Top

Category: Threats & Malware

Threats and Malware


Threats & Malware, Vulnerabilities

T-Mobile US exposes some customer data – but don’t call it a breach

September 25, 2023

Via: The Register

T-Mobile US has had another bad week on the infosec front – this time stemming from a system glitch that exposed customer account data, followed by allegations of another breach the carrier denied. According to customers who complained of the […]


Threats & Malware, Vulnerabilities

Apple squashes security bugs after iPhone flaws exploited by Predator spyware

September 22, 2023

Via: The Register

Apple emitted patches this week to close security holes that have been exploited in the wild by commercial spyware. The updates, which were issued yesterday and should be installed as soon as possible if not already, address as many as […]


Data loss, Threats & Malware

Data breach reveals distressing info: People who order pineapple on pizza

September 21, 2023

Via: The Register

Pizza Hut’s Australian outpost has suffered a data breach. The baked goods purveyor has delivered bitter news to around 190,000 customers: that their name, delivery address, email address, and phone numbers have been accessed by unautorised entities. Even more seriously, […]


Threats & Malware, Virus & Malware

India’s biggest tech centers named as cyber crime hotspots

September 21, 2023

Via: The Register

India is grappling with a three-and-a-half year surge in cyber crime, with analysis suggesting cities like Bengaluru and Gurugram – centers of India’s tech development – are hubs of this activity. The report – A Deep Dive into Cybercrime Trends […]


Data loss, Threats & Malware

Pot calls the kettle hack as China claims Uncle Sam did digital sneak peek first

September 20, 2023

Via: The Register

The ongoing face-off between Washington and Beijing over technology and security issues has taken a new twist, with China accusing the US of hacking into the servers of Huawei in 2009 and conducting other cyber-attacks to steal critical data. China’s […]


Data loss, Threats & Malware

Robocall scammers sentenced in US after netting $1.2M via India-based call centers

September 20, 2023

Via: The Register

Two Indian nationals each received 41-month prison sentences for their involvement in $1.2 million worth of robocall scams targeting the elderly, according to the district of New Jersey’s attorney’s office on Tuesday. Plantiffs Arushobike Mitra and Garbita Mitra (no relation, […]


Data loss, Threats & Malware

The Clorox Company admits cyberattack causing ‘widescale disruption’

September 19, 2023

Via: The Register

The Clorox Company, makers of bleach and other household cleaning products, doesn’t expect operations to return to normal until near month end as it combs over “widescale disruption to operations” caused by cyber baddies. The $2 billion turnover biz, whose […]


Threats & Malware, Virus & Malware

New cryptojacking attacks target uncommon AWS instances

September 19, 2023

Via: TechRadar

Cybersecurity researchers from Sysdig recently uncovered a new cryptojacking campaign that targeted uncommon Amazon Web Services (AWS) services. Cryptojacking is a type of cyberattack in which the threat actor secretly installs a cryptocurrency miner on a target endpoint. While not […]


Threats & Malware, Vulnerabilities

12,000 Juniper SRX firewalls and EX switches vulnerable to CVE-2023-36845

September 19, 2023

Via: Security Affairs

VulnCheck researchers discovered approximately 12,000 internet-exposed Juniper SRX firewalls and EX switches that are vulnerable to the recently disclosed remote code execution flaw CVE-2023-36845. In mid-August, Juniper addressed four medium-severity (CVSS 5.3) vulnerabilities (CVE-2023-36844, CVE-2023-36845, CVE-2023-36846, CVE-2023-36847) impacting EX switches […]


Threats & Malware, Virus & Malware

Cryptojackers spread their nets to capture more than just EC2

September 18, 2023

Via: The Register

As cloud native computing continues to gain popularity, so does the risk posed by criminals seeking to exploit the unwary. One newly spotted method targets services on the AWS platform, but not necessarily the ones you might think. Researchers from […]


Data loss, Threats & Malware

GAO Report Reveals IRS’s Limited Control Over Taxpayer Data Handling

September 18, 2023

Via: SecureWorld

The U.S. Internal Revenue Service (IRS) is entrusted with the vital responsibility of safeguarding sensitive taxpayer information. Recent incidents of potential unauthorized access to or disclosure of this data have raised concerns and prompted a thorough review by the Government […]


Threats & Malware, Vulnerabilities

CISA Warning: Nation-State Hackers Exploit Fortinet and Zoho Vulnerabilities

September 8, 2023

Via: The Hacker News

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Thursday warned that multiple nation-state actors are exploiting security flaws in Fortinet FortiOS SSL-VPN and Zoho ManageEngine ServiceDesk Plus to gain unauthorized access and establish persistence on compromised systems. “Nation-state advanced […]


Threats & Malware, Virus & Malware

Mac Users Beware: Malvertising Campaign Spreads Atomic Stealer macOS Malware

September 8, 2023

Via: The Hacker News

A new malvertising campaign has been observed distributing an updated version of a macOS stealer malware called Atomic Stealer (or AMOS), indicating that it’s being actively maintained by its author. An off-the-shelf Golang malware available for $1,000 per month, Atomic […]


Data loss, Threats & Malware

Outlook Hack: Microsoft Reveals How a Crash Dump Led to a Major Security Breach

September 7, 2023

Via: The Hacker News

Microsoft on Wednesday revealed that a China-based threat actor known as Storm-0558 acquired the inactive consumer signing key to forge tokens and access Outlook by compromising an engineer’s corporate account. This enabled the adversary to access a debugging environment that […]


Threats & Malware, Vulnerabilities

Alert: Apache SuperSet Vulnerabilities Expose Servers to Remote Code Execution Attacks

September 7, 2023

Via: The Hacker News

Patches have been released to address two new security vulnerabilities in Apache Superset that could be exploited by an attacker to gain remote code execution on affected systems. The update (version 2.1.1) plugs CVE-2023-39265 and CVE-2023-37941, which make it possible […]


Threats & Malware, Vulnerabilities

Coding Tips to Sidestep JavaScript Vulnerabilities

September 7, 2023

Via: Dark Reading

The Internet was all about gray backgrounds and dull text boxes in the ’90s. But JavaScript changed that, allowing us to enjoy dynamic text, interactive websites, and clickable elements without sacrificing performance. JavaScript is one of the most commonly used […]


Threats & Malware, Vulnerabilities

9 Alarming Vulnerabilities Uncovered in SEL’s Power Management Products

September 6, 2023

Via: The Hacker News

Nine security flaws have been disclosed in electric power management products made by Schweitzer Engineering Laboratories (SEL). “The most severe of those nine vulnerabilities would allow a threat actor to facilitate remote code execution (RCE) on an engineering workstation,” Nozomi […]


Threats & Malware, Virus & Malware

Researchers Warn of Cyber Weapons Used by Lazarus Group’s Andariel Cluster

September 5, 2023

Via: The Hacker News

The North Korean threat actor known as Andariel has been observed employing an arsenal of malicious tools in its cyber assaults against corporations and organizations in the southern counterpart. “One characteristic of the attacks identified in 2023 is that there […]


Threats & Malware, Virus & Malware

New Python Variant of Chaes Malware Targets Banking and Logistics Industries

September 5, 2023

Via: The Hacker News

Banking and logistics industries are under the onslaught of a reworked variant of a malware called Chaes. “It has undergone major overhauls: from being rewritten entirely in Python, which resulted in lower detection rates by traditional defense systems, to a […]


Hacker, Threats & Malware

Cybercriminals use research contests to create new attack methods

September 1, 2023

Via: Help Net Security

Adversary-sponsored research contests on cybercriminal forums focus on new methods of attack and evasion, according to Sophos. The contests mirror legitimate security conference ‘Call For Papers’ and provide the winners considerable financial rewards and recognition from peers and also potential […]