05 Oct MosaicRegressor: Second-ever UEFI rootkit found in the wild The second-ever UEFI rootkit used in the wild was found by security researchers during investigations surrounding attacks from 2019 against two non-governmental organizations (NGOs). […]
04 Oct New ransomware vaccine kills programs wiping Windows shadow volumes A new ransomware vaccine program has been created that terminates processes that try to delete volume shadow copies using Microsoft’s vssadmin.exe program, […]
03 Oct Online avatar service Gravatar allows mass collection of user info A user enumeration method discovered by an Italian security researcher Carlo Di Dato demonstrates how can Gravatar data be easily scraped by web crawlers and bots. […]
03 Oct New Jersey hospital paid ransomware gang $670K to prevent data leak University Hospital New Jersey in Newark, New Jersey, paid a $670,000 ransomware demand this month to prevent the publishing of 240 GB of stolen data, including patient info. […]
02 Oct The Week in Ransomware – October 2nd 2020 – Healthcare under attack This week started with a bang as a large hospital chain was hit by a ransomware attack that disrupted the healthcare industry. […]
02 Oct Grindr fixed a bug allowing full takeover of any user account Grindr has fixed a security flaw that could have allowed attackers to easily hijack any Grindr account if they knew the user’s email address. […]
02 Oct Google now discloses Android vulnerabilities for 3rd-party devices Google today announced the launch of a new program specifically designed to deal with security vulnerabilities the company finds in devices and software serviced by Android OEMs. […]
02 Oct HP Device Manager backdoor lets attackers take over Windows systems HP released a security advisory detailing three critical and high severity vulnerabilities in the HP Device Manager that could lead to system takeover. […]
02 Oct Microsoft now provides Defender updates for Windows install images Microsoft released a new tool designed to patch Windows 10 and Windows Server installation images with the latest Microsoft Defender updates to minimize the protection gap systems face until anti-malware definitions are updated. […]
02 Oct Top sites infiltrated with credit card skimmers and crypto miners An investigation conducted into the top 10,000 Alexa sites by Palo Alto Networks reveals many of these popular websites are infected with cryptocurrency miners and credit card skimming scripts. […]