01 Sep Hackers breached Norwegian Parliament emails to steal data Attackers have compromised a limited number of email accounts of Norwegian Parliament (Storting) representatives and employees according to Storting’s managing director Marianne Andreassen. […]
01 Sep Google now pays for bugs used to bypass its anti-fraud systems Google today announced that the company’s Vulnerability Reward Program has expanded to also include bug reports on methods threat actors can use to bypass the company’s abuse, fraud, and spam systems. […]
01 Sep Iranian hackers are selling access to corporate networks An Iranian-backed hacker group has been observed while seeking to sell access to compromised corporate networks to other threat actors on underground forums and attempting to exploit F5 BIG-IP devices vulnerable to CVE-2020-5902 exploits. […]
31 Aug American Payroll Association discloses credit card theft incident The American Payroll Association (APA) disclosed a data breach affecting members and customers after attackers successfully planted a web skimmer on the organization’s website login and online store checkout pages. […]
31 Aug Malware authors trick Apple into trusting malicious Shlayer apps The authors of the Mac malware known as Shlayer have successfully managed to get their malicious payloads through Apple’s automated notarizing process. […]
31 Aug Hackers are backdooring QNAP NAS devices with 3-year old RCE bug Hackers are scanning for vulnerable network-attached storage (NAS) devices running multiple QNAP firmware versions, trying to exploit a remote code execution (RCE) vulnerability addressed by QNAP in a previous release. […]
30 Aug Slack pays stingy $1,750 reward for a desktop hijack vulnerability A researcher responsibly disclosed multiple vulnerabilities to Slack that allowed an attacker to hijack a user’s computer, and they were only rewarded a measly $1,750. […]
29 Aug Emotet malware’s new ‘Red Dawn’ attachment is just as dangerous The Emotet botnet has begun to use a new template for their malicious attachments, and it is just as dangerous as ever. […]
29 Aug Why streaming a video could freeze Microsoft IIS servers Microsoft August 2020 security patch fixed over 120 flaws. One of these flaws lets anyone freeze IIS servers by streaming videos, and seeking through them fast. […]
28 Aug Single & penniless: FBI warns of $475M lost to romance scams The Federal Bureau of Investigation is warning of online romance scams, an ongoing online fraud trend that can lead to large financial losses, as well as devastating emotional scars. […]