Security

Critical Windows vulnerabilities exploited: CISA urges users to update

Microsoft's September 2024 Patch fixes 79 flaws, with at least four exploited in the wild. One remote code execution vulnerability, with a severity score of 9.8 out of 10, enables a “total loss of confidentiality,” divulging resources to the attacker.
Read more about Critical Windows vulnerabilities exploited: CISA urges users to update

Cybernews Business Digital Index reveals major shortcomings in corporate customer data security

Despite the growing threat of cyberattacks, many companies continue to fall short in strengthening their security measures.
Read more about Cybernews Business Digital Index reveals major shortcomings in corporate customer data security

How many dangerous permissions are too many? Popular apps see no limits

Do you have a photo of your ID on your phone? If so, do you know who else can access it? A single overly broad permission can lead to data exposure, yet most apps don’t stop at just a few dangerous permissions. Here’s what we found about 50 popular Android apps.
Read more about How many dangerous permissions are too many? Popular apps see no limits

Data leak exposes 14,000 US medical professionals: what we know so far

A massive data leak at a Florida-based recruitment company has affected more than ten thousand hospitals and medical workers.
Read more about Data leak exposes 14,000 US medical professionals: what we know so far

Researchers turn RAM into radio antenna, beaming secrets from air-gapped system

Even an isolated computer in a sealed room can be accessed by an outsider with a cheap antenna, exploiting a new RAMBO attack.
Read more about Researchers turn RAM into radio antenna, beaming secrets from air-gapped system

Wifi routers and VPN appliances targeted by notorious botnet Quad7

The mysterious Quad7 botnet has evolved its tactics to compromise several brands of Wi-Fi routers and VPN appliances. It’s armed with new backdoors, multiple vulnerabilities, some of which were previously unknown, and new staging servers and clusters, according to a report by Sekoia, a cybersecurity firm.
Read more about Wifi routers and VPN appliances targeted by notorious botnet Quad7

New malware shakes macOS security paradigm – hackers eying iPhones next

If you press a malicious link on a Mac, it will most likely lead to the Atomic MacOS Stealer (AMOS). Since its emergence in April last year, this malware has become a go-to choice for hackers stealing crypto, passwords, and session tokens. Due to high demand, its cost has tripled.
Read more about New malware shakes macOS security paradigm – hackers eying iPhones next

UK staffing agency exposes gig workers: passports, visas, and more made public

A UK staffing agency has leaked the passports of tens of thousands of gig workers, exposing them to identity theft and various other frauds.
Read more about UK staffing agency exposes gig workers: passports, visas, and more made public

Russian cyber militants responsible for damage to critical assets: US offers $10 million bounty

A lesser-known cyber actor associated with the Russian military intelligence (GRU) is responsible for attempted coups, sabotage, influence operations, and even assassination attempts in Europe, the FBI warns.
Read more about Russian cyber militants responsible for damage to critical assets: US offers $10 million bounty

Hacker slip-up? 762,000 car owners have vehicles, home addresses exposed online

When legitimate personal data leaks from a completely unknown source, the issue is much more distressing.
Read more about Hacker slip-up? 762,000 car owners have vehicles, home addresses exposed online

VMware on macOS affected by high-severity flaw: attackers can run arbitrary code

VMware Fusion, a macOS hypervisor used for running virtual machines, contains a high-severity code execution vulnerability, as disclosed by Broadcom. The only mitigation currently available is to update the software to the latest version.
Read more about VMware on macOS affected by high-severity flaw: attackers can run arbitrary code

Zyxel routers, access points, firewalls in danger: users urged to patch

Zyxel, a networking solutions provider, has released patches to dozens of its products, including business routers, firewalls, access points, 5G, DSL/Ethernet equipment, and other devices. Some of the nine disclosed vulnerabilities allow potential attackers to execute OS commands without any authorization.
Read more about Zyxel routers, access points, firewalls in danger: users urged to patch

Researchers clone YubiKeys, many security microchips may be flawed

Security chips produced by Infineon Technologies, a major secure element manufacturer spanning multiple product lines, have been found vulnerable to side-channel attacks. Researchers disclosed that YubiKey, a hardware authentication device popular among crypto enthusiasts, can be cloned.
Read more about Researchers clone YubiKeys, many security microchips may be flawed

North Korean hackers exploit Chrome zero-day to target crypto users

North Korean hackers are at it again. This time, they’re deploying a dangerous rootkit and running remote code by chaining Chromium and Windows kernel vulnerabilities to escape the browser’s security sandbox. According to Microsoft research, all they need is for the victim to visit the website.
Read more about North Korean hackers exploit Chrome zero-day to target crypto users

Security camera company Verkada agrees to pay FTC almost $3M

The Federal Trade Commission (FTC) is set to fine the security camera company Verkada $2.95 million for various violations, including its inability to implement proper security measures – one of which allowed hackers to watch customers.
Read more about Security camera company Verkada agrees to pay FTC almost $3M

Ransomware newcomer RansomHub claiming one victim per day

Ransomware ecosystem newcomer RansomHub already has at least 210 scalps under its belt. The victims include various organizations from critical infrastructure sectors in the US.
Read more about Ransomware newcomer RansomHub claiming one victim per day

Russian state hackers using cyberweapons developed by Western spyware firms

The Russian government-backed threat actor Cozy Bear is attacking governments using the same exploits and code used by commercial cyber surveillance companies Intelexa or NSO Group, infamous for the Pegasus spyware.
Read more about Russian state hackers using cyberweapons developed by Western spyware firms

BlackByte ransomware still capitalizing on known VMware ESXi flaw

Despite multiple warnings and orders for US federal agencies to patch a vulnerability in VMware ESXi, an enterprise-class software for hosting virtual machines, ransomware operators are still taking advantage of it.
Read more about BlackByte ransomware still capitalizing on known VMware ESXi flaw

Researchers trace massive data leak to US data broker: why should you care

Sensitive data exposing a staggering amount of individuals continues to leak online, most likely originating from datasets belonging to People Data Labs.
Read more about Researchers trace massive data leak to US data broker: why should you care

The unmasking of threat actor USDoD

Less than a month after my interview with the infamous hacker USDoD, he was unceremoniously de-anonymized as Luan Goncalves, a 33-year-old man from Minas Gerais, Brazil. His OPSEC was laid bare for the world to see when Baptiste Robert, CEO and founder of Predicta Lab, used his company’s OSINT tools to break down the walls of his anonymity and expose his true identity.
Read more about The unmasking of threat actor USDoD