Security News

Raspberry Robin Malware Upgrades with Discord Spread and New Exploits
2024-02-09 16:32

The operators of Raspberry Robin are now using two new one-day exploits to achieve local privilege escalation, even as the malware continues to be refined and improved to make it stealthier than...

New RustDoor macOS malware impersonates Visual Studio update
2024-02-09 15:53

A new Rust-based macOS malware spreading as a Visual Studio update to provide backdoor access to compromised systems uses infrastructure linked to the infamous ALPHV/BlackCat ransomware gang. Written in Rust, the malware can run on Intel-based and ARM architectures, say researchers at cybersecurity company Bitdefender, who are tracking it as RustDoor.

Botnet Attack Targeted Routers: A Wake-Up Call for Securing Remote Employees’ Hardware
2024-02-09 15:44

State-sponsored hackers affiliated with China have targeted small office/home office routers in the U.S. in a wide-ranging botnet attack, Federal Bureau of Investigation Director Christopher Wray announced on Wednesday, Jan. 31. The investigators also cut the routers off from other devices used in the botnet.

Americans lost record $10 billion to fraud in 2023, FTC warns
2024-02-09 15:21

The U.S. Federal Trade Commission says Americans lost over $10 billion to scammers in 2023, marking a 14% increase in reported losses compared to the previous year. Imposter scams emerged as the most frequently reported fraud category, with notable upticks in business and government impersonation reports.

Fortinet's week to forget: Critical vulns, disclosure screw-ups, and that toothbrush DDoS attack claim
2024-02-09 14:30

The only workaround recommended by Fortinet is to disable the SSL VPN. Disabling webmode won't mitigate the vulnerability, it said. Firstly, Fortinet backtracked and said these weren't vulnerabilities at all, instead explaining that they were issued in error and were duplicates of the single vulnerability mentioned in the aforementioned October advisory - CVE-2023-34992.

The ever-present state of cyber security alert
2024-02-09 14:09

Webinar As artificial intelligence technology becomes increasingly complex so do the threats from bad actors. Half the time too, we barely know that we're using AI, largely because it's getting progressively cheaper and easier for organisations to introduce, train, validate and deploy AI models and applications.

MoqHao Android Malware Evolves with Auto-Execution Capability
2024-02-09 13:34

Threat hunters have identified a new variant of Android malware called MoqHao that automatically executes on infected devices without requiring any user interaction. "Typical MoqHao requires users...

AI-generated voices in robocalls now illegal
2024-02-09 12:24

"Bad actors are using AI-generated voices in unsolicited robocalls to extort vulnerable family members, imitate celebrities, and misinform voters. We're putting the fraudsters behind these robocalls on notice," said FCC Chairwoman Jessica Rosenworcel.While currently, State Attorneys Generals can target the outcome of an unwanted AI-voice generated robocall-such as the scam or fraud they are seeking to perpetrate-this action now makes the act of using AI to generate the voice in these robocalls itself illegal, expanding the legal avenues through which state law enforcement agencies can hold these perpetrators accountable under the law.

Hands-on Review: Myrror Security Code-Aware and Attack-Aware SCA
2024-02-09 10:58

Introduction The modern software supply chain represents an ever-evolving threat landscape, with each package added to the manifest introducing new attack vectors. To meet industry requirements,...

New Coyote Trojan Targets 61 Brazilian Banks with Nim-Powered Attack
2024-02-09 10:28

Sixty-one banking institutions, all of them originating from Brazil, are the target of a new banking trojan called Coyote. "This malware utilizes the Squirrel installer for distribution,...