American Bank Systems sued for not timely disclosing ransomware attack

American Bank Systems (ABS) has been sued by a class of plaintiffs for their failure to protect customer data and for delaying the disclosure of ransomware attack. | Continue reading


@securityreport.com | 3 years ago

Steam gaming Windows privilege escalation attacks from writable install folder

Multiple privilege escalation vulnerabilities in Stream gaming service that remain unpatched can make it easy for malware and malicious threat actors to gain persistence and escalate permissions on Windows systems. | Continue reading


@securityreport.com | 3 years ago

Www.canada.gc.ca SSL certificate expires, breaking links

Government of Canada website www.canada.gc.ca is throwing SSL errors due to an expired certificate. Multiple Canadian government sites continue to have links to this older site which are now breaking. | Continue reading


@securityreport.com | 3 years ago

Mitsubishi companies hit by cyberattacks, ransomware

Mitsubishi Electric and sister companies such as Mitsubishi Polycrystalline have been hit by cyberattacks, including ransomware | Continue reading


@securityreport.com | 3 years ago

Feds arrest Romanian duo selling FUD malware crypters, CyberSeal, DataProtector

In a joint effort, international law enforcement authorities including the FBI, Europol, and the Romanian police have arrested a hacker duo that sold malware encryption tools. | Continue reading


@securityreport.com | 3 years ago

Node.js DoS flaw could crash apps via DNS lookups, patch now

NodeJS has released fixes for CVE-2020-8277, a DoS vulnerability that could be triggered via DNS requests. | Continue reading


@securityreport.com | 3 years ago

Drupal RCE via file upload (abc.html.txt, filename.php.gif)

Development team behind Drupal, a popular CMS and blogging platform has issued patches for a remote code execution vulnerability, CVE-2020-13671. | Continue reading


@securityreport.com | 3 years ago

Chaes malware strikes Latin American e-commerce sites

Researchers from the Cybereason Nocturnus Team have been keeping tabs on an undetected malware known as “Chaes.” The malware discovered sometime between mid-2020 and now | Continue reading


@securityreport.com | 3 years ago

Insomnia Cookies leaks database passwords

Continue reading


@securityreport.com | 3 years ago

New Ethereum vulnerabilities put almost $1B at stake

Researchers have discovered multiple serious vulnerabilities in Ethereum putting cryptocurrency worth million of dollars at risk | Continue reading


@securityreport.com | 3 years ago

American Bank Systems hit by Avaddon ransomware, 53 GB dump leaked

American Bank Systems (ABS), a service provider to US banks and financial institutions has suffered a ransomware attack with some of its clients' data leaked. | Continue reading


@securityreport.com | 3 years ago

Telegram app used by malware to infiltrate e-commerce sites

Telegram is being actively used by malware authors targeting e-commerce websites built on Prestashop, Magento and WooCommerce. | Continue reading


@securityreport.com | 3 years ago

Node.js malware caught posting IPs, username, and device info on GitHub

Multiple NodeJS packages laden with malicious code have been spotted on npm registry. These “typosquatting” packages served no purpose other than collecting data from the | Continue reading


@securityreport.com | 3 years ago

A malware alert left hundreds of Bank of America customers panicking

Hundreds of Bank of America customers had trouble accessing their bank accounts yesterday due to Avast and AVG antivirus engines flagging the site as "malware." | Continue reading


@securityreport.com | 3 years ago

Apple SSH privacy bug actively “exploited at large” still unpatched

A privacy bug lurking around in Apple Mac OS X since at least 2018 continues to remain unpatched and exploited at large. | Continue reading


@securityreport.com | 3 years ago

Why do planes use floppy disks even in 2020?

Airplanes are a luxury for most people to own, let alone toy with—given all the national security regulations. This year’s DEF CON, however, revealed a | Continue reading


@securityreport.com | 3 years ago

Hacker Noon leaks unfinished drafts to Google

Does your CMS leak drafts? I don’t know about you but I’d be pretty concerned if I found out an unfinished work or report I | Continue reading


@securityreport.com | 3 years ago

Hackers can unlock smart locks remotely using MQTT vulns

Share this post A new report published this week sheds light on a vulnerability in smart lock models that hackers could exploit to crack them | Continue reading


@securityreport.com | 3 years ago

20k GitHub projects use vulnerable Node.js `standard-version` library

Share this post More than 20,000 GitHub projects rely on the Node.js standard-version utility to implement semantic versioning (semver) and for generating CHANGELOG files for | Continue reading


@securityreport.com | 3 years ago