Tag: security

This new Android malware can steal your card details via the NFC chip

Cybercriminals have reportedly found a way to steal from smartphone users by exfiltrating the data read by their device’s near-field communications (NFC) chip. The scam was revealed by cybersecurity researchers at ESET, who said it includes progressive web apps (PWA), advanced WebAPKs, and significant social engineering in a multi-step approach…

Read More

SolarWinds left some serious security flaws in its Web Desk Help platform, and now it’s under attack

Security researchers have uncovered a critical-severity vulnerability in one of SolarWinds’ most popular software products. SolarWinds’ Web Help Desk is a web-based IT service management software that streamlines and automates help desk ticketing, asset management, and IT service management processes. It offers features like ticketing, incident and problem management, and…

Read More

Watch out — Google Chrome details can be stolen by this clever new ransomware

The Qilin ransomware variant has been spotted successfully exfiltrating sensitive data stored in the Google Chrome browser. In its writeup, researchers from Sophos revealed how a criminal group used previously compromised credentials to enter the IT infrastructure of an unnamed organization. The credentials were for a Virtual Private Network (VPN)…

Read More

Microsoft patches critical security bug in Copilot Studio that could have leaked private data

Microsoft Copilot Studio had a security issues which could have allowed threat actors to exfiltrate sensitive data from vulnerable endpoints, experts have warned. Cybersecurity researcher Evan Grant from Tenable, who found and reported on the vulnerability, which is described as an information disclosure flaw stemming from a server-side request forgery…

Read More

Slack AI could be tricked into leaking login details and more

Security researchers claim to have uncovered a way to trick Slack’s AI assistant into sharing sensitive information and other secrets with unauthorized users Slack, which is used by more than 35 million people worldwide, introduced its own Artificial Intelligence (AI) tool in September 2023, allowing users to summarize multiple unread…

Read More

GitHub Enterprise Server has a critical security flaw, so patch now

GitHub Enterprise Server, the self-hosted version of the GitHub platform, was found carrying a vulnerability that allowed malicious actors to elevate their privileges to admin. The vulnerability, tracked as CVE-2024-6800, and has a severity rating of 9.5/10 (critical), is described as an XML signature wrapping issue. It happens when the…

Read More