10 Oct Microsoft Exchange gets ‘better’ patch to mitigate critical bug The Exchange Team asked admins to deploy a new and “better” patch for a critical Microsoft Exchange Server vulnerability initially addressed in August. […]
09 Oct D-Link WiFi range extender vulnerable to command injection attacks The popular D-Link DAP-X1860 WiFi 6 range extender is susceptible to a vulnerability allowing DoS (denial of service) attacks and remote command injection. […]
09 Oct ALPHV ransomware gang claims attack on Florida circuit court The ALPHV (BlackCat) ransomware gang has claimed an attack that affected state courts across Northwest Florida (part of the First Judicial Circuit) last week. […]
09 Oct GNOME Linux systems exposed to RCE attacks via file downloads A memory corruption vulnerability in the open-source libcue library can let attackers execute arbitrary code on GNOME Linux systems. […]
09 Oct Over 17,000 WordPress sites hacked in Balada Injector attacks last month Multiple Balada Injector campaigns have compromised and infected over 17,000 WordPress sites using known flaws in premium theme plugins. […]
09 Oct Hackers modify online stores’ 404 pages to steal credit cards A new Magecart card skimming campaign hijacks the 404 error pages of online retailer’s websites, hiding malicious code to steal customers’ credit card information. […]
07 Oct Bounty offered for secret NSA seeds behind NIST elliptic curves algo A bounty of $12,288 has been announced for the first person to crack the NIST elliptic curves seeds and discover the original phrases that were hashed to generate them. […]
06 Oct D.C. Board of Elections confirms voter data stolen in site hack The District of Columbia Board of Elections (DCBOE) is currently probing a data leak involving an unknown number of voter records following breach claims from a threat actor known as RansomedVC. […]
06 Oct Blackbaud agrees to $49.5 million settlement for ransomware data breach Cloud computing provider Blackbaud reached a $49.5 million agreement with attorneys general from 49 U.S. states to settle a multi-state investigation of a May 2020 ransomware attack and the resulting data breach. […]
06 Oct FTC warns of ‘staggering’ losses to social media scams since 2021 The Federal Trade Commission says Americans have lost at least $2.7 billion to social media scams since 2021, with the real number likely many times larger due to unreported incidents. […]