News
-
"Maintainers Warn of Vulnerability Affecting Foundational Open-Source Tool"Two vulnerabilities have been announced by the maintainers of a popular open-source tool that provides foundational support for multiple network protocols, including SSL, TLS, HTTP, FTP, and SMTP.
-
"Recently Patched TagDiv Plugin Flaw Exploited to Hack Thousands of WordPress Sites"According to security researchers at Sucuri, a recently patched vulnerability affecting a plugin associated with the Newspaper and Newsmag themes has been exploited to hack thousands of WordPress websites as part of a long-running campaign named Balada
-
"Old-School Attacks Are Still a Danger, Despite Newer Techniques"Despite all the talk about new technologies such as ChatGPT and the growing complexity of attacks, cybercriminals continue to use numerous basic attacks because they are effective.
-
"New Magecart Campaign Alters 404 Error Pages to Steal Shoppers' Credit Cards"A Magecart campaign has been manipulating websites' default 404 error page to hide malicious code. According to Akamai, the activity targets Magento and WooCommerce websites, with some victims belonging to major food and retail companies.
-
"D-Link Wi-Fi Range Extender Vulnerable to Command Injection Attacks"The popular D-Link DAP-X1860 Wi-Fi 6 range extender is vulnerable to Denial-of-Service (DoS) and remote command injection.
-
"Dangerous Vulnerability Can Be Exploited to Carry Out Massive DDoS Attacks"Cloudflare, Google, and Amazon AWS have disclosed that a zero-day vulnerability called HTTP/2 Rapid Reset in the HTTP/2 protocol has been exploited to launch massive, high-volume Distributed Denial-of-Service (DDoS) attacks.
-
"Cable Giant Volex Targeted in Cyberattack"UK-based cable manufacturing giant Volex was recently targeted in a cyberattack involving unauthorized access to some of the company’s IT systems and data.
-
"DNA Tester 23andMe Hit By Credential Stuffing Campaign"A leading genetics testing firm recently confirmed that threat actors accessed customers’ profile information following a credential stuffing campaign.
-
"Google Expands Bug Bounty Program With Chrome, Cloud CTF Events"Google has recently announced the expansion of its vulnerability rewards program with two events focused on Chrome’s V8 JavaScript rendering engine and on Kernel-based Virtual Machine (KVM).
-
"DC Board of Elections Discloses Data Breach"The District of Columbia Board of Elections (DCBOE) recently confirmed that voter records were compromised in a data breach at a third-party services provider.
-
"Researchers Exploring a More Secure, Reliable Power Grid With UNC System Support"A team of researchers led by the University of North Carolina at Charlotte is working to develop a more secure and reliable power grid.
-
"Red Cross Issues Rules of Engagement for Civilian Hackers"The invasion of Ukraine by Russia prompted an unprecedented number of individuals to join patriotic cyber gangs.