Security News > 2022 > April

Critical RCE Flaw Reported in WordPress Elementor Website Builder Plugin
2022-04-17 22:47

Elementor, a WordPress website builder plugin with over five million active installations, has been found to be vulnerable to an authenticated remote code execution flaw that could be abused to take over affected websites. Plugin Vulnerabilities, which disclosed the flaw last week, said the bug was introduced in version 3.6.0 that was released on March 22, 2022.

Customize your Windows 11 experience with these apps
2022-04-17 21:30

The big feature update is currently available for download as an optional update and if you've already upgraded to the new operating system, you can try some new third-party programs to customize the experience and get the most out of Windows 11. Windows 11 is essentially Windows 10 with a new design, so it also comes with the same bloatware problem.

Customize Windows 11 experience with these apps
2022-04-17 21:30

The big feature update is currently available for download as an optional update and if you've already upgraded to the new operating system, you can try some new third-party programs to customize the experience and get the most out of Windows 11. Windows 11 is essentially Windows 10 with a new design, so it also comes with the same bloatware problem.

U.S. Warns of APT Hackers Targeting ICS/SCADA Systems with Specialized Malware
2022-04-17 20:07

The U.S. government on Wednesday warned of nation-state actors deploying specialized malware to maintain access to industrial control systems and supervisory control and data acquisition devices. "The APT actors have developed custom-made tools for targeting ICS/SCADA devices," multiple U.S. agencies said in an alert.

Russian Hackers Tried Attacking Ukraine's Power Grid with Industroyer2 Malware
2022-04-17 20:07

"The attackers attempted to take down several infrastructure components of their target, namely: Electrical substations, Windows-operated computing systems, Linux-operated server equipment, [and] active network equipment," The State Service of Special Communications and Information Protection of Ukraine said in a statement. Slovak cybersecurity firm ESET, which collaborated with CERT-UA to analyze the attack, said the attempted intrusion involved the use of ICS-capable malware and regular disk wipers, with the adversary unleashing an updated variant of the Industroyer malware, which was first deployed in a 2016 assault on Ukraine's power grid.

Critical Auth Bypass Bug Reported in Cisco Wireless LAN Controller Software
2022-04-17 20:04

Cisco has released patches to contain a critical security vulnerability affecting the Wireless LAN Controller that could be abused by an unauthenticated, remote attacker to take control of an affected system. "An attacker could exploit this vulnerability by logging in to an affected device with crafted credentials."

Google Releases Urgent Chrome Update to Patch Actively Exploited Zero-Day Flaw
2022-04-17 20:04

Google on Thursday shipped emergency patches to address two security issues in its Chrome web browser, one of which it says is being actively exploited in the wild.Clément Lecigne of Google's Threat Analysis Group has been credited with reporting the flaw on April 13, 2022.

GitHub Says Hackers Breached Dozens of Organizations Using Stolen OAuth Access Tokens
2022-04-17 20:04

Cloud-based repository hosting service GitHub on Friday revealed that it discovered evidence of an unnamed adversary capitalizing on stolen OAuth user tokens to unauthorizedly download private data from several organizations. "An attacker abused stolen OAuth user tokens issued to two third-party OAuth integrators, Heroku and Travis-CI, to download data from dozens of organizations, including NPM," GitHub's Mike Hanley disclosed in a report.

Microsoft: Office 2013 will reach end of support in April 2023
2022-04-17 14:00

Microsoft has reminded customers earlier this week that Microsoft Office 2013 is approaching its end of support next year, advising them to switch to a newer version to reduce their exposure to security risks. "After five years of Mainstream Support, and five years of Extended Support, Office 2013 will reach the End of Extended Support on April 11, 2023. Per the Fixed Lifecycle Policy, after this date security updates for Office 2013 will no longer be available," Microsoft told customers.

Week in review: Attackers exploiting VMware RCE, Microsoft fixes actively exploited zero-day
2022-04-17 08:00

Sandworm hackers tried to disrupt Ukraine's power gridThe Computer Emergency Response Team of Ukraine, with the help of ESET and Microsoft security experts, has thwarted a cyber attack by the Sandworm hackers, who tried to shut down electrical substations run by an energy provider in Ukraine. How to improve enterprise password security?In this video for Help Net Security, Darren Siegel, Product Specialist at Specops Software, talks about the importance of password security and what makes them vulnerable.