21 May GhostEngine mining attacks kill EDR security using vulnerable drivers A malicious crypto mining campaign codenamed ‘REF4578,’ has been discovered deploying a malicious payload named GhostEngine that uses vulnerable drivers to turn off security products and deploy an XMRig miner. […]
21 May Veeam warns of critical Backup Enterprise Manager auth bypass bug Veeam warned customers today to patch a critical security vulnerability that allows unauthenticated attackers to sign into any account via the Veeam Backup Enterprise Manager (VBEM). […]
21 May LockBit says they stole data in London Drugs ransomware attack Today, the LockBit ransomware gang claimed they were behind the April cyberattack on Canadian pharmacy chain London Drugs and is now threatening to publish stolen data online after allegedly failed negotiations. […]
21 May GitHub warns of SAML auth bypass flaw in Enterprise Server GitHub has fixed a maximum severity (CVSS v4 score: 10.0) authentication bypass vulnerability tracked as CVE-2024-4986, which impacts GitHub Enterprise Server (GHES) instances using SAML single sign-on (SSO) authentication. […]
21 May Google rolls out Chrome fix for empty pages when switching tabs Google is rolling out a server-side fix for a known issue affecting the Chrome browser that causes webpage content to temporarily disappear when users change between open tabs. […]
21 May Zoom adds post-quantum end-to-end encryption to video meetings Zoom has announced the global availability of post-quantum end-to-end encryption (E2EE) for Zoom Meetings, with Zoom Phone and Zoom Rooms to follow soon. […]
20 May Critical Fluent Bit flaw impacts all major cloud providers A critical Fluent Bit vulnerability that can be exploited in denial-of-service and remote code execution attacks impacts all major cloud providers and many technology giants. […]
20 May OmniVision discloses data breach after 2023 ransomware attack The California-based imaging sensors manufacturer OmniVision is warning of a data breach after the company suffered a Cactus ransomware attack last year. […]
20 May New BiBi Wiper version also destroys the disk partition table A new version of the BiBi Wiper malware is now deleting the disk partition table to make data restoration harder, extending the downtime for targeted victims. […]
20 May QNAP QTS zero-day in Share feature gets public RCE exploit An extensive security audit of QNAP QTS, the operating system for the company’s NAS products, has uncovered fifteen vulnerabilities of varying severity, with eleven remaining unfixed. […]