Category: security

Chinese hackers target Windows servers with SEO poisoning campaign

Hackers are taking advantage of vulnerable servers to take over websites, and use them to steal people’s credentials, deploy malware, and more. A report from Cisco Talos, who have been tracking the activity for some time now, revealed the group would first seek out vulnerable web application services such as…

Read More

Kaspersky security tools hijacked to disable online protection systems

The infamous RansomHub ransomware group has been spotted abusing a legitimate Kaspersky tool to disable endpoint detection and response (EDR) tools and then deploy stage-two malware on infected systems without being seen. Cybersecurity researchers Malwarebytes, who recently spotted the activity in the wild, noted once RansomHub compromises an endpoint and…

Read More

Microsoft confesses its recent security updates…broke Windows 10 security patches

In its latest Patch Tuesday cumulative update, Microsoft has confirmed an embarassing bug which broke older security patches installed on Windows 10 devices. The bug is tracked as CVE-2024- 43491, and affects Windows 10 version 1507 – an older version still supported for Windows 10 Enterprise 2015 LTSB and Windows…

Read More

Ivanti patches serious endpoint management software security bugs, so update now

Ivanti has released a patch for a critical security vulnerability, advising users to apply it immediately to secure their infrastructure. In an advisory, Ivanti said it had uncovered a deserialization of untrusted data weakness in its Endpoint Management (EPM) agent portal. The vulnerability is tracked as CVE-2024-29847 and carries a…

Read More

Crypto fans beware — hundreds of Android apps found using OCR to steal login details

Cybersecurity researchers from McAfee have uncovered hundreds of malicious Android apps designed to steal access to people’s cryptocurrency wallets. The researchers dubbed the campaign SpyAgent, which was made up of 280 apps in total, so far, mimicking legitimate banking apps, government services tools, TV streaming, utilities apps, and more. The…

Read More

RAMBO attack uses RAM in air-gapped computers to steal data

Cybersecurity researchers from Ben-Gurion University of the Negev, Israel, came up with a very James Bond-esque way to steal sensitive files from air-gapped systems. The method is dubbed RAMBO (short for Radiation of Air-gapped Memory Bus for Offense) because it abuses the target computer’s RAM memory to steal data, taking…

Read More