Cyber

Commercial spyware vendor exploits used by Kremlin-backed hackers, Google says

Findings undercut pledges of NSO Group and Intellexa their wares won't be abused. Critics of spyware and exploit sellers have long warned that the advanced hacking sold by commercial surveillance...

Unpatchable 0-day in surveillance cam is being exploited to install Mirai

Vulnerability is easy to exploit and allows attackers to remotely execute commands. Malicious hackers are...

Microsoft to host security summit after CrowdStrike disaster

Redmond wants to improve the resilience of Windows to buggy software. Microsoft is stepping up...

Android malware steals payment card data using previously unseen technique

Attacker then emulates the card and makes withdrawals or payments from victim's account. Newly discovered...

Hackers exploit VMware vulnerability that gives them hypervisor admin

Create new group called "ESX Admins" and ESXi automatically gives it admin rights. Microsoft is...

CircleCI warns customers to rotate ‘any and all secrets’ after hack

Image Credits: Boris Zhitkov (opens in a new window)/ Getty Images CircleCI, a company whose development products are popular with software engineers, has urged users to rotate their...

Apple releases security updates for iOS, iPadOS and macOS, fixing two actively exploited zero-days

Apple has released security updates for iPhones, iPads and Macs to patch against two vulnerabilities, which the company says are being actively exploited to...

Security flaws in court record systems used in five US states exposed sensitive legal documents

The vulnerabilities allowed public access to restricted, sealed and confidential court filings using only a web browser Image Credits: Bryce Durbin / TechCrunch Witness lists and testimony, mental health evaluations,...

ownCloud vulnerability with maximum 10 severity score comes under “mass” exploitation

Easy-to-exploit flaw can give hackers passwords and cryptographic keys to vulnerable servers. 20WITH Security researchers are tracking what they say is the “mass exploitation” of a...

Microsoft alerts CyberLink to North Korean threat

Microsoft has alerted software company CyberLink to the misuse of its software by North Korean group Diamond Sleet. The cyber gang is believed to...

MacOS targeted by ClearFake malware campaign

A data-stealing program that targets Mac operating systems (OS) is being distributed to unsuspecting targets by means of fake web browser updates, Malwarebytes has...

Thousands of routers and cameras vulnerable to new 0-day attacks by hostile botnet

Internet scans show 7,000 devices may be vulnerable. The true number could be higher. 31WITH Miscreants are actively exploiting two new zero-day vulnerabilities to wrangle routers...

Most cyberattacks in Russia come from China and North Korea

Good diplomatic relations do not necessarily extend to cyberspace, with the most devastating cyber attacks in Russia coming from its friends. China and North...

FBI warning on MGM hacker group Scattered Spider, urges victims to come forward

The FBI is warning organizations to guard against the Scattered Spider ransom group, which has already breached dozens of American firms over the past...

Pro-Hamas cybergang develops complex infection tactics with new downloader

A threat actor targeting West Asian governments now uses a labyrinthine infection chain based on delivering a new initial access downloader dubbed IronWind, cybersecurity...

In a first, cryptographic keys protecting SSH connections stolen in new attack

An error as small as a single flipped memory bit is all it takes to expose a private key. 120WITH For the first time, researchers have...

Frontegg Forward is here, allowing enterprises to securely manage their customers’ digital identities

VentureBeat presents: AI Unleashed - An exclusive executive event for enterprise data leaders. Network and learn with industry peers. Learn More Frontegg, the four-year-old startup focused on making...

Digital.ai launches Denali to help enterprises automate secure software releases

Credit: VentureBeat made with Midjourney VentureBeat presents: AI Unleashed - An exclusive executive event for enterprise data leaders. Network and learn with industry peers. Learn More Digital.ai,...

Google’s “Web Integrity” Android API could kill “alternative” media clients

Web Integrity pivots to Android, could permanently kill YouTube Vanced-style apps. 50WITH Google is killing off its proposal for "Web Environment Integrity API" as a new web standard,...
HomeCyber