Security News

'Dead simple' hijacking hole in Apache Tomcat 'now actively exploited in the wild'
2025-03-18 00:44

One PUT request, one poisoned session file, and the server’s yours A trivial flaw in Apache Tomcat that allows remote code execution and access to sensitive files is said to be under attack in the...

New MassJacker Malware Targets Piracy Users, Hijacking Cryptocurrency Transactions
2025-03-14 06:08

Users searching for pirated software are the target of a new malware campaign that delivers a previously undocumented clipper malware called MassJacker, according to findings from CyberArk....

Fake Google Chrome Sites Distribute ValleyRAT Malware via DLL Hijacking
2025-02-06 14:34

Bogus websites advertising Google Chrome have been used to distribute malicious installers for a remote access trojan called ValleyRAT. The malware, first detected in 2023, is attributed to a...

OAuth Redirect Flaw in Airline Travel Integration Exposes Millions to Account Hijacking
2025-01-28 14:02

Cybersecurity researchers have disclosed details of a now-patched account takeover vulnerability affecting a popular online travel service for hotel and car rentals. "By exploiting this flaw,...

Hackers use Windows RID hijacking to create hidden admin account
2025-01-24 17:25

A North Korean threat group has been using a technique called RID hijacking that tricks Windows into treating a low-privileged account as one with administrator permissions. [...]

Researchers Uncover PyPI Packages Stealing Keystrokes and Hijacking Social Accounts
2024-12-24 13:22

Cybersecurity researchers have flagged two malicious packages that were uploaded to the Python Package Index (PyPI) repository and came fitted with capabilities to exfiltrate sensitive information...

Increasing Awareness of DNS Hijacking: A Growing Cyber Threat
2024-11-06 21:56

Read more about DNS hijacking and how organizations can prevent it.

700K+ DrayTek routers are sitting ducks on the internet, open to remote hijacking
2024-10-02 21:33

With 14 serious security flaws found, what a gift for spies and crooks Fourteen bugs in DrayTek routers — including one critical remote-code-execution flaw that received a perfect 10 out of 10...

Session Hijacking 2.0 — The Latest Way That Attackers are Bypassing MFA
2024-09-30 11:20

Attackers are increasingly turning to session hijacking to get around widespread MFA adoption. The data supports this, as: 147,000 token replay attacks were detected by Microsoft in 2023, a 111%...

That doomsday critical Linux bug: It's CUPS. May lead to remote hijacking of devices
2024-09-26 17:34

No patches yet, can be mitigated, requires user interaction Final update After days of anticipation, what was billed as one or more critical unauthenticated remote-code execution vulnerabilities...