Security News

China-linked group abuses Fortinet 0-day with post-exploit VPN-credential stealer
2024-11-19 23:02

No word on when or if the issue will be fixed Chinese government-linked snoops are exploiting a zero-day bug in Fortinet's Windows VPN client to steal credentials and other information, according...

Helldown ransomware exploits Zyxel VPN flaw to breach networks
2024-11-19 17:00

The new 'Helldown' ransomware operation is believed to target vulnerabilities in Zyxel firewalls to breach corporate networks, allowing them to steal data and encrypt devices. [...]

Chinese Hackers Exploit T-Mobile and Other U.S. Telecoms in Broader Espionage Campaign
2024-11-19 07:02

U.S. telecoms giant T-Mobile has confirmed that it was also among the companies that were targeted by Chinese threat actors to gain access to valuable information. The adversaries, tracked as Salt...

Chinese hackers exploit Fortinet VPN zero-day to steal credentials
2024-11-18 21:20

Chinese threat actors use a custom post-exploitation toolkit named 'DeepData' to exploit a zero-day vulnerability in Fortinet's FortiClient Windows VPN client that steal credentials. [...]

Fake Discount Sites Exploit Black Friday to Hijack Shopper Information
2024-11-18 10:56

A new phishing campaign is targeting e-commerce shoppers in Europe and the United States with bogus pages that mimic legitimate brands with the goal of stealing their personal information ahead of...

Mystery Palo Alto Networks hijack-my-firewall zero-day now officially under exploit
2024-11-15 21:07

Yank access to management interface, stat A critical zero-day vulnerability in Palo Alto Networks' firewall management interface that can allow an unauthenticated attacker to remotely execute code...

Botnet exploits GeoVision zero-day to install Mirai malware
2024-11-15 19:39

A malware botnet is exploiting a zero-day vulnerability in end-of-life GeoVision devices to compromise and recruit them for likely DDoS or cryptomining attacks. [...]

High-Severity Flaw in PostgreSQL Allows Hackers to Exploit Environment Variables
2024-11-15 06:40

Cybersecurity researchers have disclosed a high-severity security flaw in the PostgreSQL open-source database system that could allow unprivileged users to alter environment variables, and...

Russian Hackers Exploit New NTLM Flaw to Deploy RAT Malware via Phishing Emails
2024-11-14 05:43

A newly patched security flaw impacting Windows NT LAN Manager (NTLM) was exploited as a zero-day by a suspected Russia-linked actor as part of cyber attacks targeting Ukraine. The vulnerability...

HTTP your way into Citrix's Virtual Apps and Desktops with fresh exploit code
2024-11-12 16:11

'Once again, we've lost a little more faith in the internet,' researcher says Researchers are publicizing a proof of concept (PoC) exploit for what they're calling an unauthenticated remote code...