Security News

Microsoft September 2024 Patch Tuesday fixes 4 zero-days, 79 flaws
2024-09-10 17:32

Today is Microsoft's September 2024 Patch Tuesday, which includes security updates for 79 flaws, including four actively exploited and one publicly disclosed zero-days. [...]

New Chrome Zero-Day
2024-09-10 11:04

According to Microsoft researchers, North Korean hackers have been using a Chrome zero-day exploit to steal cryptocurrency.

North Korean Hackers Deploy FudModule Rootkit via Chrome Zero-Day Exploit
2024-08-31 15:35

A recently patched security flaw in Google Chrome and other Chromium web browsers was exploited as a zero-day by North Korean actors in a campaign designed to deliver the FudModule rootkit. The...

North Korean hackers exploit Chrome zero-day to deploy rootkit
2024-08-30 17:04

North Korean hackers have exploited a recently patched Google Chrome zero-day (CVE-2024-7971) to deploy the FudModule rootkit after gaining SYSTEM privileges using a Windows Kernel exploit. [...]

Malware exploits 5-year-old zero-day to infect end-of-life IP cameras
2024-08-29 15:46

The Corona Mirai-based malware botnet is spreading through a 5-year-old remote code execution (RCE) zero-day in AVTECH IP cameras, which have been discontinued for years and will not receive a patch. [...]

Volt Typhoon Hackers Exploit Zero-Day Vulnerability in Versa Director Servers Used by MSPs, ISPs
2024-08-29 15:17

There are approximately 163 devices worldwide that are still exposed to attack via the CVE-2024-39717 vulnerability.

South Korean hackers exploited WPS Office zero-day to deploy malware
2024-08-28 22:50

The South Korea-aligned cyberespionage group APT-C-60 has been leveraging a zero-day code execution vulnerability in the Windows version of WPS Office to install the SpyGlace backdoor on East...

Versa Director zero-day exploited to compromise ISPs, MSPs (CVE-2024-39717)
2024-08-27 15:47

Advanced, persistent attackers have exploited a zero-day vulnerability (CVE-2024-39717) in Versa Director to compromise US-based managed service providers with a custom-made web shell dubbed...

Chinese Volt Typhoon hackers exploited Versa zero-day to breach ISPs, MSPs
2024-08-27 14:00

The Chinese state-backed hacking group Volt Typhoon is behind attacks that exploited a zero-day flaw in Versa Director to upload a custom webshell to steal credentials and breach corporate networks. [...]

Google tags a tenth Chrome zero-day as exploited this year
2024-08-26 21:58

Today, Google revealed that it patched the tenth zero-day exploited in the wild in 2024 by attackers or security researchers during hacking contests. [...]