iShutdown scripts can help detect iOS spyware on your iPhone

Security researchers found that infections with high-profile spyware Pegasus, Reign, and Predator could be discovered on compromised Apple mobile devices by checking Shutdown.log, a system log file that stores reboot events. [...] | Continue reading


@bleepingcomputer.com | 10 months ago

AMD, Apple, Qualcomm GPUs leak AI data in LeftoverLocals attacks

A new vulnerability dubbed 'LeftoverLocals' affecting graphics processing units from AMD, Apple, Qualcomm, and Imagination Technologies allows retrieving data from the local memory space. [...] | Continue reading


@bleepingcomputer.com | 10 months ago

Wazuh: Building robust cybersecurity architecture with open source tools

Open source solutions allow organizations to customize and adapt their cybersecurity infrastructure to their specific needs. Learn more from @wazuh on building open source cybersecurity infrastructure. [...] | Continue reading


@bleepingcomputer.com | 10 months ago

GitHub rotates keys to mitigate impact of credential-exposing flaw

GitHub rotated keys potentially exposed by a vulnerability patched in December that could let attackers access credentials within production containers via environment variables. [...] | Continue reading


@bleepingcomputer.com | 10 months ago

MacOS info-stealers quickly evolve to evade XProtect detection

Multiple information stealers for the macOS platform have demonstrated the capability to evade detection even when security companies follow and report about new variants frequently. [...] | Continue reading


@bleepingcomputer.com | 10 months ago

Citrix warns of new Netscaler zero-days exploited in attacks

Citrix urged customers on Tuesday to immediately patch Netscaler ADC and Gateway appliances exposed online against two actively exploited zero-day vulnerabilities. [...] | Continue reading


@bleepingcomputer.com | 10 months ago

Google fixes first actively exploited Chrome zero-day of 2024

Google has released security updates to fix the first Chrome zero-day vulnerability exploited in the wild since the start of the year. [...] | Continue reading


@bleepingcomputer.com | 10 months ago

Majorca city Calvià extorted for $11M in ransomware attack

The Calvià City Council in Majorca announced it was targeted by a ransomware attack on Saturday, which impacted municipal services. [...] | Continue reading


@bleepingcomputer.com | 10 months ago

FBI: Androxgh0st malware botnet steals AWS, Microsoft credentials

CISA and the FBI warned today that threat actors using Androxgh0st malware are building a botnet focused on cloud credential theft and using the stolen information to deliver additional malicious payloads. [...] | Continue reading


@bleepingcomputer.com | 10 months ago

PixieFail flaws impact PXE network boot in enterprise systems

A set of nine vulnerabilities, collectively called 'PixieFail,' impact the IPv6 network protocol stack of Tianocore's EDK II, the open-source reference implementation of the UEFI specification widely used in enterprise computers and servers. [...] | Continue reading


@bleepingcomputer.com | 10 months ago

Atlassian warns of critical RCE flaw in older Confluence versions

Atlassian Confluence Data Center and Confluence Server are vulnerable to a critical remote code execution (RCE) vulnerability that impacts versions released before December 5, 2023, including out-of-support releases. [...] | Continue reading


@bleepingcomputer.com | 10 months ago

The Dual Role AI Plays in Cybersecurity: How to Stay Ahead

AI presents significant advantages for organizations, but it's also being exploited to amplify and intensify cyberattacks. Learn more from Outpost24 about how hackers are harnessing the power of AI. [...] | Continue reading


@bleepingcomputer.com | 10 months ago

Ivanti Connect Secure zero-days now under mass exploitation

Two zero-day vulnerabilities affecting Ivanti's Connect Secure VPN and Policy Secure network access control (NAC) appliances are now under mass exploitation. [...] | Continue reading


@bleepingcomputer.com | 10 months ago

Windows Copilot autostart tests limited to 27" displays or larger

Microsoft says that tests of a controversial new Windows 11 feature that automatically opens the AI-powered Copilot assistant after Windows starts are limited to systems with 27-inch displays. [...] | Continue reading


@bleepingcomputer.com | 10 months ago

US court docs expose fake antivirus renewal phishing tactics

In a seizure warrant application, the U.S. Secret Service sheds light on how threat actors stole $34,000 using fake antivirus renewal subscription emails. [...] | Continue reading


@bleepingcomputer.com | 10 months ago

Microsoft working on a fix for Windows 10 0x80070643 errors

Microsoft is working to fix a known issue causing 0x80070643 errors when installing the KB5034441 security update that patches the CVE-2024-20666 BitLocker vulnerability. [...] | Continue reading


@bleepingcomputer.com | 10 months ago

Windows SmartScreen flaw exploited to drop Phemedrone malware

A Phemedrone information-stealing malware campaign exploits a Microsoft Defender SmartScreen vulnerability (CVE-2023-36025) to bypass Windows security prompts when opening URL files. [...] | Continue reading


@bleepingcomputer.com | 10 months ago

Over 178K SonicWall firewalls vulnerable to DoS, potential RCE attacks

Security researchers have found over 178,000 SonicWall next-generation firewalls (NGFW) with the management interface exposed online are vulnerable to denial-of-service (DoS) and potential remote code execution (RCE) attacks. [...] | Continue reading


@bleepingcomputer.com | 10 months ago

Latest Adblock update causes massive YouTube performance hit

Adblock and Adblock Plus users report performance issues on YouTube, initially blamed on Google but later determined to be an issue in the popular ad-blocking extension. [...] | Continue reading


@bleepingcomputer.com | 10 months ago

The new Windows 11 features coming in 2024

Windows 11 is gearing up to introduce an array of exciting new features in 2024 aimed at enhancing user experience across various aspects of the operating system. [...] | Continue reading


@bleepingcomputer.com | 10 months ago

GrapheneOS: Frequent Android auto-reboots block firmware exploits

GrapheneOS, a privacy and security-focused Android-based operating system, has posted a series of tweets on X suggesting that Android should introduce frequent auto-reboots to make it harder for forensic software vendors to exploit firmware flaws and spy on the users. [...] | Continue reading


@bleepingcomputer.com | 10 months ago

Save up to $315 on data privacy tools with AdGuard VPN

A VPN is the first defense you have again ISP throttling, commercial data trackers, and malicious actors. AdGuard VPN has three deals to choose from now through January 14th. [...] | Continue reading


@bleepingcomputer.com | 10 months ago

Hacker spins up 1 million virtual servers to illegally mine crypto

A 29-year-old man in Ukraine was arrested this week for using hacked accounts to create 1 million virtual servers used to mine $2 million in cryptocurrency.  [...] | Continue reading


@bleepingcomputer.com | 10 months ago

The Week in Ransomware - January 12th 2024 - Targeting homeowners' data

Mortgage lenders and related companies are becoming popular targets of ransomware gangs, with four companies in this sector recently attacked. [...] | Continue reading


@bleepingcomputer.com | 10 months ago

CISA: Critical Microsoft SharePoint bug now actively exploited

CISA warns that attackers are now exploiting a critical Microsoft SharePoint privilege escalation vulnerability that can be chained with another critical bug for remote code execution. [...] | Continue reading


@bleepingcomputer.com | 10 months ago

GitLab warns of critical zero-click account hijacking vulnerability

GitLab has released security updates for both the Community and Enterprise Edition to address two critical vulnerabilities, one of them allowing account hijacking with no user interaction. [...] | Continue reading


@bleepingcomputer.com | 10 months ago

Juniper warns of critical RCE bug in its firewalls and switches

Juniper Networks has released security updates to fix a critical pre-auth remote code execution (RCE) vulnerability in its SRX Series firewalls and EX Series switches. [...] | Continue reading


@bleepingcomputer.com | 10 months ago

Ivanti Connect Secure zero-days exploited to deploy custom malware

Hackers have been exploiting the two zero-day vulnerabilities in Ivanti Connect Secure disclosed this week since early December to deploy multiple families of custom malware for espionage purposes. [...] | Continue reading


@bleepingcomputer.com | 10 months ago

Major T-Mobile outage takes down account access, mobile app

A major T-Mobile outage is preventing customers from logging into their accounts and using the company's mobile app. [...] | Continue reading


@bleepingcomputer.com | 10 months ago

Framework discloses data breach after accountant gets phished

Framework Computer disclosed a data breach exposing the personal information of an undisclosed number of customers after Keating Consulting Group, its accounting service provider, fell victim to a phishing attack. [...] | Continue reading


@bleepingcomputer.com | 10 months ago

Over 150k WordPress sites at takeover risk via vulnerable plugin

Two vulnerabilities impacting the POST SMTP Mailer WordPress plugin, an email delivery tool used by 300,000 websites, could help attackers take complete control of a site authentication. [...] | Continue reading


@bleepingcomputer.com | 10 months ago

Halara probes breach after hacker leaks data for 950,000 people

Popular athleisure clothing brand Halara is investigating a data breach after the alleged data of almost 950,000 customers was leaked on a hacking forum. [...] | Continue reading


@bleepingcomputer.com | 10 months ago

Microsoft testing Windows 11 USB 80Gbps support, Copilot on login

Microsoft is now testing support for the USB4 Version 2.0 specification in Windows 11, enabling transfer speeds of up to 80 Gbps over USB Type-C cables. [...] | Continue reading


@bleepingcomputer.com | 10 months ago

Bitwarden adds passkey support to log into web password vaults

The open-source Bitwarden password manager has announced that all users can now log in to their web vaults using a passkey instead of the standard username and password pairs. [...] | Continue reading


@bleepingcomputer.com | 10 months ago

Microsoft shares script to update Windows 10 WinRE with BitLocker fixes

Microsoft has released a PowerShell script to automate updating the Windows Recovery Environment (WinRE) partition in order to fix CVE-2024-20666, a vulnerability that allowed for BitLocker encryption bypass. [...] | Continue reading


@bleepingcomputer.com | 10 months ago

New Balada Injector campaign infects 6,700 WordPress sites

A new Balada Injector campaign launched in mid-December has infected over 6,700 WordPress websites using a vulnerable version of the Popup Builder campaign. [...] | Continue reading


@bleepingcomputer.com | 10 months ago

Finland warns of Akira ransomware wiping NAS and tape backup devices

The Finish National Cybersecurity Center (NCSC-FI) is informing of increased Akira ransomware activity in December, targeting companies in the country and wiping backups. [...] | Continue reading


@bleepingcomputer.com | 10 months ago

Mandiant's X account hacked by crypto Drainer-as-a-Service gang

Cybersecurity firm and Google subsidiary Mandiant says its Twitter/X account was hijacked last week by a Drainer-as-a-Service (DaaS) gang in what it described as "likely a brute force password attack." [...] | Continue reading


@bleepingcomputer.com | 10 months ago

Cisco says critical Unity Connection bug lets attackers get root

Cisco has patched a critical Unity Connection security flaw that can let unauthenticated attackers remotely gain root privileges on unpatched devices. [...] | Continue reading


@bleepingcomputer.com | 10 months ago

Fidelity National Financial: Hackers stole data of 1.3 million people

Fidelity National Financial (FNF) has confirmed that a November cyberattack (claimed by the BlackCat ransomware gang) has exposed the data of 1.3 million customers. [...] | Continue reading


@bleepingcomputer.com | 10 months ago

Pro-Ukraine hackers breach Russian ISP in revenge for KyivStar attack

A pro-Ukraine hacktivist group named 'Blackjack' has claimed a cyberattack against Russian provider of internet services M9com as a direct response to the attack against Kyivstar mobile operator. [...] | Continue reading


@bleepingcomputer.com | 10 months ago

Ivanti warns of Connect Secure zero-days exploited in attacks

Ivanti has disclosed two Connect Secure (ICS) and Policy Secure zero-days exploited in the wild that can let remote attackers execute arbitrary commands on targeted gateways. [...] | Continue reading


@bleepingcomputer.com | 10 months ago

Fake 401K year-end statements used to steal corporate credentials

Threat actors are using communication about personal pension accounts (the 401(k) plans in the U.S.), salary adjustments, and performance reports to steal company employees' credentials. [...] | Continue reading


@bleepingcomputer.com | 10 months ago

Windows 10 KB5034441 security update fails with 0x80070643 errors

Windows 10 users worldwide report problems installing Microsoft's January Patch Tuesday updates, getting 0x80070643 errors when attempting to install the KB5034441 security update for BitLocker. [...] | Continue reading


@bleepingcomputer.com | 10 months ago

Microsoft Exchange 2019 has reached end of mainstream support

Microsoft announced the end of mainstream support for its Exchange Server 2019 on-premises mail server software on January 9, 2023. [...] | Continue reading


@bleepingcomputer.com | 10 months ago

ShinyHunters member gets 3 years in prison for breaching 60 firms

The U.S. District Court in Seattle sentenced ShinyHunters member Sebastien Raoult to three years in prison and ordered a restitution of $5,000,000. [...] | Continue reading


@bleepingcomputer.com | 10 months ago

Nigerian gets 10 years for laundering millions stolen from elderly

A Nigerian man was sentenced on Monday to 10 years and one month in prison for conspiring to launder millions stolen from elderly victims in internet fraud schemes. [...] | Continue reading


@bleepingcomputer.com | 10 months ago

US SEC’s X account hacked to announce fake Bitcoin ETF approval

The X account for the U.S. Securities and Exchange Commission was hacked today to issue a fake announcement on the approval of Bitcoin ETFs on security exchanges. [...] | Continue reading


@bleepingcomputer.com | 10 months ago