Security News

Matrix Botnet Exploits IoT Devices in Widespread DDoS Botnet Campaign
2024-11-27 05:21

A threat actor named Matrix has been linked to a widespread distributed denial-of-service (DoD) campaign that leverages vulnerabilities and misconfigurations in Internet of Things (IoT) devices to...

Hackers exploit critical bug in Array Networks SSL VPN products
2024-11-26 13:26

America's Cyber Defense Agency has received evidence of hackers actively exploiting a remote code execution vulnerability in SSL VPN products Array Networks AG and vxAG ArrayOS. [...]

RomCom Exploits Zero-Day Firefox and Windows Flaws in Sophisticated Cyberattacks
2024-11-26 10:34

The Russia-aligned threat actor known as RomCom has been linked to the zero-day exploitation of two security flaws, one in Mozilla Firefox and the other in Microsoft Windows, as part of attacks...

1000s of Palo Alto Networks firewalls hijacked as miscreants exploit critical hole
2024-11-22 21:27

PAN-PAN! Intruders inject web shell backdoors, crypto-coin miners, more Thousands of Palo Alto Networks firewalls were compromised by attackers exploiting two recently patched security bugs. The...

China-linked group abuses Fortinet 0-day with post-exploit VPN-credential stealer
2024-11-19 23:02

No word on when or if the issue will be fixed Chinese government-linked snoops are exploiting a zero-day bug in Fortinet's Windows VPN client to steal credentials and other information, according...

Helldown ransomware exploits Zyxel VPN flaw to breach networks
2024-11-19 17:00

The new 'Helldown' ransomware operation is believed to target vulnerabilities in Zyxel firewalls to breach corporate networks, allowing them to steal data and encrypt devices. [...]

Chinese Hackers Exploit T-Mobile and Other U.S. Telecoms in Broader Espionage Campaign
2024-11-19 07:02

U.S. telecoms giant T-Mobile has confirmed that it was also among the companies that were targeted by Chinese threat actors to gain access to valuable information. The adversaries, tracked as Salt...

Chinese hackers exploit Fortinet VPN zero-day to steal credentials
2024-11-18 21:20

Chinese threat actors use a custom post-exploitation toolkit named 'DeepData' to exploit a zero-day vulnerability in Fortinet's FortiClient Windows VPN client that steal credentials. [...]

Fake Discount Sites Exploit Black Friday to Hijack Shopper Information
2024-11-18 10:56

A new phishing campaign is targeting e-commerce shoppers in Europe and the United States with bogus pages that mimic legitimate brands with the goal of stealing their personal information ahead of...

Mystery Palo Alto Networks hijack-my-firewall zero-day now officially under exploit
2024-11-15 21:07

Yank access to management interface, stat A critical zero-day vulnerability in Palo Alto Networks' firewall management interface that can allow an unauthenticated attacker to remotely execute code...