Tag: security

Fortinet confirms data breach after allegedly refusing to pay ransom

Hackers recently broke into a cloud storage account belonging to cybsersecurity giant Fortinet, and stole sensitive information found there. The news was confirmed by the cybersecurity business itself, which played down the importance of the incident – however the hackers behind the attack beg to differ. In an announcement posted…

Read More

Adobe Acrobat Reader has a serious security flaw — so patch now

Adobe’s Acrobat Reader, the go-to PDF reader for many of us, is vulnerable to a flow that allows threat actors to remotely run malicious code on the target device. The vulnerability is described as a “user after free” flaw, and is tracked as CVE-2024-41896. A “use after free” flaw happens…

Read More

One small tweak gave researchers a powerful web domain ability that could prove incredibly useful for hackers

A cybersecurity researcher recently stumbled upon an Internet vulnerability allowing him to track people’s email, run code on servers, and even counterfeit HTTPS certificates – in fact, it gave him so many options, it has been described as having “superpowers”. The vulnerability is quite a simple one in nature –…

Read More

Chinese banking giant’s London HQ targeted by cybercriminals, threatening to leak millions of files

The London branch of the Industrial and Commercial Bank of China (ICBC) has suffered a ransomware attack that saw the hackers make off with plenty of sensitive data. A report from The Register, citing an announcement posted on the threat actor’s data leak site, says ICBC has until September 13…

Read More

Chinese hackers target Windows servers with SEO poisoning campaign

Hackers are taking advantage of vulnerable servers to take over websites, and use them to steal people’s credentials, deploy malware, and more. A report from Cisco Talos, who have been tracking the activity for some time now, revealed the group would first seek out vulnerable web application services such as…

Read More

Kaspersky security tools hijacked to disable online protection systems

The infamous RansomHub ransomware group has been spotted abusing a legitimate Kaspersky tool to disable endpoint detection and response (EDR) tools and then deploy stage-two malware on infected systems without being seen. Cybersecurity researchers Malwarebytes, who recently spotted the activity in the wild, noted once RansomHub compromises an endpoint and…

Read More