29 Mar Activision: Enable 2FA to secure accounts recently stolen by malware An infostealer malware campaign has reportedly collected millions of logins from users of various gaming websites, including players that use cheats, pay-to-cheat services. […]
29 Mar Red Hat warns of backdoor in XZ tools used by most Linux distros Today, Red Hat warned users to immediately stop using systems running Fedora development and experimental versions because of a backdoor found in the latest XZ Utils data compression tools and libraries. […]
28 Mar Decade-old Linux ‘wall’ bug helps make fake SUDO prompts, steal passwords A vulnerability has been discovered in the ‘util-linux’ library that could allow unprivileged users to put arbitrary text on other users’ terminals using the ‘wall’ command. […]
28 Mar Retail chain Hot Topic hit by new credential stuffing attacks American retailer Hot Topic disclosed that two waves of credential stuffing attacks in November exposed affected customers’ personal information and partial payment data. […]
28 Mar PyPI suspends new user registration to block malware campaign The Python Package Index (PyPI) has temporarily suspended user registration and the creation of new projects to deal with an ongoing malware campaign. […]
28 Mar Cisco warns of password-spraying attacks targeting VPN services Cisco has shared a set of recommendations for customers to mitigate password-spraying attacks that have been targeting Remote Access VPN (RAVPN) services configured on Cisco Secure Firewall devices. […]
28 Mar How Pentesting-as-a-Service can Reduce Overall Security Costs Penetration testing plays a critical role in finding application vulnerabilities before they can be exploited. Learn more from Outpost24 on the costs of Penetration-Testing-as-a-Service vs classic pentest offerings. […]
27 Mar New Darcula phishing service targets iPhone users via iMessage A new phishing-as-a-service (PhaaS) named ‘Darcula’ uses 20,000 domains to spoof brands and steal credentials from Android and iPhone users in more than 100 countries. […]
27 Mar Google fixes Chrome zero-days exploited at Pwn2Own 2024 Google fixed seven security vulnerabilities in the Chrome web browser on Tuesday, including two zero-days exploited during the Pwn2Own Vancouver 2024 hacking competition. […]
27 Mar INC Ransom threatens to leak 3TB of NHS Scotland stolen data The INC Ransom extortion gang is threatening to publish three terabytes of data allegedly stolen after breaching the National Health Service (NHS) of Scotland. […]