11 Oct New WordPress backdoor creates rogue admin to hijack websites A new malware has been posing as a legitimate caching plugin to target WordPress sites, allowing threat actors to create an administrator account and control the site’s activity. […]
11 Oct BianLian extortion group claims recent Air Canada breach The BianLian extortion group claims to have stolen 210GB of data after breaching the network of Air Canada, the country’s largest airline and a founding member of Star Alliance. […]
11 Oct Microsoft Defender now auto-isolates compromised accounts Microsoft Defender for Endpoint now uses automatic attack disruption to isolate compromised user accounts and block lateral movement in hands-on-keyboard attacks with the help of a new ‘contain user’ capability in public preview. […]
10 Oct Mirai DDoS malware variant expands targets with 13 router exploits A Mirai-based DDoS (distributed denial of service) malware botnet tracked as IZ1H9 has added thirteen new payloads to target Linux-based routers and routers from D-Link, Zyxel, TP-Link, TOTOLINK, and others. […]
10 Oct Microsoft Exchange gets ‘better’ patch to mitigate critical bug The Exchange Team asked admins to deploy a new and “better” patch for a critical Microsoft Exchange Server vulnerability initially addressed in August. […]
09 Oct D-Link WiFi range extender vulnerable to command injection attacks The popular D-Link DAP-X1860 WiFi 6 range extender is susceptible to a vulnerability allowing DoS (denial of service) attacks and remote command injection. […]
09 Oct ALPHV ransomware gang claims attack on Florida circuit court The ALPHV (BlackCat) ransomware gang has claimed an attack that affected state courts across Northwest Florida (part of the First Judicial Circuit) last week. […]
09 Oct GNOME Linux systems exposed to RCE attacks via file downloads A memory corruption vulnerability in the open-source libcue library can let attackers execute arbitrary code on GNOME Linux systems. […]
09 Oct Over 17,000 WordPress sites hacked in Balada Injector attacks last month Multiple Balada Injector campaigns have compromised and infected over 17,000 WordPress sites using known flaws in premium theme plugins. […]
09 Oct Hackers modify online stores’ 404 pages to steal credit cards A new Magecart card skimming campaign hijacks the 404 error pages of online retailer’s websites, hiding malicious code to steal customers’ credit card information. […]