📰 Software Vulnerability News
Page 7 - Software Vulnerability News Today
Fast, Ad-Free News Updates
Stay updated with breaking news from Software Vulnerability. Real-time updates on events, politics, business and more.
April 1, 2021
Hackers Set Up a Fake Cybersecurity Firm to Target Security Experts A North Korean government-backed campaign targeting cybersecurity researchers with malware has re-emerged with new tactics in their arsenal as part of a fresh social engineering attack. In an update shared on Wednesday, Googles Threat Analysis Group said the attackers behind the operation set up a fake security company called SecuriElite and a slew of social media accounts across Twitter and LinkedIn in an attempt to trick unsu...
April 1, 2021
DeepDotWeb Admin Pleads Guilty to Money Laundering Charges DeepDotWeb (DDW), a "news" website that "served as a gateway to numerous dark web marketplaces." According to the unsealed court documents, Tal Prihar, 37, an Israeli citizen residing in Brazil, operated DDW alongside Michael Phan, 34, of Israel, starting October 2013, in return for which they received kickbacks from the operators of the marketplaces in the form of virtual currency amounting to 8,155 bitcoins (worth $8.4 million at th...
March 16, 2021
Microsoft released a one-click mitigation software to secure vulnerable environments against the ongoing widespread ProxyLogon Exchange cyberattacks.
March 15, 2021
CEO of Encrypted Chat Platform Indicted for Aiding Organised Criminals The U.S. Department of Justice (DoJ) on Friday announced an indictment against Jean-Francois Eap, the CEO of encrypted messaging company Sky Global, and an associate for wilfully participating in a criminal enterprise to help international drug traffickers avoid law enforcement. Eap (also known as "888888") and Thomas Herdman, a former high-level distributor of Sky Global devices, have been charged with a conspiracy to viola...
March 12, 2021
New Browser Attack Allows Tracking Users Online With JavaScript Disabled Researchers have discovered a new side-channel that they say can be reliably exploited to leak information from web browsers that could then be leveraged to track users even when JavaScript is completely disabled. "This is a side-channel attack which doesnt require any JavaScript to run," the researchers said. "This means script blockers cannot stop it. The attacks work even if you strip out all of the fun parts of the web...
March 11, 2021
ProxyLogon PoC Exploit Released; Likely to Fuel More Disruptive Cyber Attacks The U.S. Cybersecurity and Infrastructure Security Agency (CISA) and the Federal Bureau of Investigation (FBI) on Wednesday issued a joint advisory warning of active exploitation of vulnerabilities in Microsoft Exchange on-premises products by nation-state actors and cybercriminals. "CISA and FBI assess that adversaries could exploit these vulnerabilities to compromise networks, steal information, encrypt data for ran...
March 9, 2021
SolarWinds Hack — New Evidence Suggests Potential Links to Chinese Hackers A malicious web shell deployed on Windows systems by leveraging a previously undisclosed zero-day in SolarWinds Orion network monitoring software may have been the work of a possible Chinese threat group. In a report published by Secureworks on Monday, the cybersecurity firm attributed the intrusions to a threat actor it calls Spiral. Back on December 22, 2020, Microsoft disclosed that a second espionage group may have...
March 9, 2021
Apple Issues Security Patch for Remote Code Execution Bug Affecting Billions of its iOS, iPadOS, macOS and watch devices.
March 8, 2021
Recent flaw in Microsoft Exchange servers believed to have infected tens of thousands of businesses, government entities.
March 6, 2021
Bug in Apples Find My Feature Couldve Exposed Users Location Histories Cybersecurity researchers on Thursday disclosed two distinct design and implementation flaws in Apples crowdsourced Bluetooth location tracking system that can lead to a location correlation attack and unauthorized access to the location history of the past seven days, thereby by deanonymizing users. The findings are a consequence of an exhaustive review undertaken by the Open Wireless Link (OWL) project, a team of researche...