Category: Uncategorized
-

Ransomware attacks doubled year on year. Are organizations equipped to handle the evolution of Ransomware in 2023? [email protected] (The Hacker News)
Ransomware attacks have only increased in sophistication and capabilities over the past year. From new evasion and anti-analysis techniques to stealthier variants coded in new languages, ransomware groups have adapted their tactics to bypass common defense strategies effectively. This article will cover just some of those new developments in Q3-2023 as well as give predictions…
-

DarkGate Malware Spreading via Messaging Services Posing as PDF Files [email protected] (The Hacker News)
A piece of malware known as DarkGate has been observed being spread via instant messaging platforms such as Skype and Microsoft Teams. In these attacks, the messaging apps are used to deliver a Visual Basic for Applications (VBA) loader script that masquerades as a PDF document, which, when opened, triggers the download and execution of an AutoIt…
-

FBI, CISA Warn of Rising AvosLocker Ransomware Attacks Against Critical Infrastructure [email protected] (The Hacker News)
The AvosLocker ransomware gang has been linked to attacks against critical infrastructure sectors in the U.S., with some of them detected as recently as May 2023. That’s according to a new joint cybersecurity advisory released by the U.S. Cybersecurity and Infrastructure Security Agency (CISA) and the Federal Bureau of Investigation (FBI) detailing the ransomware-as-a-service (RaaS)…
-
Dozens of Squid Proxy Vulnerabilities Remain Unpatched 2 Years After Disclosure Eduard Kovacs
Dozens of Squid caching proxy vulnerabilities remain unpatched two years after a researcher reported them to developers. The post Dozens of Squid Proxy Vulnerabilities Remain Unpatched 2 Years After Disclosure appeared first on SecurityWeek. Read More
-
Microsoft Offers Up to $15,000 in New AI Bug Bounty Program Ionut Arghire
Microsoft is offering rewards of up to $15,000 in a new bug bounty program dedicated to its new AI-powered Bing. The post Microsoft Offers Up to $15,000 in New AI Bug Bounty Program appeared first on SecurityWeek. Read More
-
HTTP/2 Rapid Reset Attack
A newly identified Distributed Denial-of-Service (DDoS) attack technique is used in the wild. This DDoS attack, known as ‘HTTP/2 Rapid Reset’, leverages a flaw in the implementation of protocol HTTP/2.Read More
-
SEC Investigating Progress Software Over MOVEit Hack Ionut Arghire
Progress Software confirms the SEC has launched its own investigation into costly ransomware zero-days in the MOVEit file transfer software. The post SEC Investigating Progress Software Over MOVEit Hack appeared first on SecurityWeek. Read More
-
Backdoor Malware Found on WordPress Website Disguised as Legitimate Plugin Ionut Arghire
A backdoor deployed on a compromised WordPress website poses as a legitimate plugin to hide its presence. The post Backdoor Malware Found on WordPress Website Disguised as Legitimate Plugin appeared first on SecurityWeek. Read More
-

Malicious NuGet Package Targeting .NET Developers with SeroXen RAT [email protected] (The Hacker News)
A malicious package hosted on the NuGet package manager for the .NET Framework has been found to deliver a remote access trojan called SeroXen RAT. The package, named Pathoschild.Stardew.Mod.Build.Config and published by a user named Disti, is a typosquat of a legitimate package called Pathoschild.Stardew.ModBuildConfig, software supply chain security firm Phylum said in a report today. WhileRead More
-
Apple Releases iOS 16 Update to Patch Exploited Vulnerability Eduard Kovacs
Apple has released iOS 16.7.1 and iPadOS 16.7.1 to patch CVE-2023-42824, a kernel vulnerability that has been exploited in attacks. The post Apple Releases iOS 16 Update to Patch Exploited Vulnerability appeared first on SecurityWeek. Read More
