03 Dec Zoho: Patch new ManageEngine bug exploited in attacks ASAP Business software provider Zoho urged customers today to update their Desktop Central and Desktop Central MSP installations to the latest available version. […]
02 Dec Phishing actors start exploiting the Omicron COVID-19 variant Phishing actors have quickly started to exploit the emergence of the Omicron COVID-19 variant and now use it as a lure in their malicious email campaigns. […]
02 Dec Hackers use in-house Zoho ServiceDesk exploit to drop webshells An advanced persistent threat (APT) group that had been exploiting a flaw in the Zoho ManageEngine ADSelfService Plus software has pivoted to leveraging a different vulnerability in another Zoho product. […]
02 Dec Nine WiFi routers used by millions were vulnerable to 226 flaws Security researchers analyzed nine popular WiFi routers and found a total of 226 potential vulnerabilities in them, even when running the latest firmware. […]
02 Dec New malware hides as legit nginx process on e-commerce servers eCommerce servers are being targeted with remote access malware that hides on Nginx servers in a way that makes it virtually invisible to security solutions. […]
02 Dec Planned Parenthood LA discloses data breach after ransomware attack Planned Parenthood Los Angeles has disclosed a data breach after suffering a ransomware attack in October that exposed the personal information of approximately 400,000 patients. […]
01 Dec Malicious Android app steals Malaysian bank credentials, MFA codes A fake Android app is masquerading as a housekeeping service to steal online banking credentials from the customers of eight Malaysian banks. […]
01 Dec Mozilla fixes critical bug in cross-platform cryptography library Mozilla has addressed a critical memory corruption vulnerability affecting its cross-platform Network Security Services (NSS) set of cryptography libraries. […]
01 Dec Microsoft Exchange servers hacked to deploy BlackByte ransomware BlackByte ransomware actors were observed exploiting the ProxyShell set of vulnerabilities (CVE-2021-34473, CVE-2021-34523, CVE-2021-31207) to compromise Microsoft Exchange servers. […]
01 Dec VirusTotal Collections feature helps keep neat IoC lists Scanning service VirusTotal announced today a new feature called Collections that lets researchers create and share reports with indicators of compromise observed in security incidents. […]