25 Oct Microsoft: Vice Society targets schools with multiple ransomware families A threat group known as Vice Society has been switching ransomware payloads in attacks targeting the education sector across the United States and worldwide. […]
25 Oct Dutch police arrest hacker who breached healthcare software vendor The Dutch police have arrested a 19-year-old man in western Netherlands, suspected of breaching the systems of a healthcare software vendor in the country, and stealing tens of thousands of documents. […]
24 Oct Chrome extensions with 1 million installs hijack targets’ browsers Researchers at Guardio Labs have discovered a new malvertizing campaign pushing Google Chrome and Microsoft Edge extensions that hijack searches and insert affiliate links into webpages. […]
24 Oct Apple fixes new zero-day used in attacks against iPhones, iPads In security updates released on Monday, Apple has fixed the ninth zero-day vulnerability used in attacks against iPhones since the start of the year. […]
24 Oct Iran’s atomic energy agency confirms hack after stolen data leaked online The Iranian Atomic Energy Organization (AEOI) has confirmed that one of its subsidiaries’ email servers was hacked after the ”Black Reward’ hacking group published stolen data online. […]
23 Oct Thousands of GitHub repositories deliver fake PoC exploits with malware Researchers at the Leiden Institute of Advanced Computer Science found thousands of repositories on GitHub that offer fake proof-of-concept (PoC) exploits for various vulnerabilities, some of them including malware. […]
23 Oct Typosquat campaign mimics 27 brands to push Windows, Android malware A massive, malicious campaign is underway using over 200 typosquatting domains that impersonate twenty-seven brands to trick visitors into downloading various Windows and Android malware. […]
22 Oct Android adware apps in Google Play downloaded over 20 million times Security researchers at McAfee have discovered a set of 16 malicious clicker apps that managed to sneak into Google Play, the official app store for Android. […]
22 Oct TommyLeaks and SchoolBoys: Two sides of the same ransomware gang Two new extortion gangs named ‘TommyLeaks’ and ‘SchoolBoys’ are targeting companies worldwide. However, there is a catch — they are both the same ransomware gang. […]
22 Oct Exploited Windows zero-day lets JavaScript files bypass security warnings A new Windows zero-day allows threat actors to use malicious JavaScript files to bypass Mark-of-the-Web security warnings. Threat actors are already seen using the zero-day bug in ransomware attacks. […]