01 Apr The Week in Ransomware – April 1st 2022 – ‘I can fight with a keyboard’ While ransomware is still conducting attacks and all companies must stay alert, ransomware news has been relatively slow this week. However, there were still some interesting stories that we outline below. […]
01 Apr Microsoft now lets you enable the Windows App Installer again, here’s how Microsoft now allows enterprise admins to re-enable the MSIX ms-appinstaller protocol handler disabled after Emotet abused it to deliver malicious Windows App Installer packages. […]
01 Apr Newly found Android malware records audio, tracks your location A previously unknown Android malware uses the same shared-hosting infrastructure previously seen used by the Russian APT group known as Turla, though attribution to the hacking group not possible. […]
01 Apr Russian-linked Android malware records audio, tracks your location A previously unknown Android malware has been linked to the Turla hacking group after discovering the app used infrastructure previously attributed to the threat actors. […]
01 Apr Beastmode botnet boosts DDoS power with new router exploits A Mirai-based distributed denial-of-service (DDoS) botnet tracked as Beastmode (aka B3astmode) has updated its list of exploits to include several new ones, three of them targeting various models of Totolink routers. […]
01 Apr Trend Micro fixes actively exploited remote code execution bug Japanese cybersecurity software firm Trend Micro has patched a high severity security flaw in the Apex Central product management console that can let attackers execute arbitrary code remotely. […]
01 Apr Critical GitLab vulnerability lets attackers take over accounts GitLab has addressed a critical severity vulnerability that could allow remote attackers to take over user accounts using hardcoded passwords. […]
01 Apr EU draft law adds security checks to all crypto transactions The European Parliament has taken the first steps for new legislation against money-laundering that covers cryptocurrency transactions, which are an important part of illicit activities today. […]
01 Apr Microsoft adds Windows 11 upgrade block due to IE11 known issue Microsoft has added a new safeguard hold blocking Windows 11 upgrades for Windows 10 customers who don’t import their Internet Explorer 11 (IE11) data into Microsoft Edge before trying to install the newest Windows version. […]
31 Mar Phishing uses Azure Static Web Pages to impersonate Microsoft Phishing attacks are abusing Microsoft Azure’s Static Web Apps service to steal Microsoft, Office 365, Outlook, and OneDrive credentials. […]