26 Jun LockBit lied: Stolen data is from a bank, not US Federal Reserve Recently-disrupted LockBit ransomware group, in a desperate attempt to make a comeback, claimed this week that it had hit the Federal Reserve, the central bank of the United States. Except, the rumor has been quashed. […]
26 Jun CISA: Most critical open source projects not using memory safe code The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has published research looking into 172 key open-source projects and whether they are susceptible to memory flaws. […]
26 Jun Exploit for critical Fortra FileCatalyst Workflow SQLi flaw released The Fortra FileCatalyst Workflow is vulnerable to an SQL injection vulnerability that could allow remote unauthenticated attackers to create rogue admin users and manipulate data on the application database. […]
26 Jun Hackers target new MOVEit Transfer critical auth bypass bug Threat actors are attempting to exploit a critical authentication bypass flaw impacting Progress MOVEit Transfer, which the vendor disclosed yesterday. […]
25 Jun Plugins on WordPress.org backdoored in supply chain attack A threat actor modified the source code of at least five plugins hosted on WordPress.org to include malicious PHP scripts that create new accounts with administrative privileges on websites running them. […]
25 Jun Polyfill.io JavaScript supply chain attack impacts over 100K sites Over 100,000 sites have been impacted in a supply chain attack by the Polyfill.io service after a Chinese company acquired the domain and the script was modified to redirect users to malicious and scam sites. […]
25 Jun New Medusa malware variants target Android users in seven countries The Medusa banking trojan for Android has re-emerged after almost a year of keeping a lower profile in campaigns targeting France, Italy, the United States, Canada, Spain, the United Kingdom, and Turkey. […]
25 Jun Neiman Marcus confirms data breach after Snowflake account hack Luxury retailer Neiman Marcus confirmed it suffered a data breach after hackers attempted to sell the company’s database stolen in recent Snowflake data theft attacks. […]
25 Jun FBI warns of fake law firms targeting crypto scam victims The FBI is warning of cybercriminals posing as law firms and lawyers that offer cryptocurrency recovery services to victims of investment scams and steal funds and personal information. […]
24 Jun New attack uses MSC files and Windows XSS flaw to breach networks A novel command execution technique dubbed ‘GrimResource’ uses specially crafted MSC (Microsoft Saved Console) and an unpatched Windows XSS flaw to perform code execution via the Microsoft Management Console. […]