Tag: security

Monday.com removes feature after it was abused in phishing attacks

Popular project management and collaboration tool Monday.com was forced to disable one of its features after it was abused by a threat actor to send out phishing emails. The “Share Update” feature allows users to share real-time updates, progress, or important information with team members, or stakeholders. Users can post…

Read More

Nearly a million victims hit by massive BogusBazaar campaign — credit card details stolen, but here’s how to stay safe

Almost a million people around the world have fallen victim to a highly organized fraud campaign, which scammed them out of some $50 million in the past couple of years. According to a report from SRLabs, a group of cyber-criminals, supported by a wider network of affiliates, were organized into…

Read More

Boeing says it refused to pay massive ransomware demand

Boeing has revealed it refused to pay a $200 million ransom demand from ransomware hackers who stole a tranche of sensitive data in 2023. The US Department of Justice recently unsealed an indictment against one Dmitry Yuryevich Khoroshev, who is being accused of being the one to develop and maintain…

Read More

Security flaws in BIG-IP system could have put entire networks at risk

BIG-IP Next Central Manager (NCM), a centralized management and orchestration platform for F5’s BIG-IP product family, was vulnerable to two major flaws which allowed malicious actors to take over its managed assets. The bugs, which have since been patched, are described as an SQL injection vulnerability, and an OData injection…

Read More

AI surveillance is on the horizon, but Mullvad VPN might have a fix

The security gap between our expectations and the harsh digital reality is deepening as AI-powered tools enable internet service providers (ISPs), authorities, and even data brokers to trace back our online activities despite being encrypted. That’s why one of the best VPN services on the market, Mullvad VPN, just dropped…

Read More

Watch out — hackers can exploit this plugin to gain full control of your WordPress site

An older version of LiteSpeed Cache, a popular plugin for the WordPress website builder, is vulnerable to a high-severity flaw that hackers have been increasingly exploiting. The flaw is described as an unauthenticated cross-site scripting vulnerability, and tracked as CVE-2023-40000. It carries a severity score of 8.8.  By adding malicious…

Read More