Security News

TrickMo Android Trojan Exploits Accessibility Services for On-Device Banking Fraud
2024-09-13 11:17

Cybersecurity researchers have uncovered a new variant of an Android banking trojan called TrickMo that comes packed with new capabilities to evade analysis and display fake login screens to...

New Linux Malware Campaign Exploits Oracle Weblogic to Mine Cryptocurrency
2024-09-13 05:39

Cybersecurity researchers have uncovered a new malware campaign targeting Linux environments to conduct illicit cryptocurrency mining. The activity, which specifically singles out the Oracle...

Adobe fixed Acrobat bug, neglected to mention whole zero-day exploit thing
2024-09-12 18:29

SaaS seller sets severity to 'critical' Adobe's patch for a remote code execution (RCE) bug in Acrobat this week doesn't mention that the vulnerability is considered a zero-day nor that a...

Hackers targeting WhatsUp Gold with public exploit since August
2024-09-12 16:27

Hackers have been leveraging publicly available exploit code for two critical vulnerabilities in the WhatsUp Gold network availability and performance monitoring solution from Progress Software. [...]

Adobe completes fix for Reader bug with known PoC exploit (CVE-2024-41869)
2024-09-12 12:05

Among the security updates released by Adobe on Tuesday are those for various versions of Adobe Acrobat and Reader, which fix two critical flaws that could lead to arbitrary code execution:...

Adobe fixes Acrobat Reader zero-day with public PoC exploit
2024-09-11 17:42

A cybersecurity researcher is urging users to upgrade Adobe Acrobat Reader after a fix was released yesterday for a remote code execution zero-day with a public in-the-wild proof-of-concept exploit. [...]

New PIXHELL Attack Exploits LCD Screen Noise to Exfiltrate Data from Air-Gapped Computers
2024-09-10 10:10

A new side-channel attack dubbed PIXHELL could be abused to target air-gapped computers by breaching the "audio gap" and exfiltrating sensitive information by taking advantage of the noise...

Chinese Hackers Exploit Visual Studio Code in Southeast Asian Cyberattacks
2024-09-09 12:16

The China-linked advanced persistent threat (APT) group known as Mustang Panda has been observed weaponizing Visual Studio Code software as part of espionage operations targeting government...

September 2024 Patch Tuesday forecast: Downgrade is the new exploit
2024-09-06 05:02

I asked for a calm August 2024 Patch Tuesday in last month’s forecast article and that came to pass. The updates released were limited to the regular operating systems and all forms of Office...

Cisco fixes root escalation vulnerability with public exploit code
2024-09-04 18:33

Cisco has fixed a command injection vulnerability in the Identity Services Engine (ISE) with public exploit code that lets attackers escalate privileges to root on vulnerable systems. [...]