06 Nov Cybercrime service bypasses Android security to install malware A new dropper-as-a-service (DaaS) named ‘SecuriDropper’ has emerged, using a method that bypasses Android 13’s ‘Restricted Settings’ to install malware on devices and grant them access to the Accessibility Services. […]
05 Nov Socks5Systemz proxy service infects 10,000 systems worldwide A proxy botnet called ‘Socks5Systemz’ has been infecting computers worldwide via the ‘PrivateLoader’ and ‘Amadey’ malware loaders, currently counting 10,000 infected devices. […]
04 Nov Discord will switch to temporary file links to block malware delivery Discord will switch to temporary file links for all users by the end of the year to block attackers from using its CDN (content delivery network) for hosting and pushing malware. […]
04 Nov Apple ‘Find My’ network can be abused to steal keylogged passwords Apple’s “Find My” location network can be abused by malicious actors to stealthily transmit sensitive information captured by keyloggers installed in keyboards. […]
03 Nov The Week in Ransomware – November 3rd 2023 – Hive’s Back Over the past couple of months, ransomware attacks have been escalating as new operations launch, old ones return, and existing operations continue to target the enterprise. […]
03 Nov Dutch hacker jailed for extortion, selling stolen data on RaidForums A former Dutch cybersecurity professional was sentenced to four years in prison after being found guilty of hacking and blackmailing more than a dozen companies in the Netherlands and worldwide. […]
03 Nov American Airlines pilot union hit by ransomware attack Allied Pilots Association (APA), a labor union representing 15,000 American Airlines pilots, disclosed a ransomware attack that hit its systems on Monday. […]
03 Nov Google Play adds security audit badges for Android VPN apps Google Play, Android’s official app store, is now tagging VPN apps with an ‘independent security reviews’ badge if they conducted an independent security audit of their software and platform. […]
03 Nov New Microsoft Exchange zero-days allow RCE, data theft attacks Microsoft Exchange is impacted by four zero-day vulnerabilities that attackers can exploit remotely to execute arbitrary code or disclose sensitive information on affected installations. […]
03 Nov Okta breach: 134 customers exposed in October support system hack Okta says attackers who breached its customer support system last month gained access to files belonging to 134 customers, five of them later being targeted in session hijacking attacks with the help of stolen session tokens. […]