24 Sep Hackers exploiting critical VMware vCenter CVE-2021-22005 bug Exploit code that could be used for remote code execution on VMware vCenter Server vulnerable to CVE-2021-22005 has been released today and attackers are already using it. […]
24 Sep Emergency Google Chrome update fixes zero-day exploited in the wild Google has released Chrome 94.0.4606.61 for Windows, Mac, and Linux, an emergency update addressing a high-severity zero-day vulnerability exploited in the wild. […]
24 Sep Microsoft rushes to register Autodiscover domains leaking credentials Microsoft is rushing to register Internet domains used to steal Windows credentials sent from faulty implementations of the Microsoft Exchange Autodiscover protocol. […]
24 Sep EU officially blames Russia for ‘Ghostwriter’ hacking activities The European Union has officially linked Russia to a hacking operation known as Ghostwriter that targets high-profile EU officials, journalists, and the general public. […]
24 Sep Exploit code released for three iOS 0-days that Apple failed to patch Proof-of-concept exploit code for three iOS zero-day vulnerabilities (and a fourth one patched in July) was published on GitHub after Apple delayed patching and failed to credit the researcher. […]
24 Sep Cisco fixes highly critical vulnerabilities in IOS XE Software Cisco has patched three critical vulnerabilities affecting components in its IOS XE internetworking operating system powering routers and wireless controllers, or products running with a specific configuration. […]
24 Sep SonicWall fixes critical bug allowing SMA 100 device takeover SonicWall has patched a critical security flaw impacting several Secure Mobile Access (SMA) 100 series products that can let unauthenticated attackers remotely gain admin access on targeted devices. […]
23 Sep REVil ransomware devs added a backdoor to cheat affiliates Cybercriminals are slowly realizing that the REvil ransomware operators have been hijacking ransom negotiations, to cut affiliates out of payments. […]
22 Sep Hackers are scanning for VMware CVE-2021-22005 targets, patch now! Threat actors have already started targeting Internet-exposed VMware vCenter servers unpatched against a critical arbitrary file upload vulnerability patched yesterday that could lead to remote code execution. […]
22 Sep FBI, CISA, and NSA warn of escalating Conti ransomware attacks CISA, the Federal Bureau of Investigation (FBI), and the National Security Agency (NSA) warned today of an increased number of Conti ransomware attacks targeting US organizations. […]