02 Mar Microsoft releases Windows security updates for Intel CPU flaws Microsoft has released out-of-band security updates for ‘Memory Mapped I/O Stale Data (MMIO)’ information disclosure vulnerabilities in Intel CPUs. […]
02 Mar BlackLotus bootkit bypasses UEFI Secure Boot on patched Windows 11 The developers of the BlackLotus UEFI bootkit have improved the malware with Secure Boot bypass capabilities that allow it to infected even fully patched Windows 11 systems. […]
02 Mar Chick-fil-A confirms accounts hacked in months-long “automated” attack American fast food chain Chick-fil-A has confirmed that customers’ accounts were breached in a months-long credential stuffing attack, allowing threat actors to use stored rewards balances and access personal information. […]
02 Mar Chinese hackers use new custom backdoor to evade detection The Chinese cyber espionage hacking group Mustang Panda was seen deploying a new custom backdoor named ‘MQsTTang’ in attacks starting this year. […]
02 Mar Hatch Bank discloses data breach after GoAnywhere MFT hack Fintech banking platform Hatch Bank has reported a data breach after hackers stole the personal information of almost 140,000 customers from the company’s Fortra GoAnywhere MFT secure file-sharing platform. […]
01 Mar Trezor warns of massive crypto wallet phishing campaign An ongoing phishing campaign is pretending to be Trezor data breach notifications attempting to steal a target’s cryptocurrency wallet and its assets. […]
01 Mar Aruba Networks fixes six critical vulnerabilities in ArubaOS Aruba Networks published a security advisory to inform customers about six critical-severity vulnerabilities impacting multiple versions of ArubaOS, its proprietary network operating system. […]
01 Mar Microsoft Exchange Online outage blocks access to mailboxes worldwide Microsoft is investigating an ongoing outage that is blocking Exchange Online customers worldwide from accessing their mailboxes via any connection method or sending/receiving emails. […]
01 Mar Iron Tiger hackers create Linux version of their custom malware The APT27 hacking group, aka “Iron Tiger,” has prepared a new Linux version of its SysUpdate custom remote access malware, allowing the Chinese cyberespionage group to target more services used in the enterprise. […]
28 Feb CISA warns of hackers exploiting ZK Java Framework RCE flaw The U.S. Cybersecurity & Infrastructure Security Agency (CISA) has added CVE-2022-36537 to its “Known Exploited Vulnerabilities Catalog” after threat actors began actively exploiting the remote code execution (RCE) flaw in attacks. […]