Security News > 2021

CISA, FBI and NSA Publish Joint Advisory and Scanner for Log4j Vulnerabilities
2021-12-28 19:34

Cybersecurity agencies from Australia, Canada, New Zealand, the U.S., and the U.K. on Wednesday released a joint advisory in response to widespread exploitation of multiple vulnerabilities in Apache's Log4j software library by nefarious adversaries. "Sophisticated cyber threat actors are actively scanning networks to potentially exploit Log4Shell, CVE-2021-45046, and CVE-2021-45105 in vulnerable systems. These vulnerabilities are likely to be exploited over an extended period."

New Exploit Lets Malware Attackers Bypass Patch for Critical Microsoft MSHTML Flaw
2021-12-28 19:33

A short-lived phishing campaign has been observed taking advantage of a novel exploit that bypassed a patch put in place by Microsoft to fix a remote code execution vulnerability affecting the MSHTML component with the goal of delivering Formbook malware. "The attachments represent an escalation of the attacker's abuse of the CVE-2021-40444 bug and demonstrate that even a patch can't always mitigate the actions of a motivated and sufficiently skilled attacker," SophosLabs researchers Andrew Brandt and Stephen Ormandy said in a new report published Tuesday.

New Flagpro malware linked to Chinese state-backed hackers
2021-12-28 19:23

BlackTech cyber-espionage APT group has been spotted targeting Japanese companies using novel malware that researchers call 'Flagpro'. The threat actor uses Flagpro in the initial stage of an attack for network reconnaissance, to evaluate the target's environment, and to download second-stage malware and execute it.

RedLine malware shows why passwords shouldn't be saved in browsers
2021-12-28 18:07

The RedLine information-stealing malware targets popular web browsers such as Chrome, Edge, and Opera, demonstrating why storing your passwords in browsers is a bad idea. The malware targets the 'Login Data' file found on all Chromium-based web browsers and is an SQLite database where usernames and passwords are saved.

LastPass users warned their master passwords are compromised
2021-12-28 17:27

Many LastPass users report that their master passwords have been compromised after receiving email warnings that someone tried to use it to log into their accounts from unknown locations. Reports of compromised LastPass master passwords are streaming in via multiple social media sites and online platforms, including Twitter, Reddit, and Hacker News.

Riskware Android streaming apps found on Samsung's Galaxy store
2021-12-28 16:38

Samsung's official Android app store, called the Galaxy Store, has had an infiltration of riskware apps that triggered multiple Play Protect warnings on people's devices. Scammers bet on the popularity of the pirate app, and indeed their cloned apps enjoyed a welcoming reception by the Samsung user community.

That Toy You Got for Christmas Could Be Spying on You
2021-12-28 16:31

Many adults found it charming when Mattel upgraded its classic Fisher-Price Chatter telephone for its 60th anniversary in October with actual Bluetooth capabilities, so grownups, too, can use it - and for actual mobile phone calls. The bug in Fisher-Price Chatter with Bluetooth is similar to a problem with a children's toy called My Friend Cayla - which is both a child's doll and a Bluetooth headset - that a researchers from Pen Test Partners also identified.

Check for Log4j vulnerabilities with this simple-to-use script
2021-12-28 16:06

If you're not certain whether your Java project is free from Log4j vulnerabilities, you should try this easy-to-use scanning tool immediately. Part of the problem is that Log4j is so deeply embedded in Java projects and dependencies that are used by quite a lot of tools.

2021 Wants Another Chance (A Lighter-Side Year in Review)
2021-12-28 11:00

As Chen tells it, the project manager tasked with coming up with a public product name for the Windows handheld OS was dead serious about the task. At the point when the project was dropped into his lap, the code name for the OS was Pegasus.

PECB Certified Lead Ethical Hacker: Take Your Career to the Next Level
2021-12-28 09:56

PECB offers the Certified Lead Ethical Hacker training course, which validates your ability to lawfully assess the security of a system, as well as identify and mitigate potential threats. The PECB Certified Lead Ethical Hacker exam comprises two parts: the practical exam and the report writing.