02 Dec Hackers use in-house Zoho ServiceDesk exploit to drop webshells An advanced persistent threat (APT) group that had been exploiting a flaw in the Zoho ManageEngine ADSelfService Plus software has pivoted to leveraging a different vulnerability in another Zoho product. […]
02 Dec Russian internet watchdog announces ban of six more VPN products Russia’s internet watchdog, ‘Roskomnadzor’, has announced the ban of six more VPN products, bringing the total number to more than a dozen, shows a notification to companies in the country. […]
02 Dec Nine WiFi routers used by millions were vulnerable to 226 flaws Security researchers analyzed nine popular WiFi routers and found a total of 226 potential vulnerabilities in them, even when running the latest firmware. […]
02 Dec New malware hides as legit nginx process on e-commerce servers eCommerce servers are being targeted with remote access malware that hides on Nginx servers in a way that makes it virtually invisible to security solutions. […]
02 Dec Planned Parenthood LA discloses data breach after ransomware attack Planned Parenthood Los Angeles has disclosed a data breach after suffering a ransomware attack in October that exposed the personal information of approximately 400,000 patients. […]
01 Dec Malicious Android app steals Malaysian bank credentials, MFA codes A fake Android app is masquerading as a housekeeping service to steal online banking credentials from the customers of eight Malaysian banks. […]
01 Dec Mozilla fixes critical bug in cross-platform cryptography library Mozilla has addressed a critical memory corruption vulnerability affecting its cross-platform Network Security Services (NSS) set of cryptography libraries. […]
01 Dec Microsoft Exchange servers hacked to deploy BlackByte ransomware BlackByte ransomware actors were observed exploiting the ProxyShell set of vulnerabilities (CVE-2021-34473, CVE-2021-34523, CVE-2021-31207) to compromise Microsoft Exchange servers. […]
01 Dec Europol: 18k money mules caught laundering money from online fraud Europol has announced the arrest of 1,803 money mules out of 18,351 identified following an international money-laundering crackdown operation codenamed “EMMA 7.” […]
01 Dec VirusTotal Collections feature helps keep neat IoC lists Scanning service VirusTotal announced today a new feature called Collections that lets researchers create and share reports with indicators of compromise observed in security incidents. […]