18 Jul Revolver Rabbit gang registers 500,000 domains for malware campaigns A cybercriminal gang that researchers track as Revolver Rabbit has registered more than 500,000 domain names for infostealer campaigns that target Windows and macOS systems. […]
18 Jul SolarWinds fixes 8 critical bugs in access rights audit software SolarWinds has fixed eight critical vulnerabilities in its Access Rights Manager (ARM) software, six of which allowed attackers to gain remote code execution (RCE) on vulnerable devices. […]
18 Jul Critical Cisco bug lets hackers add root users on SEG devices Cisco has fixed a critical severity vulnerability that lets attackers add new users with root privileges and permanently crash Security Email Gateway (SEG) appliances using emails with malicious attachments. […]
17 Jul Notorious FIN7 hackers sell EDR killer to other threat actors The notorious FIN7 hacking group has been spotted selling its custom “AvNeutralizer” tool, used to evade detection by killing enterprise endpoint protection software on corporate networks. […]
17 Jul Exchange Online adds Inbound DANE with DNSSEC for security boost Microsoft is rolling out inbound SMTP DANE with DNSSEC for Exchange Online in public preview, a new capability to boost email integrity and security. […]
17 Jul Cisco SSM On-Prem bug lets hackers change any user’s password Cisco has fixed a maximum severity vulnerability that allows attackers to change any user’s password on vulnerable Cisco Smart Software Manager On-Prem (Cisco SSM On-Prem) license servers, including administrators. […]
17 Jul Over 400,000 Life360 user phone numbers leaked via unsecured API A threat actor has leaked a database containing the personal information of 442,519 Life360 customers collected by abusing a flaw in the login API. […]
17 Jul Yacht giant MarineMax data breach impacts over 123,000 people MarineMax, self-described as the world’s largest recreational boat and yacht retailer, is notifying over 123,000 customers whose personal information was stolen in a March security breach claimed by the Rhysida ransomware gang. […]
16 Jul CISA warns critical Geoserver GeoTools RCE flaw is exploited in attacks CISA is warning that a critical GeoServer GeoTools remote code execution flaw tracked as CVE-2024-36401 is being actively exploited in attacks. […]
16 Jul Email addresses of 15 million Trello users leaked on hacking forum A threat actor has released over 15 million email addresses associated with Trello accounts that were collected using an unsecured API in January. […]