07 Nov Marina Bay Sands discloses data breach impacting 665,000 customers The Marina Bay Sands (MBS) luxury resort and casino in Singapore has disclosed a data breach that impacts personal data of 665,000 customers. […]
06 Nov Veeam warns of critical bugs in Veeam ONE monitoring platform Veeam released hotfixes today to address four vulnerabilities in the company’s Veeam ONE IT infrastructure monitoring and analytics platform, two of them critical. […]
06 Nov Critical Atlassian Confluence bug exploited in Cerber ransomware attacks Attackers are exploiting a recently patched and critical severity Atlassian Confluence authentication bypass flaw to encrypt victims’ files using Cerber ransomware. […]
06 Nov US sanctions Russian who laundered money for Ryuk ransomware affiliate The U.S. Department of the Treasury’s Office of Foreign Assets Control (OFAC) has sanctioned Russian national Ekaterina Zhdanova for laundering millions in cryptocurrency for various individuals, including ransomware actors. […]
06 Nov TellYouThePass ransomware joins Apache ActiveMQ RCE attacks Internet-exposed Apache ActiveMQ servers are also targeted in TellYouThePass ransomware attacks targeting a critical remote code execution (RCE) vulnerability previously exploited as a zero-day. […]
06 Nov QNAP warns of critical command injection flaws in QTS OS, apps QNAP Systems published security advisories for two critical command injection vulnerabilities that impact multiple versions of the QTS operating system and applications on its network-attached storage (NAS) devices. […]
06 Nov Cybercrime service bypasses Android security to install malware A new dropper-as-a-service (DaaS) named ‘SecuriDropper’ has emerged, using a method that bypasses Android 13’s ‘Restricted Settings’ to install malware on devices and grant them access to the Accessibility Services. […]
05 Nov Socks5Systemz proxy service infects 10,000 systems worldwide A proxy botnet called ‘Socks5Systemz’ has been infecting computers worldwide via the ‘PrivateLoader’ and ‘Amadey’ malware loaders, currently counting 10,000 infected devices. […]
04 Nov Discord will switch to temporary file links to block malware delivery Discord will switch to temporary file links for all users by the end of the year to block attackers from using its CDN (content delivery network) for hosting and pushing malware. […]
04 Nov Apple ‘Find My’ network can be abused to steal keylogged passwords Apple’s “Find My” location network can be abused by malicious actors to stealthily transmit sensitive information captured by keyloggers installed in keyboards. […]