Category: Uncategorized
-

Inferno Malware Masqueraded as Coinbase, Drained $87 Million from 137,000 Victims [email protected] (The Hacker News)
The operators behind the now-defunct Inferno Drainer created more than 16,000 unique malicious domains over a span of one year between 2022 and 2023. The scheme “leveraged high-quality phishing pages to lure unsuspecting users into connecting their cryptocurrency wallets with the attackers’ infrastructure that spoofed Web3 protocols to trick victims into authorizingRead More
-

Hackers Weaponize Windows Flaw to Deploy Crypto-Siphoning Phemedrone Stealer [email protected] (The Hacker News)
Threat actors have been observed leveraging a now-patched security flaw in Microsoft Windows to deploy an open-source information stealer called Phemedrone Stealer. “Phemedrone targets web browsers and data from cryptocurrency wallets and messaging apps such as Telegram, Steam, and Discord,” Trend Micro researchers Peter Girnus, Aliakbar Zahravi, and Simon Zuckerbraun said. “It alsoRead More
-
Adobe ColdFusion Access Control Bypass (CVE-2023-26347, CVE-2023-38205)
What is the vulnerability? Adobe ColdFusion versions 2023.5 (and earlier) and 2021.11 (and earlier) are affected by Improper Access Control vulnerabilities that could result in a Security feature bypass. According to the National Vulnerability Database (NVD), exploitation of this issue does not require user interaction. Exploitation of the vulnerabilities could give attacker access to the…
-
Hacker Behind $2 Million Cryptocurrency Mining Scheme Arrested in Ukraine Ionut Arghire
Ukrainian authorities have arrested an individual allegedly involved in a $2 million cryptojacking operation. The post Hacker Behind $2 Million Cryptocurrency Mining Scheme Arrested in Ukraine appeared first on SecurityWeek. Read More
-

3 Ransomware Group Newcomers to Watch in 2024 [email protected] (The Hacker News)
The ransomware industry surged in 2023 as it saw an alarming 55.5% increase in victims worldwide, reaching a staggering 4,368 cases. Figure 1: Year over year victims per quarter The rollercoaster ride from explosive growth in 2021 to a momentary dip in 2022 was just a teaser—2023 roared back with the same fervor as 2021,…
-

Opera MyFlaw Bug Could Let Hackers Run ANY File on Your Mac or Windows [email protected] (The Hacker News)
Cybersecurity researchers have disclosed a security flaw in the Opera web browser for Microsoft Windows and Apple macOS that could be exploited to execute any file on the underlying operating system. The remote code execution vulnerability has been codenamed MyFlaw by the Guardio Labs research team owing to the fact that it takes advantage of…
-
Information Stealer Exploits Windows SmartScreen Bypass Ionut Arghire
Attackers exploit a recent Windows SmartScreen bypass vulnerability to deploy the Phemedrone information stealer. The post Information Stealer Exploits Windows SmartScreen Bypass appeared first on SecurityWeek. Read More
-
GitLab Patches Critical Password Reset Vulnerability Ionut Arghire
GitLab has resolved a critical authentication vulnerability allowing attackers to hijack password reset emails. The post GitLab Patches Critical Password Reset Vulnerability appeared first on SecurityWeek. Read More
-
Cloud Server Abuse Leads to Huge Spike in Botnet Scanning Eduard Kovacs
Netscout sees over one million IPs conducting reconnaissance scanning on the web due to increase in use of cheap or free cloud servers. The post Cloud Server Abuse Leads to Huge Spike in Botnet Scanning appeared first on SecurityWeek. Read More
-
Juniper Networks Patches Critical Remote Code Execution Flaw in Firewalls, Switches Eduard Kovacs
Juniper Networks patches over 100 vulnerabilities, including a critical flaw that can be exploited for remote code execution against firewalls and switches. The post Juniper Networks Patches Critical Remote Code Execution Flaw in Firewalls, Switches appeared first on SecurityWeek. Read More
