Category: Uncategorized
-

Mirai-based Botnet Exploiting Zero-Day Bugs in Routers and NVRs for Massive DDoS Attacks [email protected] (The Hacker News)
An active malware campaign is leveraging two zero-day vulnerabilities with remote code execution (RCE) functionality to rope routers and video recorders into a Mirai-based distributed denial-of-service (DDoS) botnet. “The payload targets routers and network video recorder (NVR) devices with default admin credentials and installs Mirai variants when successful,” Akamai said in an advisoryRead More
-

North Korean Hackers Distribute Trojanized CyberLink Software in Supply Chain Attack [email protected] (The Hacker News)
A North Korean state-sponsored threat actor tracked as Diamond Sleet is distributing a trojanized version of a legitimate application developed by a Taiwanese multimedia software developer called CyberLink to target downstream customers via a supply chain attack. “This malicious file is a legitimate CyberLink application installer that has been modified to include malicious code that downloads,Read More
-
Researchers Discover Dangerous Exposure of Sensitive Kubernetes Secrets Ryan Naraine
Researchers at Aqua call urgent attention to the public exposure of Kubernetes configuration secrets, warning that hundreds of organizations are vulnerable to this “ticking supply chain attack bomb.” The post Researchers Discover Dangerous Exposure of Sensitive Kubernetes Secrets appeared first on SecurityWeek. Read More
-

New Flaws in Fingerprint Sensors Let Attackers Bypass Windows Hello Login [email protected] (The Hacker News)
A new research has uncovered multiple vulnerabilities that could be exploited to bypass Windows Hello authentication on Dell Inspiron 15, Lenovo ThinkPad T14, and Microsoft Surface Pro X laptops. The flaws were discovered by researchers at hardware and software product security and offensive research firm Blackwing Intelligence, who found the weaknesses in the fingerprint sensors from Goodix,Read…
-
4 data loss examples keeping backup admins up at night
Post ContentRead More
-
CISA relaunches working group on cyber insurance, ransomware
Post ContentRead More
-
185,000 Individuals Impacted by MOVEit Hack at Car Parts Giant AutoZone Eduard Kovacs
Car parts giant AutoZone says nearly 185,000 individuals were impacted by a data breach caused by the MOVEit hack. The post 185,000 Individuals Impacted by MOVEit Hack at Car Parts Giant AutoZone appeared first on SecurityWeek. Read More
-
Windows Hello Fingerprint Authentication Bypassed on Popular Laptops Eduard Kovacs
Researchers have tested the fingerprint sensors used for Windows Hello on three popular laptops and managed to bypass them. The post Windows Hello Fingerprint Authentication Bypassed on Popular Laptops appeared first on SecurityWeek. Read More
-
Sam Altman is Back as OpenAI CEO Just Days After Being Removed, Along With a New Board Associated Press
San Francisco-based OpenAI has reached an agreement in principle for Sam Altman to return to OpenAI as CEO with a new initial board. The post Sam Altman is Back as OpenAI CEO Just Days After Being Removed, Along With a New Board appeared first on SecurityWeek. Read More
-
Microsoft Offers Up to $20,000 for Vulnerabilities in Defender Products Ionut Arghire
Microsoft invites researchers to new bug bounty program focused on vulnerabilities in its Defender products. The post Microsoft Offers Up to $20,000 for Vulnerabilities in Defender Products appeared first on SecurityWeek. Read More
