14 Dec FBI seized domains linked to 48 DDoS-for-hire service platforms The US Department of Justice has seized 48 Internet domains and charged six suspects for their involvement in running ‘Booter’ or ‘Stresser’ platforms that allow anyone to easily conduct distributed denial of service attacks. […]
14 Dec Attackers use SVG files to smuggle QBot malware onto Windows systems QBot malware phishing campaigns have adopted a new distribution method using SVG files to perform HTML smuggling that locally creates a malicious installer for Windows. […]
14 Dec Microsoft patches Windows zero-day used to drop ransomware Microsoft has fixed a security vulnerability used by threat actors to circumvent the Windows SmartScreen security feature and deliver Magniber ransomware and Qbot malware payloads. […]
14 Dec VMware fixes critical ESXi and vRealize security flaws VMware released security updates to address a critical-severity vulnerability impacting ESXi, Workstation, Fusion, and Cloud Foundation, and a critical-severity command injection flaw affecting vRealize Network Insight. […]
13 Dec Microsoft-signed malicious Windows drivers used in ransomware attacks Microsoft has revoked several Microsoft hardware developer accounts after drivers signed through their profiles were used in cyberattacks, including ransomware incidents. […]
13 Dec LockBit claims attack on California’s Department of Finance The Department of Finance in California has been the target of a cyberattack now claimed by the LockBit ransomware gang. […]
13 Dec Apple security update fixes new iOS zero-day used to hack iPhones In security updates released today, Apple has fixed the tenth zero-day vulnerability since the start of the year, with this latest one actively used in attacks against iPhones. […]
12 Dec Play ransomware claims attack on Belgium city of Antwerp The Play ransomware operation has claimed responsibility for a recent cyberattack on the Belgium city of Antwerp. […]
12 Dec New Python malware backdoors VMware ESXi servers for remote access A previously undocumented Python backdoor targeting VMware ESXi servers has been spotted, enabling hackers to execute commands remotely on a compromised system. […]
12 Dec Twitter confirms recent user data leak is from 2021 breach Twitter confirmed today that the recent leak of millions of members’ profiles, including private phone numbers and email addresses, resulted from the same data breach the company disclosed in August 2022. […]