30 Jan GitHub revokes code signing certificates stolen in repo hack GitHub says that unknown attackers have stolen encrypted code-signing certificates for its Desktop and Atom applications after gaining access to some of its development and release planning repositories. […]
30 Jan QNAP fixes critical bug letting hackers inject malicious code QNAP is warning customers to install QTS and QuTS firmware updates that fix a critical security vulnerability allowing remote attackers to inject malicious code on QNAP NAS devices. […]
28 Jan Researchers to release VMware vRealize Log RCE exploit, patch now Security researchers with Horizon3’s Attack Team will release next week an exploit targeting a vulnerability chain for gaining remote code execution on unpatched VMware vRealize Log Insight appliances. […]
28 Jan Hackers use new SwiftSlicer wiper to destroy Windows domains Security researchers have identified a new data-wiping malware they named SwiftSlicer that aims to overwrite crucial files used by the Windows operating system. […]
27 Jan The Week in Ransomware – January 27th 2023 – ‘We hacked the hackers’ For the most part, this week has been relatively quiet regarding ransomware attacks and researcher — that is, until the FBI announced the disruption of the Hive ransomware operation. […]
27 Jan Ukraine: Sandworm hackers hit news agency with 5 data wipers The Ukrainian Computer Emergency Response Team (CERT-UA) found a cocktail of five different data-wiping malware strains deployed on the network of the country’s national news agency (Ukrinform) on January 17th. […]
27 Jan PlugX malware hides on USB devices to infect new Windows hosts Security researchers have analyzed a variant of the PlugX malware that can hide malicious files on removable USB devices and then infect the Windows hosts they connect to. […]
26 Jan Microsoft urges admins to patch on-premises Exchange servers Microsoft urged customers today to keep their on-premises Exchange servers patched by applying the latest supported Cumulative Update (CU) to have them always ready to deploy an emergency security update. […]
26 Jan Bitwarden password vaults targeted in Google ads phishing attack Bitwarden and other password managers are being targeted in Google ads phishing campaigns to steal users’ password vault credentials. […]
26 Jan US offers $10M bounty for Hive ransomware links to foreign governments The U.S. Department of State today offered up to $10 million for information that could help link the Hive ransomware group (or other threat actors) with foreign governments. […]