Security News > 2021

VMware releases fix for severe View Planner RCE vulnerability
2021-03-04 17:09

VMware has addressed a high severity unauthenticated RCE vulnerability in VMware View Planner, allowing attackers to abuse servers running unpatched software for remote code execution. The vulnerability was discovered and reported to VMware by Positive Technologies web application security expert Mikhail Klyuchnikov.

CISA Orders Federal Agencies to Patch Exchange Servers
2021-03-04 17:08

"CISA has determined that this exploitation of Microsoft Exchange on-premises products poses an unacceptable risk to Federal Civilian Executive Branch agencies and requires emergency action," reads the March 3 alert. "With organizations migrating to Microsoft Office 365 en masse over the last few years, it's easy to forget that on-premises Exchange servers are still in service," Saryu Nayyar, CEO, Gurucul, said via email.

Hijacking traffic to Microsoft’s windows.com with bitflipping
2021-03-04 16:37

The exploitation of bitsquatted domains tends to be automatic when a DNS request is being made from a computer impacted by a hardware error, solar flare, or cosmic rays, thereby flipping one of the bits of the legitimate domain names. Researacher sees real windows.com traffic coming to his domains!

Researcher bitsquats Microsoft's windows.com to steal traffic
2021-03-04 16:37

The exploitation of bitsquatted domains tends to be automatic when a DNS request is being made from a computer impacted by a hardware error, solar flare, or cosmic rays, thereby flipping one of the bits of the legitimate domain names. Researacher sees real windows.com traffic coming to his domains!

COVID-19 Vaccine Spear-Phishing Attacks Jump 26 Percent
2021-03-04 16:01

Between October and January the average number of COVID-19 vaccine-related spear-phishing attacks grew 26 percent, said Barracuda Networks researchers. The types of cybercriminal activity varies, from sending malicious emails that purport to be from the Centers for Disease Control and Prevention, to posting advertisements on underground forums touting vaccine doses for sale.

Hacked SendGrid accounts used in phishing attacks to steal logins
2021-03-04 16:00

A phishing campaign targeting users of Outlook Web Access and Office 365 services collected thousands of credentials relying on trusted domains such as SendGrid. Using Zoom invites as a lure and an extensive list of email addresses, the operators of the phishing campaign delivered messages from hacked accounts on the SendGrid cloud-based email delivery platform.

Managed Services Provider CompuCom Hit by Malware
2021-03-04 15:59

Managed services provider CompuCom was recently targeted in a cyberattack that led to some disruption to customer services and internal operations. In a statement issued on Wednesday, the MSP said some of its IT systems became infected with a piece of malware, which impacted the services provided to certain customers.

Report: Quality, not quantity, is the hallmark of the latest waves of phishing attacks
2021-03-04 15:24

Cybercriminals have changed tactics since COVID-19, with surgically precise social engineering attacks targeting business apps replacing batch-and-blast phishing. A survey of IT professionals and leaders from email security firm GreatHorn finds big changes afoot in the world of email-targeting cyberattacks: The daily quantity of attacks has decreased, but those that remain are more precise and easier to miss.

Cybercriminals Finding Ways to Bypass '3D Secure' Fraud Prevention System
2021-03-04 15:17

Security researchers with threat intelligence firm Gemini Advisory say they have observed dark web activities related to bypassing 3D Secure, which is designed to improve the security of online credit and debit card transactions. Gemini's security researchers say that vulnerabilities in earlier versions of 3DS could have been exploited to bypass security.

Three Top Russian Cybercrime Forums Hacked
2021-03-04 15:01

Over the past few weeks, three of the longest running and most venerated Russian-language online forums serving thousands of experienced cybercriminals have been hacked. Members of all three forums are worried the incidents could serve as a virtual Rosetta Stone for connecting the real-life identities of the same users across multiple crime forums.