17 Nov QBot phishing abuses Windows Control Panel EXE to infect devices Phishing emails distributing the QBot malware are using a DLL hijacking flaw in the Windows 10 Control Panel to infect computers, likely as an attempt to evade detection by security software. […]
16 Nov Updated RapperBot malware targets game servers in DDoS attacks The Mirai-based botnet ‘RapperBot’ has re-emerged via a new campaign that infects IoT devices for DDoS (Distributed Denial of Service) attacks against game servers. […]
16 Nov Suspected Zeus cybercrime ring leader ‘Tank’ arrested by Swiss police Vyacheslav Igorevich Penchukov, also known as Tank and one of the leaders of the notorious JabberZeus cybercrime gang, was arrested in Geneva last month. […]
16 Nov Twitter source code indicates end-to-end encrypted DMs are coming Twitter is reportedly working on finally adding end-to-end encryption (E2EE) for direct messages (DMs) exchanged between users on the social media platform. […]
16 Nov US govt: Iranian hackers breached federal agency using Log4Shell exploit The FBI and CISA revealed in a joint advisory published today that an unnamed Iranian-backed threat group hacked a Federal Civilian Executive Branch (FCEB) organization to deploy XMRig cryptomining malware. […]
16 Nov Magento stores targeted in massive surge of TrojanOrders attacks At least seven hacking groups are behind a massive surge in ‘TrojanOrders’ attacks targeting Magento 2 websites, exploiting a vulnerability that allows the threat actors to compromise vulnerable servers. […]
15 Nov North Korean hackers target European orgs with updated malware North Korean hackers are using a new version of the DTrack backdoor to attack organizations in Europe and Latin America. […]
15 Nov Windows 10 KB5020030 preview update released with ten improvements Microsoft has released this month’s optional KB5020030 Preview cumulative update for all editions of Windows 10 20H2, 21H1, 21H2, and 22H2. […]
15 Nov Google to roll out Privacy Sandbox on Android 13 starting early 2023 Google announced today that they will begin rolling out the Privacy Sandbox system on a limited number of Android 13 devices starting in early 2023. […]
15 Nov Researchers release exploit details for Backstage pre-auth RCE bug Older versions of the Spotify Backstage development portal builder are vulnerable to a critical (CVSS score: 9.8) unauthenticated remote code execution flaw allowing attackers to run commands on publicly exposed systems. […]