Security News

Botnet exploits GeoVision zero-day to install Mirai malware
2024-11-15 19:39

A malware botnet is exploiting a zero-day vulnerability in end-of-life GeoVision devices to compromise and recruit them for likely DDoS or cryptomining attacks. [...]

High-Severity Flaw in PostgreSQL Allows Hackers to Exploit Environment Variables
2024-11-15 06:40

Cybersecurity researchers have disclosed a high-severity security flaw in the PostgreSQL open-source database system that could allow unprivileged users to alter environment variables, and...

Russian Hackers Exploit New NTLM Flaw to Deploy RAT Malware via Phishing Emails
2024-11-14 05:43

A newly patched security flaw impacting Windows NT LAN Manager (NTLM) was exploited as a zero-day by a suspected Russia-linked actor as part of cyber attacks targeting Ukraine. The vulnerability...

HTTP your way into Citrix's Virtual Apps and Desktops with fresh exploit code
2024-11-12 16:11

'Once again, we've lost a little more faith in the internet,' researcher says Researchers are publicizing a proof of concept (PoC) exploit for what they're calling an unauthenticated remote code...

New Ymir Ransomware Exploits Memory for Stealthy Attacks; Targets Corporate Networks
2024-11-12 06:00

Cybersecurity researchers have flagged a new ransomware family called Ymir that was deployed in an attack two days after systems were compromised by a stealer malware called RustyStealer. "Ymir...

Cybercriminals Use Excel Exploit to Spread Fileless Remcos RAT Malware
2024-11-11 06:13

Cybersecurity researchers have discovered a new phishing campaign that spreads a new fileless variant of known commercial malware called Remcos RAT. Remcos RAT "provides purchases with a wide...

SteelFox and Rhadamanthys Malware Use Copyright Scams, Driver Exploits to Target Victims
2024-11-07 09:42

An ongoing phishing campaign is employing copyright infringement-related themes to trick victims into downloading a newer version of the Rhadamanthys information stealer since July 2024....

VEILDrive Attack Exploits Microsoft Services to Evade Detection and Distribute Malware
2024-11-06 17:52

An ongoing threat campaign dubbed VEILDrive has been observed taking advantage of legitimate services from Microsoft, including Teams, SharePoint, Quick Assist, and OneDrive, as part of its modus...

Cast a hex on ChatGPT to trick the AI into writing exploit code
2024-10-29 22:30

'It was like watching a robot going rogue' says researcher OpenAI's language model GPT-4o can be tricked into writing exploit code by encoding the malicious instructions in hexadecimal, which...

Adversarial groups adapt to exploit systems in new ways
2024-10-28 04:30

In this Help Net Security video, Jake King, Head of Threat & Security Intelligence at Elastic, discusses the key findings from the 2024 Elastic Global Threat Report. Adversaries are utilizing...