Cyber

Commercial spyware vendor exploits used by Kremlin-backed hackers, Google says

Findings undercut pledges of NSO Group and Intellexa their wares won't be abused. Critics of spyware and exploit sellers have long warned that the advanced hacking sold by commercial surveillance...

Unpatchable 0-day in surveillance cam is being exploited to install Mirai

Vulnerability is easy to exploit and allows attackers to remotely execute commands. Malicious hackers are...

Microsoft to host security summit after CrowdStrike disaster

Redmond wants to improve the resilience of Windows to buggy software. Microsoft is stepping up...

Android malware steals payment card data using previously unseen technique

Attacker then emulates the card and makes withdrawals or payments from victim's account. Newly discovered...

Hackers exploit VMware vulnerability that gives them hypervisor admin

Create new group called "ESX Admins" and ESXi automatically gives it admin rights. Microsoft is...

China state hackers infected 20,000 Fortinet VPNs, Dutch spy service says

Critical code-execution flaw was under exploitation 2 months before company disclosed it. Hackers working for the Chinese government gained access to more than 20,000 VPN...

Ransomware gangs are adopting “more brutal” tactics amid crackdowns

Researchers fear real-world violence as law enforcement plays Whac-A-Mole with gangs. Today, people around the world will head to school, doctor’s appointments, and pharmacies, only...

Nasty bug with very simple exploit hits PHP just in time for the weekend

With PoC code available and active Internet scans, speed is of the essence. A critical vulnerability in the PHP programming language can be trivially exploited...

FCC pushes ISPs to fix security flaws in Internet routing

Chair: Addressing BGP flaws will "help make our Internet routing more secure." The Federal Communications Commission wants to verify that Internet service providers are strengthening...

What kind of bug would make machine learning suddenly 40% worse at NetHack?

One day, a roguelike-playing system just kept biffing it, for celestial reasons. Members of the Legendary Computer Bugs Tribunal, honored guests, if I may have...

Ticketmaster hacked in what’s believed to be a spree hitting Snowflake customers

Researcher says Snowflake customers hit by mass scraping ... "but nobody noticed." Cloud storage provider Snowflake said that accounts belonging to multiple customers have been...

Federal agency warns critical Linux vulnerability being actively exploited

Cybersecurity and Infrastructure Security Agency urges affected users to update ASAP. The US Cybersecurity and Infrastructure Security Agency has added a critical security bug in...

Law enforcement operation takes aim at an often-overlooked cybercrime linchpin

Officials hope to sever a component crucial to the larger malware landscape. An international cast of law enforcement agencies has struck a blow at a...

Municipal broadband advocates fight off attacks from “dark money” groups

"Social welfare" groups spread industry talking points against public broadband. Cities and towns that build their own broadband networks often say they only considered the...

Researchers spot cryptojacking attack that disables endpoint protections

A key component: Installing known vulnerable drivers from Avast and IOBit. Malware recently spotted in the wild uses sophisticated measures to disable antivirus protections, destroy...

Black Basta ransomware group is imperiling critical infrastructure, groups warn

Threat group has targeted 500 organizations. One is currently struggling to cope. Federal agencies, health care associations, and security researchers are warning that a ransomware...

Claimed by hackers, Zscaler says there’s no impact or compromise

Cloud security company Zscaler is continuing an investigation into an alleged breach after a threat actor started selling “access to one of the largest...

Apple iOS app causes injury to over 200 people

An iOS app designed to help manage diabetes has caused harm to over 220 people due to a defect in the application. Tandem Diabetes Care,...

Google patches its fifth zero-day vulnerability of the year in Chrome

Exploit code for critical "use-after-free" bug is circulating in the wild. Google has updated its Chrome browser to patch a high-severity zero-day vulnerability that allows...
HomeCyber