Security News

Chinese-sponsored gang Gallium upgrades to sneaky PingPull RAT
2022-06-14 06:27

The Gallium group, believed to be a Chinese state-sponsored team, is going on the warpath with an upgraded remote access trojan that threat hunters say is difficult to detect. The backdoor, once in a compromised system, comes in three variants, each of which can communicate with the command-and-control system in one of three protocols: ICMP, HTTPS and raw TCP. All three PingPull variants have the same functionality, but each creates a custom string of code that it sends to the C2 server, which will use the unique string to identify the compromised system.

Future proofing: How companies can upgrade cyber defenses and be ready for tomorrow
2022-05-31 05:00

Today's threat landscape is constantly evolving. Threat actors and tactics are becoming more determined and advanced.

Tor project upgrades network speed performance with new system
2022-05-05 11:26

The Tor Project has published details about a newly introduced system called Congestion Control that promises to eliminate speed limits on the network. Congestion Control "Will result in significant performance improvements in Tor, as well as increased utilization of our network capacity," say the maintainers of the project.

Unofficial Windows 11 upgrade installs info-stealing malware
2022-04-18 17:18

Hackers are luring unsuspecting users with a fake Windows 11 upgrade that comes with malware that steals browser data and cryptocurrency wallets. The hackers are preying on users that jump at installing Windows 11 without spending the time to learn that the OS needs to meet certain specifications.

Microsoft fixes IE11 known issue blocking Windows 11 upgrades
2022-04-05 12:52

Microsoft has removed a compatibility hold blocking Windows 11 upgrades for Windows 10 customers after fixing a known issue leading to problems importing Internet Explorer 11 data into Microsoft Edge. The only customers impacted by the now-fixed known issue were those who didn't import their IE11 information into Microsoft Edge before starting the Windows 11 upgrade process.

Microsoft adds Windows 11 upgrade block due to IE11 known issue
2022-04-01 12:50

Microsoft has added a new safeguard hold blocking Windows 11 upgrades for Windows 10 customers who don't import their Internet Explorer 11 data into Microsoft Edge before trying to install the newest Windows version. "After upgrading to Windows 11, saved information and data from Internet Explorer 11 might not be accessible if you did not accept to import it into Microsoft Edge before the upgrade," Microsoft explained in the Windows health dashboard.

TrickBot Malware Gang Upgrades its AnchorDNS Backdoor to AnchorMail
2022-03-01 08:12

Even as the TrickBot infrastructure closed shop, the operators of the malware are continuing to refine and retool their arsenal to carry out attacks that culminated in the deployment of Conti ransomware. IBM Security X-Force, which discovered the revamped version of the criminal gang's AnchorDNS backdoor, dubbed the new, upgraded variant AnchorMail.

Fake Windows 11 upgrade installers infect you with RedLine malware
2022-02-09 12:58

Threat actors have started distributing fake Windows 11 upgrade installers to users of Windows 10, tricking them into downloading and executing RedLine stealer malware. The timing of the attacks coincides with the moment that Microsoft announced Windows 11's broad deployment phase, so the attackers were well-prepared for this move and waited for the right moment to maximize their operation's success.

TrickBot Crashes Security Researchers’ Browsers in Latest Upgrade
2022-01-26 22:39

Trojan titan TrickBot has added a striking anti-debugging feature that detects security analysis and crashes researcher browsers before its malicious code can be analyzed. The new anti-debugging feature was discovered by Security Intelligence analysts with IBM, who reported the emergence of a variety of TrickBot tactics aimed at making the job of security researcher more difficult, including server-side injection delivery and secure communications with the command-and-control server to keep code protected.

Apache OpenOffice users should upgrade to newest security release!
2021-10-12 11:01

The Apache Software Foundation has released Apache OpenOffice 4.1.11, which fixes a handful of security vulnerabilities, including CVE-2021-33035, a recently revealed RCE vulnerability that could be triggered via a specially crafted document. Apache OpenOffice is an open-source office productivity suite that includes a word processor, a spreadsheet tool, a presentation editor, a vector graphics drawing editor, a mathematical formula editor, and a database management program.