of cryptography libraries. […]
01 Dec Microsoft Exchange servers hacked to deploy BlackByte ransomware BlackByte ransomware actors were observed exploiting the ProxyShell set of vulnerabilities (CVE-2021-34473, CVE-2021-34523, CVE-2021-31207) to compromise Microsoft Exchange servers. […]
01 Dec Europol: 18k money mules caught laundering money from online fraud Europol has announced the arrest of 1,803 money mules out of 18,351 identified following an international money-laundering crackdown operation codenamed “EMMA 7.” […]
01 Dec VirusTotal Collections feature helps keep neat IoC lists Scanning service VirusTotal announced today a new feature called Collections that lets researchers create and share reports with indicators of compromise observed in security incidents. […]
30 Nov Smartwatches for children are a privacy and security nightmare Researchers analyzed the security of four popular smartwatches for children and found pre-installed downloaders, weak passwords, and unencrypted data transmissions. […]
30 Nov EwDoor botnet targets AT&T network edge devices at US firms A recently discovered botnet is attacking unpatched AT&T enterprise network edge devices using exploits for a four-year-old critical severity Blind Command Injection security flaw. […]
30 Nov Android banking malware infects 300,000 Google Play users Malware campaigns distributing Android trojans that steals online bank credentials have infected almost 300,000 devices through malicious apps pushed via Google’s Play Store. […]