Security News > 2024 > September

New HTML Smuggling Campaign Delivers DCRat Malware to Russian-Speaking Users
2024-09-27 09:00

Russian-speaking users have been targeted as part of a new campaign distributing a commodity trojan called DCRat (aka DarkCrystal RAT) by means of a technique known as HTML smuggling. The...

U.S. Sanctions Two Crypto Exchanges for Facilitating Cybercrime and Money Laundering
2024-09-27 07:47

The U.S. government on Thursday sanctioned two cryptocurrency exchanges and unsealed an indictment against a Russian national for his alleged involvement in the operation of several money...

Critical NVIDIA Container Toolkit Vulnerability Could Grant Full Host Access to Attackers
2024-09-27 05:54

A critical security flaw has been disclosed in the NVIDIA Container Toolkit that, if successfully exploited, could allow threat actors to break out of the confines of a container and gain full...

3 tips for securing IoT devices in a connected world
2024-09-27 05:00

IoT devices have become integral to how many organizations operate. From Smart TVs in conference rooms to connected sensors and wireless security cameras, these connected devices are now a fixture...

Tosint: Open-source Telegram OSINT tool
2024-09-27 04:30

Tosint is an open-source Telegram OSINT tool that extracts useful information from Telegram bots and channels. It’s suited for security researchers, investigators, and others who want to gather...

Developing an effective cyberwarfare response plan
2024-09-27 04:00

In this Help Net Security interview, Nadir Izrael, CTO at Armis, discusses how AI has transformed cyberwarfare by amplifying attacks’ scale and sophistication. Izrael emphasizes the need for...

How to lock and hide iPhone apps in iOS 18
2024-09-27 03:00

iOS 18 allows you to lock and hide apps to protect the information within them by requiring Face ID, Touch ID, or your passcode for access, while also concealing the content from searches,...

CUPS flaws enable Linux remote code execution, but there’s a catch
2024-09-26 22:03

Under certain conditions, attackers can chain a set of vulnerabilities in multiple components of the CUPS open-source printing system to execute arbitrary code remotely on vulnerable machines. [...]

Patch now: Critical Nvidia bug allows container escape, complete host takeover
2024-09-26 21:42

33% of cloud environments using the toolkit impacted, we're told A critical bug in Nvidia's widely used Container Toolkit could allow a rogue user or software to escape their containers and...

New RomCom malware variant 'SnipBot' spotted in data theft attacks
2024-09-26 21:26

A new variant of the RomCom malware called SnipBot, has been used in attacks that pivot on the network to steal data from compromised systems. [...]