Security News > 2022 > April

Wind turbine firm Nordex hit by Conti ransomware attack
2022-04-15 01:54

The Conti ransomware operation has claimed responsibility for a cyberattack on wind turbine giant Nordex, which was forced to shut down IT systems and remote access to the managed turbines earlier this month. BleepingComputer was told on March 31st that the company suffered a Conti ransomware attack which caused the entire platform to go offline.

Critical Windows RPC CVE-2022-26809 flaw raises concerns — Patch now
2022-04-14 22:50

Microsoft has fixed a new Windows RPC CVE-2022-26809 vulnerability that is raising concerns among security researchers due to its potential for widespread, significant cyberattacks once an exploit is developed.If exploited, any commands will be executed at the same privilege level as the RPC server, which in many cases has elevated or SYSTEM level permissions, providing full administrative access to the exploited device.

Rarible NFT Marketplace Flaw Could've Let Attackers Hijack Crypto Wallets
2022-04-14 22:42

Cybersecurity researchers have disclosed a now-fixed security flaw in the Rarible non-fungible token marketplace that, if successfully exploited, could have led to account takeover and theft of cryptocurrency assets. Rarible, an NFT marketplace that enables users to create, buy, and sell digital NFT art like photographs, games, and memes, has over 2.1 million active users.

This WordPress plugin protects the emails displayed on your website
2022-04-14 22:25

This WordPress plugin protects the emails displayed on your website We may be compensated by vendors who appear on this page through methods such as affiliate links or sponsored partnerships. You can still display email addresses according to custom preferences, with control over fonts, colors and more, but you'll ensure that criminal data mining misses those emails when trawling the web.

Critical VMware Cloud Director Bug Could Let Hackers Takeover Entire Cloud Infrastructure
2022-04-14 22:06

Cloud computing and virtualization technology firm VMWare on Thursday rolled out an update to resolve a critical security flaw in its Cloud Director product that could be weaponized to launch remote code execution attacks. "An authenticated, high privileged malicious actor with network access to the VMware Cloud Director tenant or provider may be able to exploit a remote code execution vulnerability to gain access to the server," VMware said in an advisory.

FBI: Payment app users targeted in social engineering attacks
2022-04-14 21:53

Cybercriminals are attempting to trick American users of digital payment apps into making instant money transfers in social engineering attacks using text messages with fake bank fraud alerts. "Under the pretext of reversing the fake money transfer, victims are swindled into sending payment to bank accounts under the control of the cyber actors," the FBI said.

Google Chrome emergency update fixes zero-day used in attacks
2022-04-14 21:36

Google has released Chrome 100.0.4896.127 for Windows, Mac, and Linux, to fix a high-severity zero-day vulnerability actively used by threat actors in attacks. "Google is aware that an exploit for CVE-2022-1364 exists in the wild," Google said in a security advisory released today.

Cisco's Webex app phoned home audio telemetry even when muted
2022-04-14 20:55

Boffins at two US universities have found that muting popular native video-conferencing apps fails to disable device microphones - and that these apps have the ability to access audio data when muted, or actually do so. One app transmits statistics of the audio to its telemetry servers while the app is muted.

Critical VMware Workspace ONE Access Flaw Under Active Exploitation in the Wild
2022-04-14 20:14

A week after VMware released patches to remediate eight security vulnerabilities in VMware Workspace ONE Access, threat actors have begun to actively exploit one of the critical flaws in the wild. Tracked as CVE-2022-22954, the critical issue relates to a remote code execution vulnerability that stems from server-side template injection in VMware Workspace ONE Access and Identity Manager.

Windows 11 tool to add Google Play secretly installed malware
2022-04-14 19:55

A popular Windows 11 ToolBox script used to add the Google Play Store to the Android Subsystem has secretly infected users with malicious scripts, Chrome extensions, and potentially other malware. While there were ways to use ADB to sideload Android apps, users began looking for methods that let them add the Google Play Store to Windows 11.