22 May PDF smuggles Microsoft Word doc to drop Snake Keylogger malware Threat analysts have discovered a recent malware distribution campaign using PDF attachments to smuggle malicious Word documents that infect users with malware. […]
22 May Google: Predator spyware infected Android devices using zero-days Google’s Threat Analysis Group (TAG) says that state-backed threat actors used five zero-day vulnerabilities to install Predator spyware developed by commercial surveillance developer Cytrox. […]
21 May Ransomware attack exposes data of 500,000 Chicago students The Chicago Public Schools has suffered a massive data breach that exposed the data of almost 500,000 students and 60,000 employee after their vendor, Battelle for Kids, suffered a ransomware attack in December. […]
21 May Malicious PyPI package opens backdoors on Windows, Linux, and Macs Yet another malicious Python package has been spotted in the PyPI registry performing supply chain attacks to drop Cobalt Strike beacons and backdoors on Windows, Linux, and macOS systems. […]
21 May Windows 11 hacked three more times on last day of Pwn2Own contest On the third and last day of the 2022 Pwn2Own Vancouver hacking contest, security researchers successfully hacked Microsoft’s Windows 11 operating system three more times using zero-day exploits. […]
20 May The Week in Ransomware – May 20th 2022 – Another one bites the dust Ransomware attacks continue to slow down, likely due to the invasion of Ukraine, instability in the region, and subsequent worldwide sanctions against Russia. […]
20 May Cisco urges admins to patch IOS XR zero-day exploited in attacks Cisco has addressed a zero-day vulnerability in its IOS XR router software that allowed unauthenticated attackers to remotely gain access to Redis instances running in NOSi Docker containers. […]
20 May Backdoor baked into premium school management plugin for WordPress Security researchers have discovered a backdoor in a premium WordPress plugin built as a complete management solution for schools. The malicious code enables a threat actor to execute PHP code without authenticating. […]
20 May Windows 11 hacked again at Pwn2Own, Telsa Model 3 also falls During the second day of the Pwn2Own Vancouver 2022 hacking competition, contestants hacked Microsoft’s Windows 11 OS again and demoed zero-days in Tesla Model 3’s infotainment system. […]
20 May Russian Sberbank says it’s facing massive waves of DDoS attacks Sberbank’s vice president and director of cybersecurity, Sergei Lebed, has told participants of the Positive Hack Days forum that the company is going through a period of unprecedented targeting by hackers. […]