Security News

YubiKey Side-Channel Attack
2024-09-06 15:16

There is a side-channel attack against YubiKey access tokens that allows someone to clone a device. It’s a complicated attack, requiring the victim’s username and password, and physical access to...

SonicWall SSLVPN access control flaw is now exploited in attacks
2024-09-06 13:20

SonicWall is warning that a recently fixed access control flaw tracked as CVE-2024-40766 in SonicOS is now "potentially" exploited in attacks, urging admins to apply patches as soon as possible. [...]

83% of organizations experienced at least one ransomware attack in the last year
2024-09-06 03:30

Ransomware is an all-too-common occurrence: 83% of organizations have experienced at least one ransomware attack in the last year, 46% of respondents experienced four or more and 14% indicated...

Russian military hackers linked to critical infrastructure attacks
2024-09-05 17:59

The United States and its allies have linked a group of Russian military intelligence hackers (tracked as Cadet Blizzard and Ember Bear) to Unit 29155 of Russia's Main Directorate of the General...

LiteSpeed Cache bug exposes 6 million WordPress sites to takeover attacks
2024-09-05 16:58

Yet, another critical severity vulnerability has been discovered in LiteSpeed Cache, a caching plugin for speeding up user browsing in over 6 million WordPress sites. [...]

New Cross-Platform Malware KTLVdoor Discovered in Attack on Chinese Trading Firm
2024-09-05 05:03

The Chinese-speaking threat actor known as Earth Lusca has been observed using a new backdoor dubbed KTLVdoor as part of a cyber attack targeting an unnamed trading company based in China. The...

Cisco Fixes Two Critical Flaws in Smart Licensing Utility to Prevent Remote Attacks
2024-09-05 04:40

Cisco has released security updates for two critical security flaws impacting its Smart Licensing Utility that could allow unauthenticated, remote attackers to elevate their privileges or access...

North Korean scammers plan wave of stealth attacks on crypto companies, FBI warns
2024-09-05 01:17

Feds warn of 'highly tailored, difficult-to-detect social engineering campaigns' The FBI has warned that North Korean operatives are plotting "complex and elaborate" social engineering attacks...

Planned Parenthood confirms cyber-attack as RansomHub threatens to leak data
2024-09-04 20:33

93GB of info feared pilfered in Montana by heartless crooks Planned Parenthood of Montana's chief exec says the org is responding to a cyber-attack on its systems, and has drafted in federal law...

Red team tool ‘MacroPack’ abused in attacks to deploy Brute Ratel
2024-09-04 20:31

The MacroPack framework, initially designed for Red Team exercises, is being abused by threat actors to deploy malicious payloads, including Havoc, Brute Ratel, and PhatomCore. [...]