18 Jan Ukraine links data-wiping attack on news agency to Russian hackers The Computer Emergency Response Team of Ukraine (CERT-UA) has linked a destructive malware attack targeting the country’s national news agency (Ukrinform) to Sandworm Russian military hackers. […]
18 Jan Illegal Solaris darknet market hijacked by competitor Kraken Solaris, a large darknet marketplace focused on drugs and illegal substances, has been taken over by a smaller competitor named ‘Kraken,’ who claims to have hacked it on January 13, 2022. […]
18 Jan Avast releases free BianLian ransomware decryptor Security software company Avast has released a free decrypter for the BianLian ransomware strain to help victims of the malware restore their files without paying a ransom. […]
17 Jan Git patches two critical remote code execution security flaws Git has patched two critical severity security vulnerabilities that could allow attackers to execute arbitrary code after successfully exploiting heap-based buffer overflow weaknesses. […]
17 Jan Hackers turn to Google search ads to push info-stealing malware Hackers are setting up fake websites for popular free and open-source software to promote malicious downloads through advertisements in Google search results. […]
17 Jan Hackers can use GitHub Codespaces to host and deliver malware GitHub Codespaces, a cloud-hosted integrated development environment (IDE), has a port forwarding feature that malicious actors can abuse to host and distribute malware to unaware developers. […]
17 Jan Over 4,000 Sophos Firewall devices vulnerable to RCE attacks Over 4,000 Sophos Firewall devices exposed to Internet access are vulnerable to attacks targeting a critical remote code execution (RCE) vulnerability. […]
16 Jan Researchers to release PoC exploit for critical Zoho RCE bug, patch now Proof-of-concept exploit code will be released later this week for a critical vulnerability allowing remote code execution (RCE) without authentication in several VMware products. […]
16 Jan MSI accidentally breaks Secure Boot for hundreds of motherboards Over 290 MSI motherboards are reportedly affected by an insecure default UEFI Secure Boot setting settings that allows any operating system image to run regardless of whether it has a wrong or missing signature. […]
16 Jan Vice Society ransomware leaks University of Duisburg-Essen’s data The Vice Society ransomware gang has claimed responsibility for the November 2022 cyberattack that forced the University of Duisburg-Essen (UDE) to reconstruct its IT infrastructure, a process that’s still ongoing. […]