Cyber News - Page 27

Home > Cyber News

This category contains informative articles and news.
Cyber News about data breaches, online privacy and security, computer security threats, cybersecurity reports, vulnerability reports. News about the latest malware attacks.
Hot news about the security of Microsoft (Patch Tuesdays), Google, Android, Apple, Linux, and other big companies and software vendors.

CYBER NEWS
CVE-2021-1675-sensorstechforum

CVE-2021-1675: Critical Windows Print Spooler Vulnerability

CVE-2021-1675 is a critical Windows vulnerability with an available proof-of-concept that could enable remote attackers execute code. The PoC code was shared on GitHub earlier this week, and taken down within a few hours. However, these few hours were enough…

CYBER NEWS
An Unpatched Vulnerability in Google Compute Engine-sensorstechforum

There’s an Unpatched Vulnerability in Google Compute Engine

There’s a vulnerability in Google’s Compute engine platform that attackers could exploit to obtain control of virtual machines over the network. The discovery comes from security researcher Imre Rad who published an analysis on GitHub. He reported about “an unpatched…

CYBER NEWS
700 Million LinkedIn Records Up for Sale on a Hacker Forum-sensorstechforum

Not Again: 700 Million LinkedIn Records Up for Sale on a Hacker Forum

The data of 700 million LinkedIn users has been compromised, according to a new report by Privacy Sharks. The researchers came across the data records on a popular underground forum where it was offered for sale. 700 Million LinkedIn Records…

CYBER NEWS
netfilter-rootkit-sensorstechforum

The Netfilter Rootkit: How Microsoft Signed a Malicious Driver

Microsoft recently document an intriguing cybersecurity accident involving a threat actor that distributed malicious drivers across gaming environments. The Netfilter Driver: a Threat to the Gaming Community Evidently, the threat actor submitted a specific driver called Netfilter, built by a…

CYBER NEWS
crackonosh-malware-sensorstechforum

Crackonosh Malware Uses Cracked Software and Disables System Defenses

Security researchers just reported the discovery of a new malware they called Crackonosh. The malware was uncovered by Avast researchers after they received reports from reddit users saying that their AV programs were missing from their systems. Crackonosh Malware in…

CYBER NEWS
CVE-2021-21998

CVE-2021-21998: Critical Bug in VMware’s Carbon Black App Control

Critical Vulnerability in VMware’s Carbon Black App Control There’s a vulnerability in VMware’s Carbon Black App Control management server. Rated 9.4 according to the CVSS scale, the severe flaw could grant threat actors with admin rights without any authentication. This…

CYBER NEWS
french connection ransomware attack-sensorstechforum

Fashion Brand French Connection (FCUK) Hit by Ransomware

French Connection (FCUK), a clothing company, is the latest victim of a ransomware attack linked to the REvil gang. The attackers seem to have found a vulnerability in the company’s back-end systems, which allowed them to grab internal data. Breached…

CYBER NEWS
Dell BIOSConnect Feature Vulnerable to RCE Attacks CVE-2021-21573-sensorstechforum

Dell BIOSConnect Feature Vulnerable to RCE Attacks (CVE-2021-21573)

Dell devices contain four high-severity security flaws that could allow remote attackers to carry out arbitrary code execution in the pre-boot environment of the devices. The vulnerabilities affect 30 million individual Dell endpoints, Eclypsium researchers discovered. The said vulnerabilities are…

CYBER NEWS
Unpatched RCE Bug Affects PlingStore, Linux Marketplaces-sensorstechforum

Unpatched RCE Bug Affects PlingStore, Linux Marketplaces

Researchers from Positive Security discovered an unpatched stored cross-site-scripting (XSS) flaw impacting Linux marketplaces. The vulnerability creates the possibility of unchecked, wormable supply-chain attacks. Affected are Pling-based marketplaces, such as AppImage Hub, Gnome-Look, KDE Discover App Store, Pling.com, and XFCE-Look.…

CYBER NEWS
CVE-2021-33515  dovecot vulnerability

CVE-2021-33515 Dovecot Vulnerability Could Allow Email Snooping

Security researchers discovered a vulnerability, CVE-2021-33515, in the underlying technology deployed by most email servers running the IMAP protocol (Internet Message Access Protocol). The vulnerability has been around for at least a year, allowing attackers to bypass TLS email protections…

CYBER NEWS
Tor Browser Version 10.0.18 Fixes User Tracking Vulnerability-sensorstechforum

Tor Browser Version 10.0.18 Fixes User Tracking Vulnerability

If you are using the Tor Browser, you should get the latest update immediately. Tor Browser 10.0.18 fixes a series of issues, one of which is a vulnerability that could allow sites to track users by fingerprinting their installed apps.…

CYBER NEWS
darkradiation-ransomware-linux-sensorstechforum

DarkRadiation Ransomware Targets Linux and Docker Containers

DarkRadiation is a new ransomware that targets Linux and Docker cloud containers. Coded in Bash, the ransomware targets specifically Red Hat/CentOS and Debian Linux distributions, according to Trend Micro’s research. Related: Previously Undetected RotaJakiro Malware Targets Linux X64 Systems For…

CYBER NEWS
android-droidmorph-sensorstechforum

DroidMorph Tool Shows How Popular Android AV Programs Fail at Protecting Users

How effective are Android anti-virus applications? A new research sheds light on how popular AV programs for Android fail to secure devices against various malware permutations. “The number of Android malware variants (clones) are on the rise and, to stop…

CYBER NEWS
iPhone Wi-Fi Bug Can Disable Its Ability to Connect to Wireless Networks-sensorstechforum-com

iPhone Wi-Fi Bug Can Disable Its Ability to Connect to Wireless Networks

Apple’s iOS is prone to a wireless networking naming issue that can disable an iPhone’s ability to connect to a Wi-Fi network. Discovered by senior security engineer at Ant Financial Light-Year Security Labs Carl Schou, the bug can permanently disable…

CYBER NEWS
Google SLSA Framework to Protect against Software Supply Chain Attacks-sensorstechforum

Google’s SLSA Framework to Protect against Software Supply Chain Attacks

Google is working on a solution to help mitigate the increasing number of software supply chain attacks. What Is Supply Chain Levels for Software Artifacts (SLSA)? Called Supply Chain Levels for Software Artifacts, or SLSA for short, the solution is…

CYBER NEWS
process-ghosting-malware-evasion-sensorstechforum

Process Ghosting: The Latest Malware Evasion Technique

Security researchers discovered a new malicious technique that helps malware achieve evasion on an infected system. Called Process Ghosting, the technique could be exploited by a threat actor to bypass security protections and run malicious code on a Windows system.…

CYBER NEWS
CVE-2021-3560 polkit vulnerability-sensorstechforum

CVE-2021-3560: 7-Year-Old polkit Bug Affects Some Linux Distros

Security researchers recently discovered a vulnerability in Linux systemd’s polkit. Identified as CVE-2021-3560, the flaw appears to have been around for at least seven years. Since polkit is used in many Linux distributions, the impact of the vulnerability should not…

CYBER NEWS
CVE-2021-32934-Critical ThroughTek Bug Could Allow Access to Access to Connected Cameras-sensorstechforum

CVE-2021-32934: Critical ThroughTek Bug Could Allow Access to Connected Cameras

A new CISA advisory warns about a critical software supply-chain vulnerability affecting ThroughTek’s SDK (software development kit). The flaw, identified as CVE-2021-32934 could be abused to gain improper access to audio and video streams. Other compromise scenarios include spoofing vulnerable…

CYBER NEWS
CVE-2021-30761-sensorstechforum

Patch Your iOS Device against CVE-2021-30761, CVE-2021-30762

To the attention of Apple users – the company recently released out-of-band-security patches addressing two-zero days in iOS 12.5.3. The vulnerabilities may have been exploited in the wild, so patch your devices immediately. iOS 12.5.4 Fixes Three Bugs: CVE-2021-30737, CVE-2021-30761,…

CYBER NEWS
Volkswagen Vendor Data Breach Exposed Details of 3.3 Million Customers-sensorstechforum

Volkswagen Vendor Data Breach Exposed Details of 3.3 Million Customers

A large-scale data breach has affected one of Volkswagen’s vendors, exposing personal details of 3.3 million customers. The vendor left one of its systems open for two years, between August 2019 and May 2021. Volkswagen Data Breach: What Happened? “On…

This website uses cookies to improve user experience. By using our website you consent to all cookies in accordance with our Privacy Policy.
I Agree