Pandemic year increases bug bounties and report submissions
Vulnerability submissions have increased over the past 12 months on at least one crowdsourced security platform, with critical issue reports recording a 65% jump. [...]
https://www.bleepingcomputer.com/news/security/pandemic-year-increases-bug-bounties-and-report-submissions/
Vulnerability submissions have increased over the past 12 months on at least one crowdsourced security platform, with critical issue reports recording a 65% jump. [...]
https://www.bleepingcomputer.com/news/security/pandemic-year-increases-bug-bounties-and-report-submissions/
BleepingComputer
Pandemic year increases bug bounties and report submissions
Vulnerability submissions have increased over the past 12 months on at least one crowdsourced security platform, with critical issue reports recording a 65% jump.
Google outage caused by critical system running out of storage
Google's global outage from yesterday was due to a bug that restricted storage space to the Identity Management System and caused the system to fail. [...]
https://www.bleepingcomputer.com/news/google/google-outage-caused-by-critical-system-running-out-of-storage/
Google's global outage from yesterday was due to a bug that restricted storage space to the Identity Management System and caused the system to fail. [...]
https://www.bleepingcomputer.com/news/google/google-outage-caused-by-critical-system-running-out-of-storage/
BleepingComputer
Google outage caused by critical system running out of storage
Google's global outage from yesterday was due to a bug that restricted storage space to the Identity Management System and caused the system to fail.
Microsoft 365 gets native app support on Apple Silicon Macs
Microsoft has started rolling out new Universal versions of Microsoft 365 apps with native support for both Apple Silicon and Intel-based Macs starting today. [...]
https://www.bleepingcomputer.com/news/microsoft/microsoft-365-gets-native-app-support-on-apple-silicon-macs/
Microsoft has started rolling out new Universal versions of Microsoft 365 apps with native support for both Apple Silicon and Intel-based Macs starting today. [...]
https://www.bleepingcomputer.com/news/microsoft/microsoft-365-gets-native-app-support-on-apple-silicon-macs/
BleepingComputer
Microsoft 365 gets native app support on Apple Silicon Macs
Microsoft has started rolling out new Universal versions of Microsoft 365 apps with native support for both Apple Silicon and Intel-based Macs starting today.
New Windows malware may soon target Linux, macOS devices
Newly discovered Windows info-stealing malware linked to an active threat group tracked as AridViper shows signs that it might be used to infect computers running Linux and macOS. [...]
https://www.bleepingcomputer.com/news/security/new-windows-malware-may-soon-target-linux-macos-devices/
Newly discovered Windows info-stealing malware linked to an active threat group tracked as AridViper shows signs that it might be used to infect computers running Linux and macOS. [...]
https://www.bleepingcomputer.com/news/security/new-windows-malware-may-soon-target-linux-macos-devices/
BleepingComputer
New Windows malware may soon target Linux, macOS devices
Newly discovered Windows info-stealing malware linked to an active threat group tracked as AridViper shows signs that it might be used to infect computers running Linux and macOS.
Microsoft to quarantine compromised SolarWinds binaries tomorrow
Microsoft has announced today that Microsoft Defender will begin quarantining compromised SolarWind Orion binaries starting tomorrow morning. [...]
https://www.bleepingcomputer.com/news/security/microsoft-to-quarantine-compromised-solarwinds-binaries-tomorrow/
Microsoft has announced today that Microsoft Defender will begin quarantining compromised SolarWind Orion binaries starting tomorrow morning. [...]
https://www.bleepingcomputer.com/news/security/microsoft-to-quarantine-compromised-solarwinds-binaries-tomorrow/
BleepingComputer
Microsoft to quarantine compromised SolarWinds binaries tomorrow
Microsoft has announced today that Microsoft Defender will begin quarantining compromised SolarWind Orion binaries starting tomorrow morning.
Gmail hit by a second outage within a single day
Gmail is suffering its second outage in 24 hours, with users able to access their email but unable to send to other Gmail users or experiencing unexpected behavior. [...]
https://www.bleepingcomputer.com/news/google/gmail-hit-by-a-second-outage-within-a-single-day/
Gmail is suffering its second outage in 24 hours, with users able to access their email but unable to send to other Gmail users or experiencing unexpected behavior. [...]
https://www.bleepingcomputer.com/news/google/gmail-hit-by-a-second-outage-within-a-single-day/
BleepingComputer
Gmail hit by a second outage within a single day
Gmail is suffering its second outage in 24 hours, with users able to access their email but unable to send to other Gmail users or are experiencing unexpected behavior.
Microsoft Authenticator brings password autofill to mobile devices
Microsoft has released a new version of Microsoft Authenticator that now acts as a password manager for Android and iOS. [...]
https://www.bleepingcomputer.com/news/microsoft/microsoft-authenticator-brings-password-autofill-to-mobile-devices/
Microsoft has released a new version of Microsoft Authenticator that now acts as a password manager for Android and iOS. [...]
https://www.bleepingcomputer.com/news/microsoft/microsoft-authenticator-brings-password-autofill-to-mobile-devices/
BleepingComputer
Microsoft Authenticator brings password autofill to mobile devices
Microsoft has released a new version of Microsoft Authenticator that now acts as a password manager for Android and iOS.
Ransomware gangs automate payload delivery with SystemBC malware
SystemBC, a commodity malware sold on underground marketplaces, is being used by ransomware-as-a-service (RaaS) operations to hide malicious traffic and automate ransomware payload delivery on the networks of compromised victims. [...]
https://www.bleepingcomputer.com/news/security/ransomware-gangs-automate-payload-delivery-with-systembc-malware/
SystemBC, a commodity malware sold on underground marketplaces, is being used by ransomware-as-a-service (RaaS) operations to hide malicious traffic and automate ransomware payload delivery on the networks of compromised victims. [...]
https://www.bleepingcomputer.com/news/security/ransomware-gangs-automate-payload-delivery-with-systembc-malware/
BleepingComputer
Ransomware gangs automate payload delivery with SystemBC malware
SystemBC, a commodity malware sold on underground marketplaces, is being used by ransomware-as-a-service (RaaS) operations to hide malicious traffic and automate ransomware payload delivery on the networks of compromised victims.
HPE discloses critical zero-day in server management software
Hewlett Packard Enterprise (HPE) has disclosed a zero-day bug in the latest versions of its proprietary HPE Systems Insight Manager (SIM) software for Windows and Linux. [...]
https://www.bleepingcomputer.com/news/security/hpe-discloses-critical-zero-day-in-server-management-software/
Hewlett Packard Enterprise (HPE) has disclosed a zero-day bug in the latest versions of its proprietary HPE Systems Insight Manager (SIM) software for Windows and Linux. [...]
https://www.bleepingcomputer.com/news/security/hpe-discloses-critical-zero-day-in-server-management-software/
BleepingComputer
HPE discloses critical zero-day in server management software
Hewlett Packard Enterprise (HPE) has disclosed a zero-day bug in the latest versions of its proprietary HPE Systems Insight Manager (SIM) software for Windows and Linux.
Malicious RubyGems packages used in cryptocurrency supply chain attack
New malicious RubyGems packages have been discovered that are being used in a supply chain attack to steal cryptocurrency from unsuspecting users. [...]
https://www.bleepingcomputer.com/news/security/malicious-rubygems-packages-used-in-cryptocurrency-supply-chain-attack/
New malicious RubyGems packages have been discovered that are being used in a supply chain attack to steal cryptocurrency from unsuspecting users. [...]
https://www.bleepingcomputer.com/news/security/malicious-rubygems-packages-used-in-cryptocurrency-supply-chain-attack/
BleepingComputer
Malicious RubyGems packages used in cryptocurrency supply chain attack
New malicious RubyGems packages have been discovered that are being used in a supply chain attack to steal cryptocurrency from unsuspecting users.
Emulated mobile devices used to steal millions from US, EU banks
Threat actors behind an ongoing worldwide mobile banking fraud campaign were able to steal millions from multiple US and EU banks, needing just a few days for each attack. [...]
https://www.bleepingcomputer.com/news/security/emulated-mobile-devices-used-to-steal-millions-from-us-eu-banks/
Threat actors behind an ongoing worldwide mobile banking fraud campaign were able to steal millions from multiple US and EU banks, needing just a few days for each attack. [...]
https://www.bleepingcomputer.com/news/security/emulated-mobile-devices-used-to-steal-millions-from-us-eu-banks/
BleepingComputer
Emulated mobile devices used to steal millions from US, EU banks
Threat actors behind an ongoing worldwide mobile banking fraud campaign were able to steal millions from multiple US and EU banks, needing just a few days for each attack.
FireEye, Microsoft create kill switch for SolarWinds backdoor
Microsoft, FireEye, and GoDaddy have collaborated to create a kill switch for the SolarWinds Sunburst backdoor that forces the malware to terminate itself. [...]
https://www.bleepingcomputer.com/news/security/fireeye-microsoft-create-kill-switch-for-solarwinds-backdoor/
Microsoft, FireEye, and GoDaddy have collaborated to create a kill switch for the SolarWinds Sunburst backdoor that forces the malware to terminate itself. [...]
https://www.bleepingcomputer.com/news/security/fireeye-microsoft-create-kill-switch-for-solarwinds-backdoor/
BleepingComputer
FireEye, Microsoft create kill switch for SolarWinds backdoor
Microsoft, FireEye, and GoDaddy have collaborated to create a kill switch for the SolarWinds Sunburst backdoor that forces the malware to terminate itself.
Malicious Chrome, Edge extensions with 3M installs still in stores
Malicious Chrome and Edge browser extensions with over 3 million installs, most of them still available on the Chrome Web Store and the Microsoft Edge Add-ons portal, are capable of stealing users' info and redirecting them to phishing sites. [...]
https://www.bleepingcomputer.com/news/security/malicious-chrome-edge-extensions-with-3m-installs-still-in-stores/
Malicious Chrome and Edge browser extensions with over 3 million installs, most of them still available on the Chrome Web Store and the Microsoft Edge Add-ons portal, are capable of stealing users' info and redirecting them to phishing sites. [...]
https://www.bleepingcomputer.com/news/security/malicious-chrome-edge-extensions-with-3m-installs-still-in-stores/
BleepingComputer
Malicious Chrome, Edge extensions with 3M installs still in stores
Malicious Chrome and Edge browser extensions with over 3 million installs, most of them still available on the Chrome Web Store and the Microsoft Edge Add-ons portal, are capable of stealing users' info and redirecting them to phishing sites.
Holiday deal: 40% off Malwarebytes Premium and Teams
Malwarebytes is running a holiday deal where you can get 40% off Malwarebytes Premium and the Malwarebytes for Teams business product for a limited time. [...]
https://www.bleepingcomputer.com/news/software/holiday-deal-40-percent-off-malwarebytes-premium-and-teams/
Malwarebytes is running a holiday deal where you can get 40% off Malwarebytes Premium and the Malwarebytes for Teams business product for a limited time. [...]
https://www.bleepingcomputer.com/news/software/holiday-deal-40-percent-off-malwarebytes-premium-and-teams/
BleepingComputer
Holiday deal: 40% off Malwarebytes Premium and Teams
Malwarebytes is running a holiday deal where you can get 40% off Malwarebytes Premium and the Malwarebytes for Teams business product for a limited time.
FBI, CISA officially confirm US govt hacks after SolarWinds breach
The compromise of multiple US federal networks following the SolarWinds breach was officially confirmed for the first time in a joint statement released earlier today by the FBI, DHS-CISA, and the Office of the Director of National Intelligence (ODNI). [...]
https://www.bleepingcomputer.com/news/security/fbi-cisa-officially-confirm-us-govt-hacks-after-solarwinds-breach/
The compromise of multiple US federal networks following the SolarWinds breach was officially confirmed for the first time in a joint statement released earlier today by the FBI, DHS-CISA, and the Office of the Director of National Intelligence (ODNI). [...]
https://www.bleepingcomputer.com/news/security/fbi-cisa-officially-confirm-us-govt-hacks-after-solarwinds-breach/
BleepingComputer
FBI, CISA officially confirm US govt hacks after SolarWinds breach
The compromise of multiple US federal networks following the SolarWinds breach was officially confirmed for the first time in a joint statement released earlier today by the FBI, DHS-CISA, and the Office of the Director of National Intelligence (ODNI).
WordPress plugin with 5 million installs has a critical vulnerability
The team behind a popular WordPress plugin has disclosed a critical file upload vulnerability and issued a patch. The vulnerable plugin, Contact Form 7, has over 5 million active installations making this upgrade a necessity for WordPress site owners out there. [...]
https://www.bleepingcomputer.com/news/security/wordpress-plugin-with-5-million-installs-has-a-critical-vulnerability/
The team behind a popular WordPress plugin has disclosed a critical file upload vulnerability and issued a patch. The vulnerable plugin, Contact Form 7, has over 5 million active installations making this upgrade a necessity for WordPress site owners out there. [...]
https://www.bleepingcomputer.com/news/security/wordpress-plugin-with-5-million-installs-has-a-critical-vulnerability/
BleepingComputer
WordPress plugin with 5 million installs has a critical vulnerability
The team behind a popular WordPress plugin has disclosed a critical file upload vulnerability and issued a patch. The vulnerable plugin, Contact Form 7, has over 5 million active installations making this upgrade a necessity for WordPress site owners out…
Iranian nation-state hackers linked to Pay2Key ransomware
Iranian-backed hacking group Fox Kitten has been linked to the Pay2Key ransomware operation that has recently started targeting organizations from Israel and Brazil. [...]
https://www.bleepingcomputer.com/news/security/iranian-nation-state-hackers-linked-to-pay2key-ransomware/
Iranian-backed hacking group Fox Kitten has been linked to the Pay2Key ransomware operation that has recently started targeting organizations from Israel and Brazil. [...]
https://www.bleepingcomputer.com/news/security/iranian-nation-state-hackers-linked-to-pay2key-ransomware/
BleepingComputer
Iranian nation-state hackers linked to Pay2Key ransomware
Iranian-backed hacking group Fox Kitten has been linked to the Pay2Key ransomware operation that has recently started targeting organizations from Israel and Brazil.
CISA: APT group behind US govt hacks used multiple access vectors
The US Cybersecurity and Infrastructure Security Agency (CISA) said that the APT group behind the recent compromise campaign targeting US government agencies used more than one initial access vector. [...]
https://www.bleepingcomputer.com/news/security/cisa-apt-group-behind-us-govt-hacks-used-multiple-access-vectors/
The US Cybersecurity and Infrastructure Security Agency (CISA) said that the APT group behind the recent compromise campaign targeting US government agencies used more than one initial access vector. [...]
https://www.bleepingcomputer.com/news/security/cisa-apt-group-behind-us-govt-hacks-used-multiple-access-vectors/
BleepingComputer
CISA: Hackers breached US govt using more than SolarWinds backdoor
The US Cybersecurity and Infrastructure Security Agency (CISA) said that the APT group behind the recent compromise campaign targeting US government agencies used more than one initial access vector.
Ransomware masquerades as mobile version of Cyberpunk 2077
A threat actor is distributing fake Windows and Android installers for the Cyberpunk 2077 game that is installing a ransomware calling itself CoderWare. [...]
https://www.bleepingcomputer.com/news/security/ransomware-masquerades-as-mobile-version-of-cyberpunk-2077/
A threat actor is distributing fake Windows and Android installers for the Cyberpunk 2077 game that is installing a ransomware calling itself CoderWare. [...]
https://www.bleepingcomputer.com/news/security/ransomware-masquerades-as-mobile-version-of-cyberpunk-2077/
BleepingComputer
Ransomware masquerades as mobile version of Cyberpunk 2077
A threat actor is distributing fake Windows and Android installers for the Cyberpunk 2077 game that is installing a ransomware calling itself CoderWare.
Nation-state hackers breached US think tank thrice in a row
An advanced hacking group believed to be working for the Russian government has compromised the internal network of a think tank in the U.S. three times. [...]
https://www.bleepingcomputer.com/news/security/nation-state-hackers-breached-us-think-tank-thrice-in-a-row/
An advanced hacking group believed to be working for the Russian government has compromised the internal network of a think tank in the U.S. three times. [...]
https://www.bleepingcomputer.com/news/security/nation-state-hackers-breached-us-think-tank-thrice-in-a-row/
BleepingComputer
US think tank breached three times in a row by SolarWinds hackers
An advanced hacking group believed to be working for the Russian government has compromised the internal network of a think tank in the U.S. three times.
Bouncy Castle fixes cryptography API authentication bypass flaw
A severe authentication bypass vulnerability has been reported in Bouncy Castle, a popular open-source cryptography library. When exploited, the vulnerability (CVE-2020-28052) can allow an attacker to gain access to user and administrator accounts due to a cryptographic weakness in the manner passwords are checked. [...]
https://www.bleepingcomputer.com/news/security/bouncy-castle-fixes-cryptography-api-authentication-bypass-flaw/
A severe authentication bypass vulnerability has been reported in Bouncy Castle, a popular open-source cryptography library. When exploited, the vulnerability (CVE-2020-28052) can allow an attacker to gain access to user and administrator accounts due to a cryptographic weakness in the manner passwords are checked. [...]
https://www.bleepingcomputer.com/news/security/bouncy-castle-fixes-cryptography-api-authentication-bypass-flaw/