Yet another unpatched #vulnerability has been uncovered in Windows Printer Spooler, making it the fourth printer-related vulnerability found in recent weeks.
Read: https://thehackernews.com/2021/07/researcher-uncover-yet-another.html
Read: https://thehackernews.com/2021/07/researcher-uncover-yet-another.html
Remember that fun-looking Wi-Fi name bug on iOS?
🔥 Turns out the vulnerability can not only disable the iPhone's network functionality, but can also be exploited to remotely execute malicious code on targeted Apple devices.
Details: https://thehackernews.com/2021/07/turns-out-that-low-risk-ios-wi-fi.html
🔥 Turns out the vulnerability can not only disable the iPhone's network functionality, but can also be exploited to remotely execute malicious code on targeted Apple devices.
Details: https://thehackernews.com/2021/07/turns-out-that-low-risk-ios-wi-fi.html
Researchers have gained insight into a group of Romanian cybercriminals which have been identified carrying out cryptojacking attacks on #Linux machines with weak passwords.
Read: https://thehackernews.com/2021/07/researchers-warn-of-linux-cryptojacking.html
Read: https://thehackernews.com/2021/07/researchers-warn-of-linux-cryptojacking.html
The United States and its global allies have officially blamed hackers affiliated with the Chinese government for the massive cyberattack on Microsoft Exchange servers.
Read: https://thehackernews.com/2021/07/us-and-global-allies-accuse-china-of.html
Read: https://thehackernews.com/2021/07/us-and-global-allies-accuse-china-of.html
Researchers warn of a new malware strain, dubbed "MosaicLoader," that hides among Windows Defender exclusions to evade detection by Microsoft's antivirus program.
Read details: https://thehackernews.com/2021/07/this-new-malware-hides-itself-among.html
Read details: https://thehackernews.com/2021/07/this-new-malware-hides-itself-among.html
Millions of HP, Samsung and Xerox printers worldwide are vulnerable to a new vulnerability (CVE-2021-3438) that has gone undetected for 16 years.
Read details: https://thehackernews.com/2021/07/16-year-old-security-bug-affects.html
Read details: https://thehackernews.com/2021/07/16-year-old-security-bug-affects.html
New Windows and Linux Flaws Give Attackers Highest System Privileges (SYSTEM / root):
1 — Microsoft has tagged this new vulnerability CVE-2021-36934, marking it as the 3rd publicly disclosed unpatched Windows bug this month.
2 — Dubbed "Sequoia," the Linux flaw (CVE-2021-33909) affects all kernel versions from 2014, including default installations of Ubuntu, Debian, Fedora and RHEL.
https://thehackernews.com/2021/07/new-windows-and-linux-flaws-give.html
1 — Microsoft has tagged this new vulnerability CVE-2021-36934, marking it as the 3rd publicly disclosed unpatched Windows bug this month.
2 — Dubbed "Sequoia," the Linux flaw (CVE-2021-33909) affects all kernel versions from 2014, including default installations of Ubuntu, Debian, Fedora and RHEL.
https://thehackernews.com/2021/07/new-windows-and-linux-flaws-give.html
Cybersecurity researchers have discovered multiple vulnerabilities in CODESYS automation software and the WAGO PLC platform that can be remotely exploited to compromise an organization's cloud operating technology infrastructure (OT).
Read: https://thehackernews.com/2021/07/several-new-critical-flaws-affect.html
Read: https://thehackernews.com/2021/07/several-new-critical-flaws-affect.html
XLoader, a low-cost and popular Windows malware available on rent, has now been upgraded to allow cybercriminals to spy on Apple's macOS users.
Read: https://thehackernews.com/2021/07/xloader-windows-infostealer-malware-now.html
Read: https://thehackernews.com/2021/07/xloader-windows-infostealer-malware-now.html
In an apparent supply-chain attack, a software package available from the official NPM repository has been caught stealing users’ saved passwords from their Chrome web browser.
Read details: https://thehackernews.com/2021/07/malicious-npm-package-caught-stealing.html
Read details: https://thehackernews.com/2021/07/malicious-npm-package-caught-stealing.html
Another hacker, a British national, has been arrested in connection with the high-profile 2020 Twitter hack who played a role in the massive bitcoin scam.
Read details: https://thehackernews.com/2021/07/another-hacker-arrested-for-2020.html
Read details: https://thehackernews.com/2021/07/another-hacker-arrested-for-2020.html
Oracle warns of three newly discovered critical vulnerabilities in Weblogic server software that can be exploited remotely without authentication.
Read: https://thehackernews.com/2021/07/oracle-warns-of-critical-remotely.html
As part of the July 2021 Patch Updates, Oracle also released 342 fixes that span multiple products.
Read: https://thehackernews.com/2021/07/oracle-warns-of-critical-remotely.html
As part of the July 2021 Patch Updates, Oracle also released 342 fixes that span multiple products.
Kaseya has received a universal REvil decryptor to help customers recover data, nearly 3 weeks after a supply-chain ransomware attack impacted the company.
https://thehackernews.com/2021/07/kaseya-gets-universal-decryptor-to-help.html
https://thehackernews.com/2021/07/kaseya-gets-universal-decryptor-to-help.html
Nasty macOS malware XCSSET has been updated once again to steal sensitive data from a variety of apps, including Chrome and Telegram.
Read: https://thehackernews.com/2021/07/nasty-macos-malware-xcsset-now-targets.html
Read: https://thehackernews.com/2021/07/nasty-macos-malware-xcsset-now-targets.html
A newly discovered "PetitPotam" NTLM relay attack can be exploited by attackers to completely take over Windows domains by forcing remote servers—including Domain Controllers—to authenticate with a malicious machine.
Details: https://thehackernews.com/2021/07/new-petitpotam-ntlm-relay-attack-lets.html
Details: https://thehackernews.com/2021/07/new-petitpotam-ntlm-relay-attack-lets.html
Microsoft warns of a notorious cross-platform crypto-mining malware that has refined and improved its techniques to attack Windows and #Linux operating systems.
Read details: https://thehackernews.com/2021/07/microsoft-warns-of-lemonduck-malware.html
Read details: https://thehackernews.com/2021/07/microsoft-warns-of-lemonduck-malware.html
A growing number of cybercriminals are switching from conventional programming languages to "exotic" languages—such as Go, Rust, Nim, Dlang—for #malware development that can bypass security, and complicate reverse-engineering efforts.
Read: https://thehackernews.com/2021/07/hackers-turning-to-exotic-programming.html
Read: https://thehackernews.com/2021/07/hackers-turning-to-exotic-programming.html
Rapid7 has uncovered multiple flaws affecting 3 open-source projects — EspoCRM, Pimcore, Akaunting — that are used by several small & medium-sized businesses that could provide a pathway for more sophisticated attacks.
Details: https://thehackernews.com/2021/07/several-bugs-found-in-3-open-source.html
Details: https://thehackernews.com/2021/07/several-bugs-found-in-3-open-source.html
Zimbra email collaboration software, used by over 200,000 companies, has been found vulnerable to multiple flaws that could be exploited to compromise email accounts & even take full control of mail server when hosted on a cloud infrastructure.
https://thehackernews.com/2021/07/new-bug-could-let-attackers-hijack.html
https://thehackernews.com/2021/07/new-bug-could-let-attackers-hijack.html
An Iranian cyberespionage group spent years posing as an aerobics instructor on Facebook to infect the computer of an aerospace defense contractor with malware.
Read details: https://thehackernews.com/2021/07/hackers-posed-as-aerobics-instructors.html
Read details: https://thehackernews.com/2021/07/hackers-posed-as-aerobics-instructors.html
Chinese cyberespionage group PKPLUG deployed a previously undocumented variant of PlugX RAT on compromised systems during the recent wave of attacks on #Microsoft Exchange servers.
Read details: https://thehackernews.com/2021/07/chinese-hackers-implant-plugx-variant.html
Read details: https://thehackernews.com/2021/07/chinese-hackers-implant-plugx-variant.html