11 Oct All Windows versions can now block admin brute-force attacks Microsoft announced today that IT admins can now configure any Windows system still receiving security updates to automatically block brute force attacks targeting local administrator accounts via a group policy. […]
11 Oct Android leaks some traffic even when ‘Always-on VPN’ is enabled Mullvad VPN has discovered that Android leaks traffic every time the device connects to a WiFi network, even if the “Block connections without VPN,” or “Always-on VPN,” features is enabled. […]
11 Oct VMware vCenter Server bug disclosed last year still not patched VMware informed customers today that vCenter Server 8.0 (the latest version) is still waiting for a patch to address a high-severity privilege escalation vulnerability disclosed in November 2021. […]
10 Oct Caffeine service lets anyone launch Microsoft 365 phishing attacks A phishing-as-a-service (PhaaS) platform named ‘Caffeine’ makes it easy for threat actors to launch attacks, featuring an open registration process allowing anyone to jump in and start their own phishing campaigns. […]
10 Oct Hackers behind IcedID malware attacks diversify delivery tactics The threat actors behind IcedID malware phishing campaigns are utilizing a wide variety of distribution methods, likely to determine what works best against different targets. […]
10 Oct Toyota discloses data leak after access key exposed on GitHub Toyota Motor Corporation is warning that customers’ personal information may have been exposed after an access key was publicly available on GitHub for almost five years. […]
10 Oct Fortinet says critical auth bypass bug is exploited in attacks Fortinet has confirmed today that a critical authentication bypass security vulnerability patched last week is being exploited in the wild. […]
10 Oct US airports’ sites taken down in DDoS attacks by pro-Russian hackers The pro-Russian hacktivist group ‘KillNet’ is claiming large-scale distributed denial-of-service (DDoS) attacks against the websites of several major airports in the U.S., making them unaccessible. […]
09 Oct Intel confirms leaked Alder Lake BIOS Source Code is authentic Intel has confirmed that a source code leak for the UEFI BIOS of Alder Lake CPUs is authentic and has been released by a third party. […]
09 Oct Solana Phantom security update NFTs push password-stealing malware Hackers are airdropping NFTs to Solana cryptocurrency owners pretending to be alerts for a new Phantom security update that lead to the installation of password-stealing malware and the theft of cryptocurrency wallets. […]