News
-
"Ransomware Gang Threatens to Overthrow Costa Rica Government"The Russian-speaking ransomware gang Conti that infiltrated some Costa Rican government computer systems has upped its threat, saying its goal is now to overthrow the government. Conti attacked Costa Rica in April, accessing multiple critical systems in…
-
"Hackers Can Abuse Low-Power Mode to Run Malware on Powered-Off iPhones"Security researchers from a university in Germany have analyzed the low-power mode (LPM) implementation on iPhones and found that it introduces potentially serious security risks, even allowing attackers to run malware on powered-off devices. LPM…
-
"US Manufacturing Giant Parker Hit by Conti Ransomware Gang"US manufacturing company Parker-Hannifin Corporation has announced a data breach exposing employees’ personal identifiable information (PII) after Conti ransomware actors published reportedly stolen data last month. Parker-Hannifin Corporation is…
-
"How to Turn a Coke Can Into an Eavesdropping Device"According to a team of academics from Ben-Gurion University of the Negev, a soda can, a smartphone stand, or any bright lightweight desk decoration could lead to eavesdropping. This can even be done in a soundproof room if an attacker can see the object…
-
"Researchers Find 134 Flaws in the Way Word, PDFs, Handle Scripts"Security researchers have created a tool named Cooper that detects flaws in the way apps such as Microsoft Word and Adobe Acrobat process JavaScript. Through the use of Cooper, the researchers discovered 134 bugs, 59 of which have been deemed…
-
"'Sysrv' Botnet Targeting Recent Spring Cloud Gateway Vulnerability"Security researchers at Microsft are warning that a new variant of the Sysrv botnet has added a recent Spring Cloud Gateway vulnerability to its exploit portfolio. The Sysrv botnet has been active since at least late 2020, looking to exploit known…
-
"Ransomware Group Strikes Second U.S. Health Care System in The Last Two Months"A prolific ransomware group called AvosLocker recently hit a Dallas-based nonprofit Catholic health system with more than 600 facilities across four U.S. states, Mexico, Chile, and Colombia. The attack on CHRISTUS Health marks the second health…
-
"Post-Exploitation Framework Targets Microsoft Servers"Since at least 2021, a post-exploitation framework known as IceApple has been targeting global enterprises that employ Microsoft's extensible web server software and Microsoft Exchange servers, according to Falcon OverWatch, CrowdStrike's proactive…
-
"Fake Binance NFT Mystery Box Bots Steal Victim's Crypto Wallets"A new RedLine malware distribution campaign has been seen promoting fake Binance NFT mystery box bots on YouTube in order to trick people into downloading the information-stealing malware from GitHub repositories. Binance mystery boxes are collections of…
-
"New Google Team to Help Critical Open Source Projects Improve Security"Google is increasing its investment in open source software security by forming a new team of developers committed to assisting the maintainers of major open source projects in improving their software's security. The new Open Source Maintenance Crew is…
-
"Threat Actors Use Telegram to Spread ‘Eternity’ Malware-as-a-Service"Cybercrimals can find everything from information stealing to ransomware and crypto-mining modules offered by the Eternity Project as recently advertised on a popular Telegram channel. For prices ranging from $90 to $490, would be hackers can purchase…
-
"Cybersecurity Guidance for Supply Chain Risk Management"NIST releases new guidance for dealing with cybersecurity risks throughout the supply chain. Supply chain is a vital part of global commerce. But vulnerabilities in the technology used to manage it can cause problems for businesses and their customers.…