Cyber News - Page 24

Home > Cyber News

This category contains informative articles and news.
Cyber News about data breaches, online privacy and security, computer security threats, cybersecurity reports, vulnerability reports. News about the latest malware attacks.
Hot news about the security of Microsoft (Patch Tuesdays), Google, Android, Apple, Linux, and other big companies and software vendors.

CYBER NEWS
CVE-2021-30860  FORCEDENTRY zero-day in Apple devices

CVE-2021-30860: Fix Your Apple Device against the FORCEDENTRY Zero-Day

There’s a new zero-day, zero-click vulnerability in all types of Apple devices, including Macs, iPhones, iPads, and WatchOS. The flaw has been called FORCEDENTRY. Related: The State of Apple’s Privacy So Far in 2021 How was the Apple FORCEDENTRY (CVE-2021-30860)…

CYBER NEWS
puma data leak

Puma Source Code Stolen by Hackers in an Attempt to Extort the Company

Puma, the sportswear manufacturer, has been compromised in a cyberattack. Reports by The Record (by Recorded Future) reveal that some of Puma’s source code has been stolen by hackers, in an attempt to try and extort the company into paying…

CYBER NEWS
meris-botnet-ddos-sensorstechforum

Meris Botnet: A DDoS Plague of a New Kind

At the end of June, 2021, security researchers from Russian firm Qrator started observing “a botnet of a new kind.” A joint research with Yandex followed to discover more about this new DDoS threat “emerging in almost real-time”. Related: New…

CYBER NEWS
CVE-2018-13379: Access Information to 87,000 FortiGate SSL-VPN Devices Leaked

CVE-2018-13379: Access Information to 87,000 FortiGate SSL-VPN Devices Leaked

A threat actor has recently disclosed SSL-VPN access information to 87,000 FortiGate SSL-VPN devices, Fortinet has confirmed. Unpatched CVE-2018-13379 in FortiGate SSL-VPN Devices Caused the Leak According to the statement, the said credentials were taken from systems that remained unpatched…

CYBER NEWS
CVE-2021-40539- Critical Zero-Day in Zoho ManageEngine ADSelfService Plus-sensorstechforum

CVE-2021-40539: Critical Zero-Day in Zoho ManageEngine ADSelfService Plus

CISA has released an alert regarding a new, critical zero-day vulnerability affecting Zoho ManageEngine servers. Related: Three New Zero-Days Disclosed in Kaseya Unitrends More specifically, an authentication bypass flaw affects the REST API URLs in ADSelfService Plus, which could lead…

CYBER NEWS
Spook.js-New Spectre-Like Attack Endangers the Chrome Browser-sensorstechforum

Spook.js: New Spectre-Like Attack Endangers Chrome, Chromium-Based Browsers

A team of scholars from universities in Australia, Israel, and the United States has created a new side-channel attack that targets Google Chrome’s Site Isolation feature. The attack, called Spook.js, is a new transient execution side channel exploit targeting Chrome…

CYBER NEWS
CVE-2021-40444 zero-day

CVE-2021-40444 Zero-Day Used in Attacks against Windows Users

A new zero-day vulnerability, CVE-2021-40444, was found lurking in Internet Explorer, making it possible for hackers to exploit exposed Windows systems via malicious Office documents. Related: CVE-2021-36948 Zero-Day in Windows Update Medic Exploited in the Wild CVE-2021-40444 RCE Flaw Used…

CYBER NEWS
Latest Phishing Attacks Themed with Windows 11 -sensorstechforum

Beware: Latest Phishing Attacks Themed with Windows 11

Windows 11 is already making the headlines in terms of hackers’ exploitation. Apparently, FIN7, a well-known hacking group, has been using Windows 11 themes in an attempt to trick recipients in a recent phishing campaign targeting a PoS (point-of-sale) company.…

CYBER NEWS
Fake Cracked Software Delivers STOP Ransomware, Infostealers and Cryptominers-sensorstechforum

Fake Cracked Software Delivers STOP Ransomware, Infostealers and Cryptominers

To shed some light on the everlasting “bundled malware” threat, Sophos researchers recently performed a thorough investigation on a network of websites related to an ongoing Racoon infostealer campaign, acting as a “dropper as a service.” This network distributed a…

CYBER NEWS
CVE-2021-28139

BrakTooth Vulnerabilities Affect Billions of Devices (CVE-2021-28139)

A total of 16 vulnerabilities are plaguing the Bluetooth software stack of numerous SoC (system-on chip) chipsets. Called BrakTooth, the vulnerabilities affect 1,400 chipsets used in laptops, smartphones, IoT and industrial devices. If exploited, the flaws could crash and freeze…

CYBER NEWS
tp-link firmware vulnerabilities

Amazon Best-Selling TP-Link Router Shipped with Vulnerable Firmware

A number of security flaws in the default firmware and web interface app of a popular router were discovered by CyberNews researchers that could expose its owners at risk of man-in-the-middle and denial-of-service attacks. TP-Link AC1200 Archer C50 (v6) is…

CYBER NEWS
CVE-2021-38312 and CVE-2021-38314-sensorstechforum

Gutenberg Template Library WordPress Plugin Contains Two Flaws (CVE-2021-38312)

Two security vulnerabilities were discovered in the Gutenberg Template Library & Redux Framework plugin for WordPress, CVE-2021-38312 and CVE-2021-38314. Discovered by Defiant researchers, the vulnerabilities could impact more than a million WordPress websites running the plugin. Both flaws affect plugin…

CYBER NEWS
LockFile Ransomware Uses Unique Intermittent Encryption to Evade Detection-sensorstechforum

LockFile Ransomware Uses Unique Intermittent Encryption to Evade Detection

The LockFile ransomware emerged in July 2021. The ransomware has been exploiting the ProxyShell vulnerabilities in Microsoft Exchange servers in its attacks. The flaws are deployed “to breach targets with unpatched, on premises Microsoft Exchange servers, followed by a PetitPotam…

CYBER NEWS
proxytoken-exploit-sensorstechforum

ProxyToken (CVE-2021-33766) Exploit Allows Attackers to Read Your Mail

ProxyToken, or CVE-2021-33766 is a serious security vulnerability in Microsoft Exchange that could allow an unauthenticated threat actor to access and steal emails from the victim’s mailbox. The issue was reported to the Zero Day Initiative in March 2021 by…

CYBER NEWS

Hackers Use Open Redirect Links to Bypass Detection in Phishing Operation

Microsoft researchers detected a new phishing campaign leveraging open redirector links (open redirects) in emails in an attempt to bypass security software and trick users into visiting malicious pages. Related: Microsoft and Google’s Cloud Infrastructure Abused by Hackers in Phishing…

CYBER NEWS
kaseya unitrends mitigations

Kaseya Releases Patches and Mitigations Addresing the Unitrends Flaws

In July, Kaseya announced three new zero-day vulnerabilities impacting its Kaseya Unitrends service. The vulnerabilities were represented by an authenticated RCE flaw on the server, a privilege escalation flaw from read-only user to admin on the server, and an undisclosed…

CYBER NEWS
4 emerging ransomware-as-a-service groups

Threat Alert: 4 Emerging Ransomware-as-a-Service Groups

Palo Alto’s Unit 42 researchers shed light on four emerging ransomware groups making the headlines this year. The discovery comes after an extensive research and analysis of the underground including web leak sites and fresh onion sites. These ransomware-as-a-service operators…

CYBER NEWS
most prevalent malware and vulnerabilities in linux in 2021

Linux Threat Landscape 2021: Most Prevalent Malware and Vulnerabilities

What are the threats endangering Linux systems? Security researchers from Trend Micro just released a report focused on the “pressing security issues including malware and vulnerabilities that compromise Linux systems in the first half of 2021.” Related: The Facefish Operation:…

CYBER NEWS
Black Kingdom Hackers Try to Recruit Employees to Deploy Ransomware-sensorstechforum

Black Kingdom Hackers Try to Recruit Employees to Deploy Ransomware

Security researchers are reporting emails soliciting company insiders to install the Demon (Black Kingdom) ransomware on their organizations’ networks. Nigerian Threat Actor Behind the Campaign According to a report by Abnormal Security, a Nigerian threat actor is trying to recruit…

CYBER NEWS
Hackers Are Exploiting the ProxyShell Microsoft Exchange Flaws CVE-2021-34473

Hackers Are Exploiting the ProxyShell Microsoft Exchange Flaws (CVE-2021-34473)

According to an alert released by the U.S. Cybersecurity and Infrastructure Security Agency (CISA), cybercriminals are currently exploiting the so-called ProxyShell Microsoft Exchange vulnerabilities: CVE-2021-34473, CVE-2021-34523, and CVE-2021-31207. CISA Warns against ProxyShell Attacks The agency’s strong advice is for organizations…

This website uses cookies to improve user experience. By using our website you consent to all cookies in accordance with our Privacy Policy.
I Agree