What's new arround internet

Last one

Src Date (GMT) Titre Description Tags Stories Notes
bleepingcomputer.webp 2022-05-19 13:24:57 U.S. DOJ will no longer prosecute ethical hackers under CFAA (lien direct) The U.S. Department of Justice (DOJ) has announced a revision of its policy on how federal prosecutors should charge violations of the Computer Fraud and Abuse Act (CFAA), carving out "good-fath" security research from being prosecuted. [...] ★★★★
bleepingcomputer.webp 2022-05-19 11:24:04 Lazarus hackers target VMware servers with Log4Shell exploits (lien direct) The North Korean hacking group known as Lazarus is exploiting the Log4J remote code execution vulnerability to inject backdoors that fetch information-stealing payloads on VMware Horizon servers. [...] Vulnerability APT 38
bleepingcomputer.webp 2022-05-19 09:00:00 Phishing websites now use chatbots to steal your credentials (lien direct) Threat analysts have observed a new trend in the phishing space which is to incorporate interactive chatbots on sites that guide visitors through the process of losing their sensitive data. [...] Threat ★★★
bleepingcomputer.webp 2022-05-19 07:39:11 Microsoft Teams, Windows 11 hacked on first day of Pwn2Own (lien direct) During the first day of Pwn2Own Vancouver 2022, contestants won $800,000 after successfully exploiting 16 zero-day bugs to hack multiple products, including Microsoft's Windows 11 operating system and the Teams communication platform. [...]
bleepingcomputer.webp 2022-05-19 06:38:26 QNAP alerts NAS customers of new DeadBolt ransomware attacks (lien direct) Taiwan-based network-attached storage (NAS) maker QNAP warned customers on Thursday to secure their devices against attacks pushing DeadBolt ransomware payloads. [...] Ransomware
bleepingcomputer.webp 2022-05-19 05:36:56 Ransomware gangs rely more on weaponizing vulnerabilities (lien direct) Security researchers are warning that external remote access services continue to be the main vector for ransomware gangs to breach company networks. [...] Ransomware
bleepingcomputer.webp 2022-05-18 18:27:02 Microsoft releases first ISO image for new Windows 11 Dev builds (lien direct) Microsoft has released the first ISO image for the new Windows 11 Preview builds in the Dev channel, allowing Windows Insiders to perform clean installs of the operating system. [...]
bleepingcomputer.webp 2022-05-18 17:36:18 Spanish police dismantle phishing gang that emptied bank accounts (lien direct) The Spanish police have announced the arrest of 13 people and the launch of investigations on another 7 for their participation in a phishing ring that defrauded at least 146 people. [...]
bleepingcomputer.webp 2022-05-18 17:12:57 Critical Jupiter WordPress plugin flaws let hackers take over sites (lien direct) WordPress security analysts have discovered a set of vulnerabilities impacting the Jupiter Theme and JupiterX Core plugins for WordPress, one of which is a critical privilege escalation flaw. [...]
bleepingcomputer.webp 2022-05-18 16:13:12 National bank hit by ransomware trolls hackers with dick pics (lien direct) After suffering a ransomware attack by the Hive operation, the Bank of Zambia made it clear that they were not going to pay by posting a picture of male genitalia and telling the hackers to s… (well, you can use your imagination). [...] Ransomware
bleepingcomputer.webp 2022-05-18 14:37:51 US recovers $15 million from global Kovter ad fraud operation (lien direct) The US government has recovered over $15 million from Swiss bank accounts belonging to operators behind the '3ve' online advertising fraud scheme. [...]
bleepingcomputer.webp 2022-05-18 13:38:57 DHS orders federal agencies to patch VMware bugs within 5 days (lien direct) The Department of Homeland Security's cybersecurity unit ordered Federal Civilian Executive Branch (FCEB) agencies today to urgently update or remove VMware products from their networks by Monday due to an increased risk of attacks. [...]
bleepingcomputer.webp 2022-05-18 12:01:42 VMware patches critical auth bypass flaw in multiple products (lien direct) VMware warned customers today to immediately patch a critical authentication bypass vulnerability "affecting local domain users" in multiple products that can be exploited to obtain admin privileges. [...] Vulnerability
bleepingcomputer.webp 2022-05-18 11:20:56 CISA shares guidance to block ongoing F5 BIG-IP attacks (lien direct) In a joint advisory issued today, CISA and the Multi-State Information Sharing and Analysis Center (MS-ISAC) warned admins of active attacks targeting a critical F5 BIG-IP network security vulnerability (CVE-2022-1388). [...] Vulnerability
bleepingcomputer.webp 2022-05-18 10:54:14 Fake crypto sites lure wannabe thieves by spamming login credentials (lien direct) Threat actors are luring potential thieves by spamming login credentials for other people account's on fake crypto trading sites, illustrating once again, that there is no honor among thieves. [...] Threat
bleepingcomputer.webp 2022-05-18 09:27:23 Microsoft warns of brute-force attacks targeting MSSQL servers (lien direct) Microsoft warned of brute-forcing attacks targeting Internet-exposed and poorly secured Microsoft SQL Server (MSSQL) database servers using weak passwords. [...]
bleepingcomputer.webp 2022-05-17 18:16:00 (Déjà vu) North Korean devs pose as US freelancers to aid DRPK govt hackers (lien direct) The U.S. government is warning that the Democratic People's Republic of Korea (DPRK) is dispatching its IT workers to get freelance jobs at companies across the world to obtain privileged access that is sometimes used to facilitate cyber intrusions. [...]
bleepingcomputer.webp 2022-05-17 18:16:00 North Korean devs pose as US freelancers and aid DRPK govt hackers (lien direct) The U.S. government is warning that the Democratic People's Republic of Korea (DPRK) is dispatching its IT workers to get freelance jobs at companies across the world to obtain privileged access that is sometimes used to facilitate cyber intrusions. [...]
bleepingcomputer.webp 2022-05-17 16:22:43 Microsoft: Windows Server 20H2 reaches end of service in August (lien direct) Microsoft has reminded customers today that Windows Server, version 20H2 will be reaching the end of service (EOS) on August 9, 2022. [...]
bleepingcomputer.webp 2022-05-17 15:12:06 NVIDIA fixes ten vulnerabilities in Windows GPU display drivers (lien direct) NVIDIA has released a security update for a wide range of graphics card models, addressing four high-severity and six medium-severity vulnerabilities in its GPU drivers. [...]
bleepingcomputer.webp 2022-05-17 14:47:48 Microsoft Defender for Endpoint gets new troubleshooting mode (lien direct) Microsoft says Defender for Endpoint now comes with a new 'troubleshooting mode' that will help Windows admins test Defender Antivirus performance and run compatibility scenarios without getting blocked by tamper protection. [...]
bleepingcomputer.webp 2022-05-17 11:33:32 Cybersecurity agencies reveal top initial access attack vectors (lien direct) A joint security advisory issued by multiple national cybersecurity authorities revealed today the top 10 attack vectors most exploited by threat actors for breaching networks. [...] Threat
bleepingcomputer.webp 2022-05-17 10:30:19 Hackers can steal your Tesla Model 3, Y using new Bluetooth attack (lien direct) Security researchers at the NCC Group have developed a tool to carry out a Bluetooth Low Energy (BLE) relay attack that bypasses all existing protections to authenticate on target devices. [...] Tool
bleepingcomputer.webp 2022-05-17 10:01:02 What is ISO 27001 and Why it Matters for Compliance Standards (lien direct) ISO 27001 may seem like a big undertaking, but the certification can pay off in more ways than one-including overlap with compliance regulations. Read about the benefits of ISO 27001 and how to get started. [...]
bleepingcomputer.webp 2022-05-17 08:00:00 (Déjà vu) CISA warns admins to patch actively exploited Spring, Zyxel bugs (lien direct) The Cybersecurity and Infrastructure Security Agency (CISA) has added two more vulnerabilities to its list of actively exploited bugs, a code injection bug in the Spring Cloud Gateway library and a command injection flaw in Zyxel firmware for business firewalls and VPN devices. [...]
bleepingcomputer.webp 2022-05-17 08:00:00 CISA warns admins to patch actively exploited VMware, Zyxel bugs (lien direct) The Cybersecurity and Infrastructure Security Agency (CISA) has added two more vulnerabilities to its list of actively exploited bugs, a code injection bug in the Spring Cloud Gateway library and a command injection flaw in Zyxel firmware for business firewalls and VPN devices. [...]
bleepingcomputer.webp 2022-05-17 07:16:46 Hackers target Tatsu WordPress plugin in millions of attacks (lien direct) Hackers are massively exploiting a remote code execution vulnerability, CVE-2021-25094, in the Tatsu Builder plugin for WordPress, which is installed on about 100,000 websites. [...]
bleepingcomputer.webp 2022-05-16 18:32:04 HTML attachments remain popular among phishing actors in 2022 (lien direct) HTML files remain one of the most popular attachments used in phishing attacks for the first four months of 2022, showing that the technique remains effective against antispam engines and works well on the victims themselves. [...]
bleepingcomputer.webp 2022-05-16 17:15:41 Third-party web trackers log what you type before submitting (lien direct) An extensive study looking into the top 100k ranking websites has revealed that many are leaking information you enter in the site forms to third-party trackers before you even press submit. [...]
bleepingcomputer.webp 2022-05-16 16:46:50 US links Thanos and Jigsaw ransomware to 55-year-old doctor (lien direct) The US Department of Justice today said that Moises Luis Zagala Gonzalez (Zagala), a 55-year-old cardiologist with French and Venezuelan citizenship residing in Ciudad Bolivar, Venezuela, created and rented Jigsaw and Thanos ransomware to cybercriminals. [...] Ransomware
bleepingcomputer.webp 2022-05-16 14:33:32 Apple emergency update fixes zero-day used to hack Macs, Watches (lien direct) Apple has released security updates to address a zero-day vulnerability that threat actors can exploit in attacks targeting Macs and Apple Watch devices. [...] Hack Vulnerability Threat
bleepingcomputer.webp 2022-05-16 14:05:30 Ukraine supporters in Germany targeted with PowerShell RAT malware (lien direct) An unknown threat actor is targeting German users interested in the Ukraine crisis, infecting them with a custom PowerShell RAT (remote access trojan) and stealing their data. [...] Malware Threat
bleepingcomputer.webp 2022-05-16 13:24:38 CISA warns not to install May Windows updates on domain controllers (lien direct) The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has removed a Windows security flaw from its catalog of known exploited vulnerabilities due to Active Directory (AD) authentication issues caused by the May 2022 updates that patch it. [...]
bleepingcomputer.webp 2022-05-16 12:35:18 Kali Linux 2022.2 released with 10 new tools, WSL improvements, and more (lien direct) Offensive Security has released ​Kali Linux 2022.2, the second version in 2022, with desktop enhancements, a fun April Fools screensaver, WSL GUI improvements, terminal tweaks, and best of all, new tools to play with! [...] ★★★★
bleepingcomputer.webp 2022-05-16 11:43:07 Sophos antivirus driver caused BSODs after Windows KB5013943 update (lien direct) Sophos has released a fix for a known issue triggering blue screens of death (aka BSODs) on Windows 11 systems running Sophos Home antivirus software after installing the KB5013943 upda [...]
bleepingcomputer.webp 2022-05-16 10:17:58 Engineering firm Parker discloses data breach after ransomware attack (lien direct) The Parker-Hannifin Corporation announced a data breach exposing employees' personal information after the Conti ransomware gang began publishing allegedly stolen data last month. [...] Ransomware Data Breach
bleepingcomputer.webp 2022-05-15 18:15:20 What\'s new and improved in Windows 11 22H2, coming soon (lien direct) Windows 11 version 22H2 aka Sun Valley 2 is set to launch later this year. Unlike the original Windows 11 release, it won't be a massive update with radical design changes. Instead, Sun Valley 2 will be similar to Windows 10 Anniversary Update, so you can expect minor improvements and a few new features. [...]
bleepingcomputer.webp 2022-05-15 14:47:10 Hackers are exploiting critical bug in Zyxel firewalls and VPNs (lien direct) Hackers have started to exploit a recently patched critical vulnerability, tracked as CVE-2022-30525, that affects Zyxel firewall and VPN devices for businesses. [...]
bleepingcomputer.webp 2022-05-15 12:34:09 Fake Pixelmon NFT site infects you with password-stealing malware (lien direct) A fake Pixelmon NFT site entices fans with free tokens and collectibles while infecting them with malware that steals their cryptocurrency wallets. [...] Malware
bleepingcomputer.webp 2022-05-15 10:00:00 Windows admins frustrated by Quick Assist moving to Microsoft Store (lien direct) Windows admins have been expressing their dismay at Microsoft's decision to move the Quick Assist remote assistance tool to the Microsoft Store. [...] Tool
bleepingcomputer.webp 2022-05-14 15:39:02 (Déjà vu) Microsoft fixes new PetitPotam Windows NTLM Relay attack vector (lien direct) A recent security update for a Windows NTLM Relay Attack has been confirmed to be a previously unfixed vector for the PetitPotam attack. [...]
bleepingcomputer.webp 2022-05-14 15:39:02 New Windows PetitPotam NTLM Relay attack vector fixed in May updates (lien direct) A recent security update for a Windows NTLM Relay Attack has been confirmed to be a previously unfixed vector for the PetitPotam attack. [...]
bleepingcomputer.webp 2022-05-14 11:18:09 Angry IT admin wipes employer\'s databases, gets 7 years in prison (lien direct) Han Bing, a former database administrator for Lianjia, a Chinese real-estate brokerage giant, has been sentenced to 7 years in prison for logging into corporate systems and deleting the company's data. [...]
bleepingcomputer.webp 2022-05-14 10:02:27 (Déjà vu) Crypto robber who lured victims via Snapchat and stole £34,000 jailed (lien direct) Online crypto scams and ponzi schemes leveraging social media platforms are hardly anything new. But, this gruesome case of a London-based crypto robber transcends the virtual realm and tells a shocking tale of real-life victims from whom the perpetrator successfully stole £34,000. [...]
bleepingcomputer.webp 2022-05-14 10:02:27 Crypto thief threatened to cut man\'s fingers \'one by one,\' stole £34K (lien direct) Online crypto scams and ponzi schemes leveraging social media platforms are hardly anything new. But, this gruesome case of a London-based crypto robber transcends the virtual realm and tells a shocking tale of real-life victims from whom the perpetrator successfully stole £34,000. [...]
bleepingcomputer.webp 2022-05-13 16:58:23 The Week in Ransomware - May 13th 2022 - A National Emergency (lien direct) While ransomware attacks have slowed during Russia's invasion of Ukraine and the subsequent sanctions, the malware threat continues to affect organizations worldwide. [...] Ransomware Malware Threat
bleepingcomputer.webp 2022-05-13 14:16:08 Italian CERT: Hacktivists hit govt sites in \'Slow HTTP\' DDoS attacks (lien direct) Italy's Computer Security Incident Response Team (CSIRT) has published an announcement about the recent DDoS attacks that key sites in the country suffered in the last couple of days. [...]
bleepingcomputer.webp 2022-05-13 13:48:24 Microsoft: Sysrv botnet targets Windows, Linux servers with new exploits (lien direct) Microsoft says the Sysrv botnet is now exploiting vulnerabilities in the Spring Framework and WordPress to ensnare and deploy cryptomining malware on vulnerable Windows and Linux servers. [...] Malware
bleepingcomputer.webp 2022-05-13 12:24:40 Fake Binance NFT Mystery Box bots steal victim\'s crypto wallets (lien direct) A new RedLine malware distribution campaign promotes fake Binance NFT mystery box bots on YouTube to lure people into infecting themselves with the information-stealing malware from GitHub repositories. [...] Malware
bleepingcomputer.webp 2022-05-13 11:38:42 SonicWall \'strongly urges\' admins to patch SSLVPN SMA1000 bugs (lien direct) SonicWall "strongly urges" customers to patch several high-risk security flaws impacting its Secure Mobile Access (SMA) 1000 Series line of products that can let attackers bypass authorization and, potentially, compromise unpatched appliances. [...]
Last update at: 2024-06-25 22:07:42
See our sources.
My email:

To see everything: RSS Twitter