28 Jan Finland warns of Facebook accounts hijacked via Messenger phishing Finland’s National Cyber Security Centre (NCSC-FI) warns of an ongoing phishing campaign attempting to hijack Facebook accounts by impersonating victims’ friends in Facebook Messenger chats. […]
28 Jan Microsoft Outlook RCE zero-day exploits now selling for $400,000 Exploit broker Zerodium has announced a pay jump to 400,000 for zero-day vulnerabilities that allow remote code execution (RCE) in Microsoft Outlook email client. […]
28 Jan QNAP force-installs update after DeadBolt ransomware hits 3,600 devices QNAP force-updated customer’s Network Attached Storage (NAS) devices with firmware containing the latest security updates to protect against the DeadBolt ransomware, which has already encrypted over 3,600 devices. […]
27 Jan DeepDotWeb admin imprisoned for advertising illegal dark web markets An Israeli citizen who operated DeepDotWeb (DDW), a news site and review site for dark web sites, has received a sentence of 97 months in prison for money laundering and was ordered to forfeit $8,414,173. […]
27 Jan Taiwanese Apple and Tesla contractor hit by Conti ransomware Delta Electronics, a Taiwanese electronics company and a provider for Apple, Tesla, HP, and Dell, disclosed that it was the victim of a cyberattack discovered on Friday morning. […]
27 Jan Lazarus hackers use Windows Update to deploy malware North Korean-backed hacking group Lazarus has added the Windows Update client to its list of living-off-the-land binaries (LoLBins) and is now actively using it to execute malicious code on Windows systems. […]
27 Jan Microsoft warns of multi-stage phishing campaign leveraging Azure AD Microsoft’s threat analysts have uncovered a large-scale, multi-phase phishing campaign that uses stolen credentials to register devices onto the target’s network and use them to distribute phishing emails. […]
26 Jan Linux version of LockBit ransomware targets VMware ESXi servers LockBit is the latest ransomware gang whose Linux encryptor has been discovered to be focusing on the encryption of VMware ESXi virtual machines. […]
26 Jan Apple fixes new zero-day exploited to hack macOS, iOS devices Apple has released security updates to fix two zero-day vulnerabilities, with one publicly disclosed and the other exploited in the wild by attackers to hack into iPhones and Macs. […]
26 Jan Chaes banking trojan hijacks Chrome with malicious extensions A large-scale campaign involving over 800 compromised WordPress websites is spreading banking trojans that target the credentials of Brazilian e-banking users. […]