Security News

Researchers Find Exploit Allowing NTLMv1 Despite Active Directory Restrictions
2025-01-16 11:20

Cybersecurity researchers have found that the Microsoft Active Directory Group Policy that's designed to disable NT LAN Manager (NTLM) v1 can be trivially bypassed by a misconfiguration. "A simple...

Python-Based Malware Powers RansomHub Ransomware to Exploit Network Flaws
2025-01-16 06:45

Cybersecurity researchers have detailed an attack that involved a threat actor utilizing a Python-based backdoor to maintain persistent access to compromised endpoints and then leveraged this...

Hackers exploit critical Aviatrix Controller RCE flaw in attacks
2025-01-13 17:57

Threat actors are exploiting a critical remote command execution vulnerability, tracked as CVE-2024-50603, in Aviatrix Controller instances to install backdoors and crypto miners. [...]

Hackers Exploit Aviatrix Controller Vulnerability to Deploy Backdoors and Crypto Miners
2025-01-13 13:33

A recently disclosed critical security flaw impacting the Aviatrix Controller cloud networking platform has come under active exploitation in the wild to deploy backdoors and cryptocurrency...

Nominet probes network intrusion linked to Ivanti zero-day exploit
2025-01-13 10:29

Unauthorized activity detected, but no backdoors found UK domain registrar Nominet is investigating a potential intrusion into its network related to the latest Ivanti zero-day exploits.…

Fake LDAPNightmware exploit on GitHub spreads infostealer malware
2025-01-11 15:21

A deceptive proof-of-concept (PoC) exploit for CVE-2024-49113 (aka "LDAPNightmare") on GitHub infects users with infostealer malware that exfiltrates sensitive data to an external FTP server. [...]

New Web3 attack exploits transaction simulations to steal crypto
2025-01-10 18:12

Threat actors are employing a new tactic called "transaction simulation spoofing" to steal crypto, with one attack successfully stealing 143.45 Ethereum, worth approximately $460,000. [...]

Google Project Zero Researcher Uncovers Zero-Click Exploit Targeting Samsung Devices
2025-01-10 15:39

Cybersecurity researchers have detailed a now-patched security flaw impacting Monkey's Audio (APE) decoder on Samsung smartphones that could lead to code execution. The high-severity...

Zero-day exploits plague Ivanti Connect Secure appliances for second year running
2025-01-09 14:45

Factory resets and apply patches is the advice amid fortnight delay for other appliances The cybersecurity industry is urging those in charge of defending their orgs to take mitigation efforts...

Security pros baited with fake Windows LDAP exploit traps
2025-01-09 13:16

Tricky attackers trying yet again to deceive the good guys on home territory Security researchers are once again being lured into traps by attackers, this time with fake exploits of serious...