Tag: security

Spoof Eventbrite phishing emails look to lure in victims in major attack

Cybercriminals are increasingly abusing Eventbrite to run successful phishing campaigns, experts have warned. A report from cybersecurity researchers Perception Point claims to have observed a 900% growth in the rate of such email attacks recently. The method is quite simple – a malicious actor will register an account with Eventbrite,…

Read More

Thousands of CyberPanel instances taken offline in massive ransomware attack

Cybercriminals have taken advantage of multiple vulnerabilities in CyberPanel to install ransomware and force tens of thousands of instances offline. Victims might be in luck though, since a decryption key appears to be available. A cybersecurity researcher alias DreyAnd has announced finding three major vulnerabilities in CyberPanel 2.3.6, and possibly…

Read More

Google Chrome cookie encryption system can be easily bypassed, experts warn

The cookie encryption system that Google introduced to the Chrome browser a few months ago can easily be bypassed, experts have warned. In fact, a security researcher has recently published a new tool that does just that. In July 2024, Google released Chrome 127, a new version of the Chrome…

Read More

Nvidia GPU owners told to update now to patch a range of serious security flaws

Nvidia has released a new patch for its GPU Display Driver for Windows and Linux to fix a handful of rather serious vulnerabilities. If exploited, the vulnerabilities mostly lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering, which means they are rather serious. Among…

Read More

Wi-Fi Alliance test suite has a worrying security flaw

Wi-Fi Test Suite carries a vulnerability that allows for elevation of privilege and remote code execution (RCE) attacks – and since there is no patch, and no word if there ever will be a patch, users are advised to replace the affected endpoints, or at least stop using them until…

Read More

Windows kernel components can be installed to bypass defense systems

Experts have uncovered a method allowing cybercriminals to bypass Windows security features such as Driver Signature Enforcement (DSE), and thus install rootkits on fully updated systems. A report from cybersecurity researcher Alon Leviev of SafeBreach claims the attack is possible by downgrading certain Windows kernel components. By taking over the…

Read More