News
-
"VoltSchemer Attacks Use Wireless Chargers to Inject Voice Commands, Fry Phones"Researchers from the University of Florida and CertiK have demonstrated a new set of attacks dubbed VoltSchemer that can inject voice commands to manipulate a smartphone's voice assistant via the magnetic field emitted by an off-the-shelf wireless char
-
"Chrome 122, Firefox 123 Patch High-Severity Vulnerabilities"Google and Mozilla recently released Chrome and Firefox software updates to resolve multiple vulnerabilities in both browsers, including high-severity memory safety bugs.
-
"Hybrid Security in the Cloud - Improving Cloud Security Model for Web Applications Using Hybrid Encryption Techniques"A team of researchers in India developed a hybrid approach to improving the security of online applications, particularly within cloud computing.
-
"'KeyTrap' DNS Bug Threatens Widespread Internet Outages"Researchers recently discovered a fundamental design flaw in a Domain Name System (DNS) security extension that could lead to widespread Internet outages.
-
"36% of Code Generated by GitHub CoPilot Contains Security Flaws"According to Veracode, 42 percent of applications and 71 percent of organizations have security debt, which is defined as flaws that have gone unfixed for more than a year.
-
"Knight Ransomware Source Code for Sale After Leak Site Shuts Down"A representative of the Knight ransomware is selling the alleged source code for version 3.0 of the ransomware on a hacker forum.
-
"New Malicious PyPI Packages Caught Using Covert Side-Loading Tactics"Researchers have found two malicious packages on the Python Package Index (PyPI) repository that used a technique known as DLL side-loading to avoid detection by security software and execute malicious code.
-
"Websites Hacked via Vulnerability in Bricks Builder WordPress Plugin"According to security researchers at Patchstack, hackers are exploiting a recently patched vulnerability in the Bricks Builder plugin for WordPress to hack websites and deploy malware.
-
"New Redis Attack Campaign Weakens Systems Before Deploying Cryptominer"Researchers warn that cloud attackers have launched a new cryptocurrency jacking campaign targeting exposed Redis deployments.
-
"28,500 Microsoft Exchange Servers Vulnerable"It has been confirmed that 28,500 Microsoft Exchange servers are vulnerable to Elevation of Privilege (EoP), putting affected organizations at risk because many users rely on Exchange for work.
-
"'MrAgent' Ransomware Tool From RansomHouse Group Targets ESXi Servers"MrAgent is a new ransomware tool that operates as a binary designed to run mainly on VMware ESXi hypervisors. Its purpose is to automate and track ransomware deployment across large environments with multiple hypervisors.
-
"Cactus Ransomware Gang Claims the Theft of 1.5TB of Data From Energy Management and Industrial Automation Firm Schneider Electric"The Cactus ransomware group claims to have stolen 1.5TB of data from the energy management and industrial automation company Schneider Electric.