Security News > 2024 > June

PHP command injection flaw exploited to deliver ransomware (CVE-2024-4577)
2024-06-13 11:51

An OS command injection vulnerability in Windows-based PHP in CGI mode is being exploited by the TellYouThePass ransomware gang. Imperva says the attacks started on June 8, two days after the PHP development team pushed out fixes, and one day after Watchtowr researchers published a technical analysis of the flaw and proof-of-concept exploit code.

Student's flimsy bin bags blamed for latest NHS data breach
2024-06-13 11:30

Your profile can be used to present content that appears more relevant based on your possible interests, such as by adapting the order in which content is shown to you, so that it is even easier for you to find content that matches your interests. Content presented to you on this service can be based on your content personalisation profiles, which can reflect your activity on this or other services, possible interests and personal aspects.

Why SaaS Security is Suddenly Hot: Racing to Defend and Comply
2024-06-13 11:30

Recent supply chain cyber-attacks are prompting cyber security regulations in the financial sector to tighten compliance requirements, and other industries are expected to follow. Many companies...

AI and the Indian Election
2024-06-13 11:02

Deepfakes were not the only manifestation of AI in the Indian elections. Long before the election began, Indian Prime Minister Narendra Modi addressed a tightly packed crowd celebrating links between the state of Tamil Nadu in the south of India and the city of Varanasi in the northern state of Uttar Pradesh.

Pakistan-linked Malware Campaign Evolves to Target Windows, Android, and macOS
2024-06-13 10:26

Threat actors with ties to Pakistan have been linked to a long-running malware campaign dubbed Operation Celestial Force since at least 2018. The activity, still ongoing, entails the use of an...

Cybercriminals Employ PhantomLoader to Distribute SSLoad Malware
2024-06-13 10:19

The nascent malware known as SSLoad is being delivered by means of a previously undocumented loader called PhantomLoader, according to findings from cybersecurity firm Intezer. "The loader is...

Urgently needed: AI governance in cyber warfare
2024-06-13 09:19

If we abandon the ethics of cyber war, we might as well stop defending liberal democracies, because we're behaving like our opponents want us to behave. Traditionally, western countries did not invest in non-kinetic cyber warfare because at the time the West held the upper hand in terms of superior technologies that allowed it more room to maneuver in this domain.

Ukraine Police Arrest Suspect Linked to LockBit and Conti Ransomware Groups
2024-06-13 08:05

The Cyber Police of Ukraine has announced the arrest of a local man who is suspected to have offered their services to LockBit and Conti ransomware groups. The unnamed 28-year-old native of the...

Google Warns of Pixel Firmware Security Flaw Exploited as Zero-Day
2024-06-13 07:08

Google has warned that a security flaw impacting Pixel Firmware has been exploited in the wild as a zero-day. The high-severity vulnerability, tagged as CVE-2024-32896, has been described as an...

New Cross-Platform Malware 'Noodle RAT' Targets Windows and Linux Systems
2024-06-13 06:25

A previously undocumented cross-platform malware codenamed Noodle RAT has been put to use by Chinese-speaking threat actors either for espionage or cybercrime for years. While this backdoor was...