News
-
"Chrome 127 Patches 24 Vulnerabilities"Google recently announced the release of Chrome 127 to the stable channel with patches for 24 vulnerabilities, including 16 reported by external researchers.
-
"PINEAPPLE and FLUXROOT Hacker Groups Abuse Google Cloud for Credential Phishing""FLUXROOT," a Latin America (LATAM)-based financially motivated actor, has used Google Cloud serverless projects to conduct credential phishing, bringing further attention to the abuse of cloud computing.
-
"Ad-Injecting Malware Posing as DwAdsafe Ad Blocker Uses Microsoft-Signed Driver"ESET researchers have found a sophisticated Chinese browser injector. This signed ad-injecting driver comes from a "mysterious" Chinese company.
-
"Fake CrowdStrike Repair Manual Pushes New Infostealer Malware"CrowdStrike warns of a fake recovery manual that installs a new information-stealing malware called "Daolpu." Threat actors have been taking advantage of the chaos surrounding the buggy CrowdStrike Falcon update that caused global Information Technolog
-
"Swipe Right for Data Leaks: Dating Apps Expose Location, More"Karel Dhondt and Victor Le Pochat, researchers at KU Leuven, found that many dating apps may leak users' sensitive data and exact locations. They analyzed 15 location-based dating apps to determine what user data a malicious actor could steal.
-
"Play Ransomware Expands to Target VMWare ESXi Environments"Trend Micro reports that the "Play" ransomware group now has a Linux variant targeting VMWare ESXi environments.
-
"Chinese Espionage Group Upgrades Malware Arsenal to Target All Major OS"Symantec found that the Chinese espionage group "Daggerfly," also known as "Evasive Panda" and "Bronze Highland," has updated its malware toolkit to target most major operating systems.
-
"Telegram Zero-Day Enabled Malware Delivery"ESET warns that Telegram for Android was exploited to distribute malware disguised as videos.
-
"FrostyGoop ICS Malware Left Ukrainian City's Residents Without Heating"In January 2024, the Industrial Control System (ICS) malware "FrostyGoop" disrupted systems at a municipal district energy company in the Ukrainian city of Lvivy.
-
"Microsoft Says 8.5 Million Windows Devices Impacted by CrowdStrike Incident, Publishes Recovery Tool"According to Microsoft, CrowdStrike's faulty software update, which caused massive Information Technology (IT) outages worldwide, affected 8.5 million Windows devices.
-
"CrowdStrike Incident Leveraged for Malware Delivery, Phishing, Scams"After the cybersecurity company CrowdStrike pushed a routine sensor configuration update that caused a logic error and a Blue Screen of Death (BSOD) on Windows systems, many organizations worldwide were disrupted.
-
"SwRI Evaluates Cybersecurity Risks Associated With EV Fast-Charging Equipment"Southwest Research Institute (SwRI) engineers have identified cybersecurity vulnerabilities with Electric Vehicles (EVs) using direct current fast-charging systems.