Security News

New critical Apache Struts flaw exploited to find vulnerable servers
2024-12-17 18:04

A recently patched critical Apache Struts 2 vulnerability tracked as CVE-2024-53677 is actively exploited using public proof-of-concept exploits to find vulnerable devices. [...]

Are your Prometheus servers and exporters secure? Probably not
2024-12-15 23:58

Plus: Netscaler brute force barrage; BeyondTrust API key stolen; and more Infosec in brief There's a problem of titanic proportions brewing for users of the Prometheus open source monitoring...

Europol Shuts Down Manson Market Fraud Marketplace, Seizes 50 Servers
2024-12-05 14:55

Europol on Thursday announced the shutdown of a clearnet marketplace called Manson Market that facilitated online fraud on a large scale. The operation, led by German authorities, has resulted in...

BT unit took servers offline after Black Basta ransomware breach
2024-12-04 18:37

Multinational telecommunications giant BT Group (formerly British Telecom) has confirmed that its BT Conferencing business division shut down some of its servers following a Black Basta ransomware...

Russia-Linked Turla Exploits Pakistani Hackers' Servers to Target Afghan and Indian Entities
2024-12-04 17:23

The Russia-linked advanced persistent threat (APT) group known as Turla has been linked to a previously undocumented campaign that involved infiltrating the command-and-control (C2) servers of a...

Russian hackers hijack Pakistani hackers' servers for their own attacks
2024-12-04 17:00

The notorious Russian cyber-espionage group Turla is hacking other hackers, hijacking the Pakistani threat actor Storm-0156's infrastructure to launch their own covert attacks on already...

Russian hackers hijack Pakistani hackers' servers for their own attacks
2024-12-04 17:00

The notorious Russian cyber-espionage group Turla is hacking other hackers, hijacking the Pakistani threat actor Storm-0156's infrastructure to launch their own covert attacks on already...

New Windows Server 2012 zero-day gets free, unofficial patches
2024-11-29 17:00

Free unofficial security patches have been released through the 0patch platform to address a zero-day vulnerability introduced over two years ago in the Windows Mark of the Web (MotW) security...

Hackers exploit ProjectSend flaw to backdoor exposed servers
2024-11-27 21:00

Threat actors are using public exploits for a critical authentication bypass flaw in ProjectSend to upload webshells and gain remote access to servers. [...]

Critical Flaw in ProjectSend Under Active Exploitation Against Public-Facing Servers
2024-11-27 16:05

A critical security flaw impacting the ProjectSend open-source file-sharing application has likely come under active exploitation in the wild, according to findings from VulnCheck. The...