Security News

Chinese Hackers Exploit Visual Studio Code in Southeast Asian Cyberattacks
2024-09-09 12:16

The China-linked advanced persistent threat (APT) group known as Mustang Panda has been observed weaponizing Visual Studio Code software as part of espionage operations targeting government...

September 2024 Patch Tuesday forecast: Downgrade is the new exploit
2024-09-06 05:02

I asked for a calm August 2024 Patch Tuesday in last month’s forecast article and that came to pass. The updates released were limited to the regular operating systems and all forms of Office...

Cisco fixes root escalation vulnerability with public exploit code
2024-09-04 18:33

Cisco has fixed a command injection vulnerability in the Identity Services Engine (ISE) with public exploit code that lets attackers escalate privileges to root on vulnerable systems. [...]

Hacktivists Exploits WinRAR Vulnerability in Attacks Against Russia and Belarus
2024-09-03 13:29

A hacktivist group known as Head Mare has been linked to cyber attacks that exclusively target organizations located in Russia and Belarus. "Head Mare uses more up-to-date methods for obtaining...

Week in review: SonicWall critical firewalls flaw fixed, APT exploits WPS Office for Windows RCE
2024-09-01 08:00

Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: SonicWall patches critical flaw affecting its firewalls (CVE-2024-40766) SonicWall has patched a...

North Korean Hackers Deploy FudModule Rootkit via Chrome Zero-Day Exploit
2024-08-31 15:35

A recently patched security flaw in Google Chrome and other Chromium web browsers was exploited as a zero-day by North Korean actors in a campaign designed to deliver the FudModule rootkit. The...

North Korean hackers exploit Chrome zero-day to deploy rootkit
2024-08-30 17:04

North Korean hackers have exploited a recently patched Google Chrome zero-day (CVE-2024-7971) to deploy the FudModule rootkit after gaining SYSTEM privileges using a Windows Kernel exploit. [...]

Cyberattackers Exploit Google Sheets for Malware Control in Likely Espionage Campaign
2024-08-30 13:04

Cybersecurity researchers have uncovered a novel malware campaign that leverages Google Sheets as a command-and-control (C2) mechanism. The activity, detected by Proofpoint starting August 5,...

Threat Actors Exploit Microsoft Sway to Host QR Code Phishing Campaigns
2024-08-29 20:42

Threat actors are abusing Microsoft Sway to host QR Code phishing campaigns.

What a coincidence. Spyware makers, Russia's Cozy Bear seem to share same exploits
2024-08-29 20:03

Google researchers note similarities, can't find smoking-gun link Google's Threat Analysis Group (TAG) has spotted an interesting pattern: A Kremlin-linked cyber-espionage crew and commercial...