Security News

CISA warns of actively exploited Apache HugeGraph-Server bug
2024-09-19 22:53

The U.S. Cybersecurity and Infrastructure Agency (CISA) has added five flaws to its Known Exploited Vulnerabilities (KEV) catalog, among which is a remote code execution (RCE) flaw impacting...

New TeamTNT Cryptojacking Campaign Targets CentOS Servers with Rootkit
2024-09-19 13:27

The cryptojacking operation known as TeamTNT has likely resurfaced as part of a new campaign targeting Virtual Private Server (VPS) infrastructures based on the CentOS operating system. "The...

Russian security firm Dr.Web disconnects all servers after breach
2024-09-18 15:49

On Tuesday, Russian anti-malware company Doctor Web (Dr.Web) disclosed a security breach after its systems were targeted in a cyberattack over the weekend. [...]

Critical VMware vCenter Server bugs fixed (CVE-2024-38812)
2024-09-18 10:38

Broadcom has released fixes for two vulnerabilities affecting VMware vCenter Server that can be triggered by sending a specially crafted network packet, and could lead to remote code execution...

VMware patches remote make-me-root holes in vCenter Server, Cloud Foundation
2024-09-17 20:50

Bug reports made in China Broadcom has emitted a pair of patches for vulnerabilities in VMware vCenter Server that a miscreant with network access to the software could exploit to completely...

Broadcom fixes critical RCE bug in VMware vCenter Server
2024-09-17 19:57

Broadcom has fixed a critical VMware vCenter Server vulnerability that attackers can exploit to gain remote code execution on unpatched servers via a network packet. [...]

New Linux malware Hadooken targets Oracle WebLogic servers
2024-09-13 17:05

Hackers are targeting Oracle WebLogic servers to infect them with a new Linux malware named "Hadooken, which launches a cryptominer and a tool for distributed denial-of-service (DDoS) attacks. [...]

'Hadooken' Linux malware targets Oracle WebLogic servers
2024-09-13 00:31

Nastyware seeks creds, mines crypto, and plants ransomware that isnt deployed - for now? An unknown attacker is exploiting weak passwords to break into Oracle WebLogic servers and deploy an...

Exposed Selenium Grid Servers Targeted for Crypto Mining and Proxyjacking
2024-09-12 12:56

Internet-exposed Selenium Grid instances are being targeted by bad actors for illicit cryptocurrency mining and proxyjacking campaigns. "Selenium Grid is a server that facilitates running test...

DragonRank Black Hat SEO Campaign Targeting IIS Servers Across Asia and Europe
2024-09-11 15:39

A "simplified Chinese-speaking actor" has been linked to a new campaign that has targeted multiple countries in Asia and Europe with the end goal of performing search engine optimization (SEO)...