16 May Norway recommends replacing SSL VPN to prevent breaches The Norwegian National Cyber Security Centre (NCSC) recommends replacing SSLVPN/WebVPN solutions with alternatives due to the repeated exploitation of related vulnerabilities in edge network devices to breach corporate networks. […]
16 May MediSecure e-script firm hit by ‘large-scale’ ransomware data breach Electronic prescription provider MediSecure in Australia has shut down its website and phone lines following a ransomware attack believed to originate from a third-party vendor. […]
16 May Russian hackers use new Lunar malware to breach a European govt’s agencies Security researchers discovered two previously unseen backdoors dubbed LunarWeb and LunarMail that were used to compromise a European government’s diplomatic institutions abroad. […]
16 May Kimsuky hackers deploy new Linux backdoor in attacks on South Korea The North Korean hacker group Kimsuki has been using a new Linux malware called Gomir that is a version of the GoBear backdoor delivered via trojanized software installers. […]
15 May Google fixes third actively exploited Chrome zero-day in a week Google has released a new emergency Chrome security update to address the third zero-day vulnerability exploited in attacks within a week. […]
15 May FBI seize BreachForums hacking forum used to leak stolen data The FBI has seized the notorious BreachForums hacking forum that leaked and sold stolen corporate data to other cybercriminals. […]
15 May Banco Santander warns of a data breach exposing customer info Banco Santander S.A. announced it suffered a data breach impacting customers after an unauthorized actor accessed a database hosted by one of its third-party service providers. […]
14 May PoC exploit released for RCE zero-day in D-Link EXO AX4800 routers The D-Link EXO AX4800 (DIR-X4860) router is vulnerable to remote unauthenticated command execution that could lead to complete device takeovers by attackers with access to the HNAP port. […]
14 May Apple fixes Safari WebKit zero-day flaw exploited at Pwn2Own Apple has released security updates to fix a zero-day vulnerability in the Safari web browser exploited during this year’s Pwn2Own Vancouver hacking competition. […]
14 May Apple and Google add alerts for unknown Bluetooth trackers to iOS, Android On Monday, Apple and Google jointly announced a new privacy feature that warns Android and iOS users when an unknown Bluetooth tracking device travels with them. […]