30 Mar Realtek and Cacti flaws now actively exploited by malware botnets Multiple malware botnets actively target Cacti and Realtek vulnerabilities in campaigns detected between January and March 2023, spreading ShellBot and Moobot malware. […]
30 Mar Bing search results hijacked via misconfigured Microsoft app A misconfigured Microsoft application allowed anyone to log in and modify Bing.com search results in real-time, as well as inject XSS attacks to potentially breach the accounts of Office 365 users. […]
30 Mar New AlienFox toolkit steals credentials for 18 cloud services A new modular toolkit called ‘AlienFox’ allows threat actors to scan for misconfigured servers to steal authentication secrets and credentials for cloud-based email services. […]
29 Mar Hackers compromise 3CX desktop app in a supply chain attack A digitally signed and trojanized version of the 3CX Voice Over Internet Protocol (VOIP) desktop client is reportedly being used to target the company’s customers in an ongoing supply chain attack. […]
29 Mar SafeMoon ‘burn’ bug abused to drain $8.9 million from liquidity pool The SafeMoon token liquidity pool lost $8.9 million after a hacker exploited a newly created ‘burn’ smart contract function that artificially inflated the price, allowing the actors to sell SafeMoon at a much higher price. […]
29 Mar Microsoft Defender mistakenly tagging URLs as malicious Microsoft Defender is mistakenly flagging legitimate links as malicious, with some customers having already received dozens of alert emails since the issues began over five hours ago. […]
29 Mar Google finds more Android, iOS zero-days used to install spyware Google’s Threat Analysis Group (TAG) discovered several exploit chains using Android, iOS, and Chrome zero-day and n-day vulnerabilities to install commercial spyware and malicious apps on targets’ devices. […]
28 Mar Trojanized Tor browsers target Russians with crypto-stealing malware A surge of trojanized Tor Browser installers targets Russians and Eastern Europeans with clipboard-hijacking malware that steals infected users’ cryptocurrency transactions. […]
28 Mar Crown Resorts confirms ransom demand after GoAnywhere breach Crown Resorts, Australia’s largest gambling and entertainment company, has confirmed that it suffered a data breach after its GoAnywhere secure file-sharing server was breached using a zero-day vulnerability. […]
28 Mar Newly exposed APT43 hacking group targeting US orgs since 2018 A new North Korean hacking group has been revealed to be targeting government organizations, academics, and think tanks in the United States, Europe, Japan, and South Korea for the past five years. […]