Security News

Malware locks browser in kiosk mode to steal Google credentials
2024-09-14 14:09

A malware campaign uses the unusual method of locking users in their browser's kiosk mode to annoy them into entering their Google credentials, which are then stolen by information-stealing malware. [...]

Say Goodbye to Phishing: Must-Haves to Eliminate Credential Theft
2024-09-13 11:17

Even as cyber threats become increasingly sophisticated, the number one attack vector for unauthorized access remains phished credentials (Verizon DBIR, 2024). Solving this problem resolves over...

Hackers inject malicious JS in Cisco store to steal credit cards, credentials
2024-09-04 15:48

Cisco's site for selling company-themed merchandise is currently offline and under maintenance due to hackers compromising it with JavaScript code that steals sensitive customer details provided...

New QR Code Phishing Campaign Exploits Microsoft Sway to Steal Credentials
2024-08-28 06:49

Cybersecurity researchers are calling attention to a new QR code phishing (aka quishing) campaign that leverages Microsoft Sway infrastructure to host fake pages, once again highlighting the abuse...

New Qilin Ransomware Attack Uses VPN Credentials, Steals Chrome Data
2024-08-23 10:24

The threat actors behind a recently observed Qilin ransomware attack have stolen credentials stored in Google Chrome browsers on a small set of compromised endpoints. The use of credential...

SolarWinds left critical hardcoded credentials in its Web Help Desk product
2024-08-22 22:36

Why go to the effort of backdooring code when devs will basically do it for you accidentally anyway SolarWinds left hardcoded credentials in its Web Help Desk product that can be used by remote,...

Qilin ransomware now steals credentials from Chrome browsers
2024-08-22 21:40

The Qilin ransomware group has been using a new tactic and deploys a custom stealer to steal account credentials stored in Google Chrome browser. [...]

Hardcoded Credential Vulnerability Found in SolarWinds Web Help Desk
2024-08-22 16:35

SolarWinds has issued patches to address a new security flaw in its Web Help Desk (WHD) software that could allow remote unauthenticated users to gain unauthorized access to susceptible instances....

SolarWinds fixes hardcoded credentials flaw in Web Help Desk
2024-08-22 15:01

SolarWinds has released a hotfix for a critical Web Help Desk vulnerability that allows attackers to log into unpatched systems using hardcoded credentials. [...]

Czech Mobile Users Targeted in New Banking Credential Theft Scheme
2024-08-20 19:59

Mobile users in the Czech Republic are the target of a novel phishing campaign that leverages a Progressive Web Application (PWA) in an attempt to steal their banking account credentials. The...