Security News

MyOpenVDP: Open-source web application to securely disclose vulnerabilities
2022-10-26 03:15

MyOpenVDP is a turnkey open-source solution allowing anyone to host their own vulnerability disclosure policy. Developed by YesWeHack, the web application is available on GitHub.

Oops, web trackers may have leaked 3 million patients' info
2022-10-20 23:42

A hospital network in Wisconsin and Illinois fears visitor tracking code on its websites may have transmitted personal information on as many as 3 million patients to Meta, Google, and other third parties. Advocate Aurora Health reported the potential breach to the US government's Health and Human Services.

Product showcase: ImmuniWeb Discovery – attack surface management with dark web monitoring
2022-10-20 04:15

The underlying concept is simple and efficient: combining Attack Surface Management with dark web monitoring to boost their synergized value, making the "1+1=3" formula possible. Importantly, every single IT asset will be mapped onto the cyber threat landscape, visualizing the ongoing phishing campaigns targeting your customers or employees, dark web announcements selling access to your compromised systems or corporate data, rogue mobile applications usurping your corporate identity, stolen credentials from your applications or third-party systems processing your data, and IoCs found on your systems.

Windows Mark of the Web bypass zero-day gets unofficial patch
2022-10-17 18:14

A free unofficial patch has been released through the 0patch platform to address an actively exploited zero-day flaw in the Windows Mark of the Web security mechanism. Windows automatically adds MotW flags to all documents and executables downloaded from untrusted sources, including files extracted from downloaded ZIP archives, using a special 'Zone.Id' alternate data stream.

Web browser app mode can be abused to make desktop phishing pages
2022-10-03 16:35

A new phishing technique using Chrome's Application Mode feature allows threat actors to display local login forms that appear as desktop applications, making it easier to steal credentials. Because desktop applications are generally harder to spoof, users are less likely to treat them with the same caution they reserve for browser windows that are more widely abused for phishing.

Ex-eBay execs jailed for cyberstalking web critics
2022-09-30 00:58

Two now-former eBay executives who pleaded guilty to cyberstalking charges this year have been sent down and fined tens of thousands of dollars. James Baugh, ex-senior director of safety and security at the internet tat bazaar, was sentenced to nearly five years - 57 months - behind bars, plus two years of supervised release and fined $40,000 for harassing, both electronically and physically, Ina and David Steiner, who produce EcommerceBytes, a website and newsletter critical of eBay.

The web's cruising at 13 million new and nefarious domain names a month
2022-09-28 20:20

Akamai reckons that, in the first half of 2022 alone, it flagged nearly 79 million newly observed domains as malicious. According to the internet infrastructure giant, that amounts to 13 million malicious domain detections per month, equal to 20 percent of all successfully resolving NODs.

Want to sneak a RAT into Windows? Buy Quantum Builder on the dark web
2022-09-28 17:00

Quantum Builder lets attackers to create malicious Microsoft Windows LNK shortcuts. Quantum Builder has been linked to the advanced persistent threat gang Lazarus Group, based on shared tactics, techniques, and procedures and overlaps in source code, but they can't with any confidence attribute the current campaign to Lazarus or any particular threat group.

Cyber Criminals Using Quantum Builder Sold on Dark Web to Deliver Agent Tesla Malware
2022-09-28 12:36

A recently discovered malware builder called Quantum Builder is being used to deliver the Agent Tesla remote access trojan. Sold on the dark web for €189 a month, Quantum Builder is a customizable tool for generating malicious shortcut files as well as HTA, ISO, and PowerShell payloads to deliver next-stage malware on the targeted machines, in this case Agent Tesla.

Google, Microsoft can get your passwords via web browser's spellcheck
2022-09-17 18:39

Extended spellcheck features in Google Chrome and Microsoft Edge web browsers transmit form data, including personally identifiable information and in some cases, passwords, to Google and Microsoft respectively. In cases where Chrome Enhanced Spellcheck or Edge's Microsoft Editor were enabled, "Basically anything" entered in form fields of these browsers was transmitted to Google and Microsoft.