Security News > 2022 > February

Iranian hackers target VMware Horizon servers with Log4j exploits
2022-02-18 19:55

An Iranian-aligned hacking group tracked as TunnelVision was spotted exploiting Log4j on VMware Horizon servers to breach corporate networks in the Middle East and the United States. Security analysts at SentinelLabs who have been tracking the activity chose that name due to the group's heavy reliance on tunneling tools, which help them hide their activities from detecting solutions.

Adobe warns of second critical security hole in Adobe Commerce, Magento
2022-02-18 19:20

Adobe has put out a warning about another critical security bug affecting its Magento/Adobe Commerce product - and IT pros need to install a second patch after an initial update earlier this week failed to fully plug the first one. It's tracked as ​​CVE-2022-24087 and - like the earlier vuln, CVE-2022-24086 - impacts both Magento Open Source and Adobe Commerce.

FCC proposes $45 million fine for health insurance robocaller
2022-02-18 18:47

The US Federal Communications Commission today proposed the largest-ever fine against a robocaller for Telephone Consumer Protection Act violations. The Commission wants to hit Florida-based lead generator Interstate Brokers with a $45 million TCPA fine for making more than 500,000 unlawful robocalls without an emergency purpose or the consumers' prior express consent.

New Critical RCE Bug Found in Adobe Commerce, Magento
2022-02-18 16:55

Another zero-day bug has been discovered in the Magento Open Source and Adobe Commerce platforms, while researchers have created a working proof-of-concept exploit for the recently patched CVE-2022-24086 vulnerability that came under active attack and forced Adobe to push out an emergency patch last weekend. The new flaw, detailed on Thursday, has the same level of severity assigned to its predecessor, which Adobe patched on Feb. 13.

WordPress force installs UpdraftPlus patch on 3 million sites
2022-02-18 16:19

WordPress has taken the rare step of force-updating the UpdraftPlus plugin on all sites to fix a high-severity vulnerability allowing website subscribers to download the latest database backups, which often contain credentials and PII. Three million sites use the popular WordPress plugin, so the potential for exploitation was substantial, affecting a significant share of the internet, including large platforms. The vulnerability affects UpdraftPlus versions 1.16.7 to 1.22.2, and the developers fixed it with the release of 1.22.3 or 2.22.3 for the Premium version.

How to add notes to iCloud passwords in macOS 12.3 and iOS 15.4
2022-02-18 15:34

How to add notes to iCloud passwords in macOS 12.3 and iOS 15.4. Now, with iOS 15.4 and macOS 12.3, Apple has added another feature to iCloud Keychain: Notes.

Should we expect to keep communication private in the digital age?
2022-02-18 15:21

I suggested, let's just be realistic and say we should accept that we can't have a realistic expectation of privacy. Btrower said this issue is a "Slam dunk" - yes, but how? Because, "You have no hope of privacy if a powerful enough adversary targets you. There are many routes to failure and exposure. The only hope of modest privacy is being someone who is not interesting enough to look at. Given the value of successfully targeting you as a consumer, you are indeed interesting to look at for anybody who can capitalize on this."

Conti ransomware gang takes over TrickBot malware operation
2022-02-18 15:11

After four years of activity and numerous takedown attempts, the death knell of TrickBot has sounded as its top members move under new management, the Conti ransomware syndicate, who plan to replace it with the stealthier BazarBackdoor malware. TrickBot is a Windows malware platform that uses multiple modules for various malicious activities, including information stealing, password stealing, infiltrating Windows domains, initial access to networks, and malware delivery.

Cyberattack threat: Corporate users infected via Microsoft Teams
2022-02-18 14:31

Cyberattack threat: Corporate users infected via Microsoft Teams. Researchers from Avanan, a Check Point company, have announced the discovery of attacks exploiting the Microsoft Teams communication platform to infect corporate users.

Severe WordPress Plug-In UpdraftPlus Bug Threatens Backups
2022-02-18 14:25

The WordPress plug-in "UpdraftPlus" was patched on Wednesday to correct a vulnerability that left sensitive backups at risk, potentially exposing personal information and authentication data. UpdraftPlus is a tool for creating, restoring and migrating backups for WordPress files, databases, plug-ins and themes.