Malware & Threats

Adobe Patches Code Execution Flaws in Substance 3D Stager

Adobe Patches Code Execution Flaws in Substance 3D Stager 2024-01-09 at 20:02 By Ryan Naraine Patch Tuesday: Adobe patches six security flaws in the Substance 3D Stager product and warned of code execution risks on Windows and macOS. The post Adobe Patches Code Execution Flaws in Substance 3D Stager appeared first on SecurityWeek. This article […]

Adobe Patches Code Execution Flaws in Substance 3D Stager Read More »

Turkish Hackers Target Microsoft SQL Servers in Americas, Europe

Turkish Hackers Target Microsoft SQL Servers in Americas, Europe 2024-01-09 at 18:32 By Ionut Arghire Researchers at Securonix warn that Turkish threat actors are targeting organizations in the Americas and Europe with ransomware campaigns. The post Turkish Hackers Target Microsoft SQL Servers in Americas, Europe appeared first on SecurityWeek. This article is an excerpt from

Turkish Hackers Target Microsoft SQL Servers in Americas, Europe Read More »

New ‘SpectralBlur’ macOS Backdoor Linked to North Korea

New ‘SpectralBlur’ macOS Backdoor Linked to North Korea 2024-01-05 at 15:45 By Ionut Arghire SpectralBlur is a new macOS backdoor that shows similarities with North Korean hacking group’s KandyKorn malware. The post New ‘SpectralBlur’ macOS Backdoor Linked to North Korea appeared first on SecurityWeek. This article is an excerpt from SecurityWeek RSS Feed View Original

New ‘SpectralBlur’ macOS Backdoor Linked to North Korea Read More »

Several Infostealers Using Persistent Cookies to Hijack Google Accounts

Several Infostealers Using Persistent Cookies to Hijack Google Accounts 2024-01-03 at 17:46 By Ionut Arghire A vulnerability in Google’s authentication process allows malware to restore cookies and hijack user sessions. The post Several Infostealers Using Persistent Cookies to Hijack Google Accounts appeared first on SecurityWeek. This article is an excerpt from SecurityWeek RSS Feed View

Several Infostealers Using Persistent Cookies to Hijack Google Accounts Read More »

In Other News: Ubisoft Hack, NASA Security Guidance, TikTok Requests iPhone Passcode

In Other News: Ubisoft Hack, NASA Security Guidance, TikTok Requests iPhone Passcode 2023-12-29 at 16:01 By SecurityWeek News Noteworthy stories that might have slipped under the radar: Ubisoft investigating alleged hack, NASA releases security guidance, TikTok scares iPhone users.  The post In Other News: Ubisoft Hack, NASA Security Guidance, TikTok Requests iPhone Passcode appeared first

In Other News: Ubisoft Hack, NASA Security Guidance, TikTok Requests iPhone Passcode Read More »

Barracuda Zero-Day Used to Target Government, Tech Organizations in US, APJ

Barracuda Zero-Day Used to Target Government, Tech Organizations in US, APJ 2023-12-28 at 13:01 By Eduard Kovacs The new Barracuda ESG zero-day CVE-2023-7102 has been used by Chinese hackers to target organizations in the US and APJ region. The post Barracuda Zero-Day Used to Target Government, Tech Organizations in US, APJ appeared first on SecurityWeek.

Barracuda Zero-Day Used to Target Government, Tech Organizations in US, APJ Read More »

Chinese Hackers Deliver Malware to Barracuda Email Security Appliances via New Zero-Day

Chinese Hackers Deliver Malware to Barracuda Email Security Appliances via New Zero-Day 2023-12-27 at 13:16 By Eduard Kovacs Chinese hackers exploited a zero-day tracked as CVE-2023-7102 to deliver malware to Barracuda Email Security Gateway (ESG) appliances. The post Chinese Hackers Deliver Malware to Barracuda Email Security Appliances via New Zero-Day appeared first on SecurityWeek. This

Chinese Hackers Deliver Malware to Barracuda Email Security Appliances via New Zero-Day Read More »

Chameleon Android Malware Can Bypass Biometric Security

Chameleon Android Malware Can Bypass Biometric Security 2023-12-22 at 20:02 By Ionut Arghire A variant of the Chameleon Android banking trojan features new bypass capabilities and has expanded its targeting area. The post Chameleon Android Malware Can Bypass Biometric Security appeared first on SecurityWeek. This article is an excerpt from SecurityWeek RSS Feed View Original

Chameleon Android Malware Can Bypass Biometric Security Read More »

CISA Warns of FXC Router, QNAP NVR Vulnerabilities Exploited in the Wild

CISA Warns of FXC Router, QNAP NVR Vulnerabilities Exploited in the Wild 22/12/2023 at 14:46 By Eduard Kovacs CISA released ICS advisories for FXC router and QNAP NRV flaws and added them to its known exploited vulnerabilities catalog.  The post CISA Warns of FXC Router, QNAP NVR Vulnerabilities Exploited in the Wild appeared first on

CISA Warns of FXC Router, QNAP NVR Vulnerabilities Exploited in the Wild Read More »

NSA Blocked 10 Billion Connections to Malicious and Suspicious Domains

NSA Blocked 10 Billion Connections to Malicious and Suspicious Domains 20/12/2023 at 18:32 By Ionut Arghire The National Security Agency has published a new yearly report detailing its cybersecurity efforts throughout 2023. The post NSA Blocked 10 Billion Connections to Malicious and Suspicious Domains appeared first on SecurityWeek. This article is an excerpt from SecurityWeek

NSA Blocked 10 Billion Connections to Malicious and Suspicious Domains Read More »

Outlook Plays Attacker Tunes: Vulnerability Chain Leading to Zero-Click RCE

Outlook Plays Attacker Tunes: Vulnerability Chain Leading to Zero-Click RCE 19/12/2023 at 23:55 By Ionut Arghire Akamai researchers document more vulnerabilities and patch bypasses leading to zero-click remote code execution in Microsoft Outlook. The post Outlook Plays Attacker Tunes: Vulnerability Chain Leading to Zero-Click RCE appeared first on SecurityWeek. This article is an excerpt from

Outlook Plays Attacker Tunes: Vulnerability Chain Leading to Zero-Click RCE Read More »

Russian Cyberspies Exploiting TeamCity Vulnerability at Scale: Government Agencies

Russian Cyberspies Exploiting TeamCity Vulnerability at Scale: Government Agencies 14/12/2023 at 14:35 By Ionut Arghire US, UK, and Poland warn of Russia-linked cyberespionage group’s broad exploitation of recent TeamCity vulnerability. The post Russian Cyberspies Exploiting TeamCity Vulnerability at Scale: Government Agencies appeared first on SecurityWeek. This article is an excerpt from SecurityWeek RSS Feed View

Russian Cyberspies Exploiting TeamCity Vulnerability at Scale: Government Agencies Read More »

Adobe Patches 207 Security Bugs in Mega Patch Tuesday Bundle

Adobe Patches 207 Security Bugs in Mega Patch Tuesday Bundle 12/12/2023 at 23:47 By Ryan Naraine Adobe warned users on both Windows and macOS systems about exposure to code execution, memory leaks and denial-of-service security issues. The post Adobe Patches 207 Security Bugs in Mega Patch Tuesday Bundle appeared first on SecurityWeek. This article is

Adobe Patches 207 Security Bugs in Mega Patch Tuesday Bundle Read More »

North Korean Hackers Developing Malware in Dlang Programming Language

North Korean Hackers Developing Malware in Dlang Programming Language 11/12/2023 at 18:16 By Ionut Arghire North Korean hackers have used Dlang-based malware in attacks against manufacturing, agriculture, and physical security organizations. The post North Korean Hackers Developing Malware in Dlang Programming Language appeared first on SecurityWeek. This article is an excerpt from SecurityWeek RSS Feed

North Korean Hackers Developing Malware in Dlang Programming Language Read More »

Trail of Bits Spinout iVerify Tackles Mercenary Spyware Threat

Trail of Bits Spinout iVerify Tackles Mercenary Spyware Threat 06/12/2023 at 19:03 By Ryan Naraine iVerify, a seed-stage startup spun out of Trail of Bits, ships a mobile threat hunting platform to neutralize iOS and Android zero-days. The post Trail of Bits Spinout iVerify Tackles Mercenary Spyware Threat appeared first on SecurityWeek. This article is

Trail of Bits Spinout iVerify Tackles Mercenary Spyware Threat Read More »

5 Critical Steps to Prepare for AI-Powered Malware in Your Connected Asset Ecosystem

5 Critical Steps to Prepare for AI-Powered Malware in Your Connected Asset Ecosystem 06/12/2023 at 14:17 By Rik Ferguson AI-powered attacks will become progressively more common, and a well-rounded security approach involves more than simply managing incidents effectively. The post 5 Critical Steps to Prepare for AI-Powered Malware in Your Connected Asset Ecosystem appeared first

5 Critical Steps to Prepare for AI-Powered Malware in Your Connected Asset Ecosystem Read More »

Russian Pleads Guilty to Role in Developing TrickBot Malware

Russian Pleads Guilty to Role in Developing TrickBot Malware 04/12/2023 at 18:16 By Ionut Arghire Russian national Vladimir Dunaev pleaded guilty to involvement in the development and use of the TrickBot malware that caused tens of millions of dollars in losses. The post Russian Pleads Guilty to Role in Developing TrickBot Malware appeared first on

Russian Pleads Guilty to Role in Developing TrickBot Malware Read More »

New ‘Turtle’ macOS Ransomware Analyzed

New ‘Turtle’ macOS Ransomware Analyzed 01/12/2023 at 15:01 By Eduard Kovacs New Turtle macOS ransomware is not sophisticated but shows that cybercriminals continue to target Apple devices. The post New ‘Turtle’ macOS Ransomware Analyzed appeared first on SecurityWeek. This article is an excerpt from SecurityWeek RSS Feed View Original Source

New ‘Turtle’ macOS Ransomware Analyzed Read More »

Apple Patches WebKit Flaws Exploited on Older iPhones

Apple Patches WebKit Flaws Exploited on Older iPhones 30/11/2023 at 23:02 By Ryan Naraine Apple’s security response team warns that flaws CVE-2023-42916 and CVE-2023-42917 were already exploited against versions of iOS before iOS 16.7.1. The post Apple Patches WebKit Flaws Exploited on Older iPhones appeared first on SecurityWeek. This article is an excerpt from SecurityWeek

Apple Patches WebKit Flaws Exploited on Older iPhones Read More »

Scroll to Top