14 Jul Mantis botnet behind the record-breaking DDoS attack in June The record-breaking distributed denial-of-service (DDoS) attack that Cloudflare mitigated last month originated from a new botnet called Mantis, which is currently described as “the most powerful botnet to date.” […]
14 Jul New Retbleed speculative execution CPU attack bypasses Retpoline fixes Security researchers have discovered a new speculative execution attack called Retbleed that affects processors from both Intel and AMD and could be used to extract sensitive information. […]
13 Jul New Lilith ransomware emerges with extortion site, lists first victim A new ransomware operation has been launched under the name ‘Lilith,’ and it has already posted its first victim on a data leak site created to support double-extortion attacks. […]
13 Jul New Android malware on Google Play installed 3 million times A new Android malware family on the Google Play Store that secretly subscribes users to premium services was downloaded over 3,000,000 times. […]
13 Jul $8 million stolen in large-scale Uniswap airdrop phishing attack Uniswap, a popular decentralized cryptocurrency exchange, lost close to $8 million worth of Ethereum in a sophisticated phishing attack yesterday. […]
12 Jul VMware patches vCenter Server flaw disclosed in November Eight months after disclosing a high-severity privilege escalation flaw in vCenter Server’s IWA (Integrated Windows Authentication) mechanism, VMware has finally released a patch for one of the affected versions. […]
12 Jul Microsoft fixes dozens of Azure Site Recovery privilege escalation bugs Microsoft has fixed 32 vulnerabilities in the Azure Site Recovery suite that could have allowed attackers to gain elevated privileges or perform remote code execution. […]
12 Jul CISA orders agencies to patch new Windows zero-day used in attacks CISA has added an actively exploited local privilege escalation vulnerability in the Windows Client/Server Runtime Subsystem (CSRSS) to its list of bugs abused in the wild. […]
12 Jul New ‘Luna Moth’ hackers breach orgs via fake subscription renewals A new data extortion group has been breaching companies to steal confidential information, threatening victims to make the files publicly available unless they pay a ransom. […]
11 Jul Hackers can unlock Honda cars remotely in Rolling-PWN attacks A team of security researchers found that several modern Honda car models have a vulnerable rolling code mechanism that allows unlocking the cars or even starting the engine remotely. […]