📰 Oftware Vulnerability News
Page 78 - Oftware Vulnerability News Today
Fast, Ad-Free News Updates
Stay updated with breaking news from Oftware Vulnerability. Real-time updates on events, politics, business and more.
May 20, 2021
23 Android Apps Expose Over 100,000,000 Users Personal Data Misconfigurations in multiple Android apps leaked sensitive data of more than 100 million users, potentially making them a lucrative target for malicious actors. "By not following best-practices when configuring and integrating third-party cloud-services into applications, millions of users private data was exposed," Check Point researchers said in an analysis published today and shared with The Hacker News. "In some cases, this type o...
May 20, 2021
Watering Hole Attack Was Used to Target Florida Water Utilities An investigation undertaken in the aftermath of the Oldsmar water plant hack earlier this year has revealed that an infrastructure contractor in the U.S. state of Florida hosted malicious code on its website in whats known as a watering hole attack. "This malicious code seemingly targeted water utilities, particularly in Florida, and more importantly, was visited by a browser from the city of Oldsmar on the same day of the poisonin...
May 17, 2021
U.S. Pipeline Ransomware Attackers Go Dark After Servers and Bitcoin Are Seized Just as Colonial Pipeline restored all of its systems to operational status in the wake of a crippling ransomware incident a week ago, DarkSide, the cybercrime syndicate behind the attack, claimed it lost control of its infrastructure, citing a law enforcement seizure. All the dark websites operated by the gang, including its DarkSide Leaks blog, ransom collection site, and breach data content delivery network (CDN)...
May 17, 2021
Why Password Hygiene Needs a Reboot In todays digital world, password security is more important than ever. While biometrics, one-time passwords (OTP), and other emerging forms of authentication are often touted as replacements to the traditional password, today, this concept is more marketing hype than anything else. But just because passwords arent going anywhere anytime soon doesnt mean that organizations dont need to modernize their approach to password hygiene right now. The Compromised C...
May 13, 2021
Dark Web Getting Loaded With Bogus Covid-19 Vaccines and Forged Cards
May 12, 2021
Is it still a good idea to require users to change their passwords? For as long as corporate IT has been in existence, users have been required to change their passwords periodically. In fact, the need for scheduled password changes may be one of the most long-standing of all IT best practices. Recently, however, things have started to change. Microsoft has reversed course on the best practices that it has had in place for decades and no longer recommends that organizations require users to cha...
May 3, 2021
New Chinese Malware Targeted Russias Largest Nuclear Submarine Designer A threat actor believed to be working on behalf of Chinese state-sponsored interests was recently observed targeting a Russia-based defense contractor involved in designing nuclear submarines for the naval arm of the Russian Armed Forces. The phishing attack, which singled out a general director working at the Rubin Design Bureau, leveraged the infamous "Royal Road" Rich Text Format (RTF) weaponizer to deliver a previously ...
April 27, 2021
Hackers Threaten to Leak D.C. Police Informants Info If Ransom Is Not Paid The Metropolitan Police Department (MPD) of the District of Columbia has become the latest high-profile government agency to fall victim to a ransomware attack. The Babuk Locker gang claimed in a post on the dark web that they had compromised the DC Polices networks and stolen 250 GB of unencrypted files. Screenshots shared by the group, and seen by The Hacker News, include various folders containing what appears to be i...
April 26, 2021
Emotet Malware Destroys Itself From All Infected Computers Emotet, the notorious email-based Windows malware behind several botnet-driven spam campaigns and ransomware attacks, was automatically wiped from infected computers en masse following a European law enforcement operation. The development comes three months after a coordinated disruption of Emotet as part of "Operation Ladybird" to seize control of servers used to run and maintain the malware network. The orchestrated effort saw at leas...
April 26, 2021
3.2 Billion Leaked Passwords Contain 1.5 Million Records with Government Emails A staggering number of 3.28 billion passwords linked to 2.18 billion unique email addresses were exposed in whats one of the largest data dumps of breached usernames and passwords. In addition, the leak includes 1,502,909 passwords associated with email addresses from government domains across the world, with the U.S. government alone taking up 625,505 of the exposed passwords, followed by the U.K (205,099), Austral...