17 Oct Malware dev claims to sell new BlackLotus Windows UEFI bootkit A threat actor is selling on hacking forums what they claim to be a new UEFI bootkit named BlackLotus, a malicious tool with capabilities usually linked to state-backed threat groups. […]
17 Oct MyDeal data breach impacts 2.2M users, stolen data for sale online Woolworths’ MyDeal subsidiary has disclosed a data breach affecting 2.2 million customers, with the hacker trying to sell the stolen data on a hacker forum. […]
17 Oct Windows Mark of the Web bypass zero-day gets unofficial patch A free unofficial patch has been released through the 0patch platform to address an actively exploited zero-day flaw in the Windows Mark of the Web (MotW) security mechanism. […]
17 Oct Australian insurance firm Medibank confirms ransomware attack Health insurance provider Medibank has confirmed that a ransomware attack is responsible for last week’s cyberattack and disruption of online services. […]
16 Oct New PHP information-stealing malware targets Facebook accounts Threat analysts have spotted a new Ducktail campaign using a new infostealer variant and novel TTPs (tactics, techniques, and procedures), while the Facebook users it targets are no longer limited to holders of business accounts. […]
16 Oct Google search crashes when you ask “How many emojis on Apple” Google Search is timing out when users search for specific terms like “How many emojis on iOS,” “How many emojis on Apple” and “How many emojis on Windows.” […]
15 Oct Over 45,000 VMware ESXi servers just reached end-of-life Over 45,000 VMware ESXi servers inventoried by Lansweeper just reached end-of-life (EOL), with VMware no longer providing software and security updates unless companies purchase an extended support contract. […]
15 Oct Fortinet urges admins to patch bug with public exploit immediately Fortinet urges customers to urgently patch their appliances against a critical authentication bypass FortiOS, FortiProxy, and FortiSwitchManager vulnerability exploited in attacks. […]
15 Oct Almost 900 servers hacked using Zimbra zero-day flaw Almost 900 servers have been hacked using a critical Zimbra Collaboration Suite (ZCS) vulnerability, which at the time was a zero-day without a patch for nearly 1.5 months. […]
14 Oct The Week in Ransomware – October 14th 2022 – Bitcoin Trickery This week’s news is action-packed, with police tricking ransomware into releasing keys to victims calling ransomware operations liars. […]