Security News > 2021

QNAP caught napping as disclosure delay expires, critical NAS bugs revealed
2021-04-02 23:07

Some QNAP network attached storage devices are vulnerable to attack because of two critical vulnerabilities, one that enables unauthenticated remote code execution and another that provides the ability to write to arbitrary files. On Thursday QNAP released TS-231 firmware version 4.3.6.1620, which addresses a command injection vulnerability and a vulnerability in Apache HTTP server.

Hackers Set Up a Fake Cybersecurity Firm to Target Security Experts
2021-04-02 23:05

A North Korean government-backed campaign targeting cybersecurity researchers with malware has re-emerged with new tactics in their arsenal as part of a fresh social engineering attack. In an update shared on Wednesday, Google's Threat Analysis Group said the attackers behind the operation set up a fake security company called SecuriElite and a slew of social media accounts across Twitter and LinkedIn in an attempt to trick unsuspecting researchers into visiting the company's booby-trapped website "Where a browser exploit was waiting to be triggered."

Friday Squid Blogging: 500-Million-Year-Old Cephalopod
2021-04-02 21:10

As the article notes Intel have an overly rich CISC system at the CPU ISA level, but in reality dropped the internal CISC von Numann architecture for a RISC Harvard architecture a very long time ago. The "Go faster stripes" mentality is what has given us the joys of those low level hardware faults like Meltdown and Spector that to solve require not just major changes in the low level "Register Transfer Language"(RTL) that underlies even the most basic of microcode, it more importantly takes ten's of percents of ISA level performance away from the user.

Brown University hit by cyberattack, some systems still offline
2021-04-02 20:01

Brown University, a private US research university, had to disable systems and cut connections to the data center after suffering a cyberattack on Tuesday. The university's Computing & Information Services staff took "a number of aggressive steps to protect the University's digital resources, including shutting down connections to our central data center and systems within it."

FBI: APTs Actively Exploiting Fortinet VPN Security Holes
2021-04-02 19:56

UPDATE. The FBI and the Cybersecurity and Infrastructure Security Agency are warning that advanced persistent threat nation-state actors are actively exploiting known security vulnerabilities in the Fortinet FortiOS cybersecurity operating system, affecting the company's SSL VPN products. The bug tracked as CVE-2018-13379 is a path-traversal issue in Fortinet FortiOS, where the SSL VPN web portal allows an unauthenticated attacker to download system files via specially crafted HTTP resource requests.

FirstNet public safety cellular network adds 5G and data encryption
2021-04-02 19:04

AT&T's public safety network picks up new features, including full tower-to-core encryption and a custom 5G setup. FirstNet, the dedicated public safety cell carrier, is adding 5G support and new encryption for user data.

Asteelflash electronics maker hit by REvil ransomware attack
2021-04-02 18:17

Asteelflash, a leading French electronics manufacturing services company, has suffered a cyberattack by the REvil ransomware gang who is demanding a $24 million ransom. Asteelflash is a world-leading French electronics manufacturing services company that specializes in the design, engineering, and printing of printed circuit boards.

Call of Duty Cheats Expose Gamers to Malware, Takeover
2021-04-02 18:16

Activision, the company behind Call of Duty: Warzone, has issued a warning that a threat actor is taking out ads for cheat tools, which instead turn out to be remote-access trojan malware. The scam was first floated in March when a cyberattacker posted in hacking forums that they had a free, "Newbie-friendly" method for spreading a RAT: Convince victims the malware is a video game cheat, Activision said in its warning.

FBI and CISA warn of state hackers attacking Fortinet FortiOS servers
2021-04-02 17:04

The Federal Bureau of Investigation and the Cybersecurity and Infrastructure Security Agency warn of advanced persistent threat actors targeting Fortinet FortiOS servers using multiple exploits. In the Joint Cybersecurity Advisory published today, the agencies warn admins and users that the state-sponsored hacking groups are "Likely" exploiting Fortinet FortiOS vulnerabilities CVE-2018-13379, CVE-2020-12812, and CVE-2019-5591.

Popular Twitch AdBlock shuts down after Twitch breaks extension
2021-04-02 16:54

The popular Twitch AdBlock extension has been removed from both Chrome Web Store and Firefox Addons site. Twitch AdBlock was the choice of extension among Twitch users for restricting ads when using Twitch.