📰 Software Vulnerability News
Page 8 - Software Vulnerability News Today
Fast, Ad-Free News Updates
Stay updated with breaking news from Software Vulnerability. Real-time updates on events, politics, business and more.
March 1, 2021
SolarWinds Blames Intern for solarwinds123 Password Lapse As cybersecurity researchers continue to piece together the sprawling SolarWinds supply chain attack, top executives of the Texas-based software services firm blamed an intern for a critical password lapse that went unnoticed for several years. The said password "solarwinds123" was originally believed to have been publicly accessible via a GitHub repository since June 17, 2018, before the misconfiguration was addressed on November 22, 2...
February 26, 2021
Study Finds Malicious Amazon Alexa Skills Can Easily Bypass Vetting Process
February 26, 2021
North Korean Hackers Targeting Defense Firms with ThreatNeedle Malware
February 25, 2021
Ukraine Says Russian Hackers Launched Supply-Chain Malware Attack Against its Government Agencies
February 25, 2021
Chinese Hackers Using Firefox Extension to Spy On Tibetan Organizations Cybersecurity researchers today unwrapped a new campaign aimed at spying on vulnerable Tibetan communities globally by deploying a malicious Firefox extension on target systems. "Threat actors aligned with the Chinese Communist Partys state interests delivered a customized malicious Mozilla Firefox browser extension that facilitated access and control of users Gmail accounts," Proofpoint said in an analysis. The Sunnyvale-b...
February 22, 2021
New Silver Sparrow Malware Infected Nearly 30,000 Apple Macs Days after the first malware targeting Apple M1 chips was discovered in the wild, researchers have disclosed yet another previously undetected piece of malicious software that was found in about 30,000 Macs running Intel x86_64 and the iPhone makers M1 processors. However, the ultimate goal of the operation remains something of a conundrum, what with the lack of a next-stage or final payload leaving researchers unsure of its distribut...
February 16, 2021
A flaw in Telegram messaging app could have exposed users' secret messages, photos, and videos
February 16, 2021
Hackers Exploit IT Monitoring Tool Centreon to Target Several French Entities Centreon. The intrusion campaign — which breached "several French entities" — is said to have started in late 2017 and lasted until 2020, with the attacks particularly impacting web-hosting providers, said the French information security agency ANSSI in an advisory. "On compromised systems, ANSSI discovered the presence of a backdoor in the form of a webshell dropped on several Centreon servers exposed to the inte...
February 16, 2021
Unpatched ShareIT Android App Flaw Could Let Hackers Inject Malware Multiple unpatched vulnerabilities have been discovered in SHAREit, a popular app with over one billion downloads, that could be abused to leak a users sensitive data, execute arbitrary code, and possibly lead to remote code execution. The findings come from cybersecurity firm Trend Micros analysis of the Android version of the app, which allows users to share or transfer files between devices. But in a worrisome twist, the fla...
February 15, 2021
Apple will proxy Safe Browsing requests to hide iOS users IP from Google Apples upcoming iOS 14.5 update will come with a new feature that will redirect all fraudulent website checks through its own proxy servers as a workaround to preserve user privacy and prevent leaking IP addresses to Google. A built-in security-focused feature in the Safari browser, "Fraudulent Website Warning," alerts users about dangerous websites that have been reported as deceptive, malicious, or harmful. To achieve th...