08 Nov WhatsApp now lets users hide their location during calls WhatsApp is rolling out a new privacy feature that helps Android and iOS users hide their location during calls by relaying the connection through WhatsApp servers. […]
07 Nov Microsoft Authenticator now blocks suspicious MFA alerts by default Microsoft has introduced a new protective feature in the Authenticator app to block notifications that appear suspicious based on specific checks performed during the account login stage. […]
07 Nov Marina Bay Sands discloses data breach impacting 665,000 customers The Marina Bay Sands (MBS) luxury resort and casino in Singapore has disclosed a data breach that impacts personal data of 665,000 customers. […]
06 Nov Veeam warns of critical bugs in Veeam ONE monitoring platform Veeam released hotfixes today to address four vulnerabilities in the company’s Veeam ONE IT infrastructure monitoring and analytics platform, two of them critical. […]
06 Nov Critical Atlassian Confluence bug exploited in Cerber ransomware attacks Attackers are exploiting a recently patched and critical severity Atlassian Confluence authentication bypass flaw to encrypt victims’ files using Cerber ransomware. […]
06 Nov US sanctions Russian who laundered money for Ryuk ransomware affiliate The U.S. Department of the Treasury’s Office of Foreign Assets Control (OFAC) has sanctioned Russian national Ekaterina Zhdanova for laundering millions in cryptocurrency for various individuals, including ransomware actors. […]
06 Nov TellYouThePass ransomware joins Apache ActiveMQ RCE attacks Internet-exposed Apache ActiveMQ servers are also targeted in TellYouThePass ransomware attacks targeting a critical remote code execution (RCE) vulnerability previously exploited as a zero-day. […]
06 Nov QNAP warns of critical command injection flaws in QTS OS, apps QNAP Systems published security advisories for two critical command injection vulnerabilities that impact multiple versions of the QTS operating system and applications on its network-attached storage (NAS) devices. […]
06 Nov Cybercrime service bypasses Android security to install malware A new dropper-as-a-service (DaaS) named ‘SecuriDropper’ has emerged, using a method that bypasses Android 13’s ‘Restricted Settings’ to install malware on devices and grant them access to the Accessibility Services. […]
05 Nov Socks5Systemz proxy service infects 10,000 systems worldwide A proxy botnet called ‘Socks5Systemz’ has been infecting computers worldwide via the ‘PrivateLoader’ and ‘Amadey’ malware loaders, currently counting 10,000 infected devices. […]