Security News > 2019 > September

BMC vulnerabilities in Supermicro servers allow remote takeover, data exfiltration attacks
2019-09-03 11:10

A slew of vulnerabilities affecting the baseboard management controllers (BMCs) of Supermicro servers could be exploited by remote attackers to gain access to corporate networks, Eclypsium...

Massive iPhone Hack Targets Uyghurs
2019-09-03 11:09

China is being blamed for a massive surveillance operation that targeted Uyghur Muslims. This story broke in waves, the first wave being about the iPhone. Earlier this year, Google's Project Zero...

China’s new face-swapping app Zao gets whiplash-fast privacy backlash
2019-09-03 10:53

Fast trip: in two days, it debuted, shot to the top of China's App Store, sparked privacy outrage, and got banned by WeChat.

FBI asks Google for help finding criminals
2019-09-03 10:39

FBI agents issued Google with a warrant in November 2018, seeking its help with a bank robbery the month before.

BMC Vulnerabilities Expose Supermicro Servers to Remote USB-Attacks
2019-09-03 10:19

Enterprise servers powered by Supermicro motherboards can remotely be compromised by virtually plugging in malicious USB devices, cybersecurity researchers at firmware security company Eclypsium...

XKCD forums breached
2019-09-03 10:17

How did the Correct Horse Battery get Stapled?

USBAnywhere: BMC Flaws Expose Supermicro Servers to Remote Attacks
2019-09-03 10:02

Tens of thousands of servers made by Supermicro could be exposed to remote attacks from the internet due to baseboard management controller (BMC) vulnerabilities identified by researchers at...

‘USBAnywhere’ Bugs Open Supermicro Servers to Remote Attackers
2019-09-03 10:00

Trivial-to-exploit authentication flaws can give an unsophisticated remote attacker 'omnipotent' control over a server and its contents.

Enjoy the holiday weekend America? Well-rested? Good. Supermicro server boards can be remotely hijacked
2019-09-03 10:00

Virtual USB hub allows attackers to get into BMCs Tens of thousands of servers around the world are believed to be hosting a vulnerability that would allow an attacker to remotely commandeer them.…

Attackers are exploiting vulnerable WP plugins to backdoor sites
2019-09-03 09:05

A group of attackers that has been injecting WordPress-based sites with a script redirecting visitors to malicious and fraudulent pages has now also started backdooring the vulnerable...