15 Jul Attackers scan 1.6 million WordPress sites for vulnerable plugin Security researchers have detected a massive campaign that scanned close to 1.6 million WordPress sites for the presence of a vulnerable plugin that allows uploading files without authentication. […]
14 Jul Microsoft links Holy Ghost ransomware operation to North Korean hackers For more than a year, North Korean hackers have been running a ransomware operation called HolyGhost, attacking small businesses in various countries. […]
14 Jul PayPal phishing kit added to hacked WordPress sites for full ID theft A newly discovered phishing kit targeting PayPal users is trying to steal a large set of personal information from victims that includes government identification documents and photos. […]
14 Jul Mantis botnet behind the record-breaking DDoS attack in June The record-breaking distributed denial-of-service (DDoS) attack that Cloudflare mitigated last month originated from a new botnet called Mantis, which is currently described as “the most powerful botnet to date.” […]
14 Jul New Retbleed speculative execution CPU attack bypasses Retpoline fixes Security researchers have discovered a new speculative execution attack called Retbleed that affects processors from both Intel and AMD and could be used to extract sensitive information. […]
13 Jul New Lilith ransomware emerges with extortion site, lists first victim A new ransomware operation has been launched under the name ‘Lilith,’ and it has already posted its first victim on a data leak site created to support double-extortion attacks. […]
13 Jul New Android malware on Google Play installed 3 million times A new Android malware family on the Google Play Store that secretly subscribes users to premium services was downloaded over 3,000,000 times. […]
13 Jul $8 million stolen in large-scale Uniswap airdrop phishing attack Uniswap, a popular decentralized cryptocurrency exchange, lost close to $8 million worth of Ethereum in a sophisticated phishing attack yesterday. […]
12 Jul VMware patches vCenter Server flaw disclosed in November Eight months after disclosing a high-severity privilege escalation flaw in vCenter Server’s IWA (Integrated Windows Authentication) mechanism, VMware has finally released a patch for one of the affected versions. […]
12 Jul Microsoft fixes dozens of Azure Site Recovery privilege escalation bugs Microsoft has fixed 32 vulnerabilities in the Azure Site Recovery suite that could have allowed attackers to gain elevated privileges or perform remote code execution. […]