Skip to main content

Security News

Filter by:

New GwisinLocker ransomware encrypts Windows and Linux ESXi servers

A new ransomware family called 'GwisinLocker' targets South Korean healthcare, industrial, and pharmaceutical companies with Windows and Linux encryptors, including support for encrypting VMware ESXi servers and virtual machines. [...]
Bleepingcomputer 6 Aug 2022 1306 Views

Hackers try to extort survey firm QuestionPro after alleged data theft

Hackers attempted to extort the online survey platform QuestionPro after claiming to have stolen the company's database containing respondents' personal information.
BleepingComputer 5 Aug 2022 828 Views

New Traffic Light Protocol standard released after five years

The Forum of Incident Response and Security Teams (FIRST) has published TLP 2., a new version of its Traffic Light Protocol (TLP) standard, five years after the release of the initial version.
Bleepingcomputer 5 Aug 2022 1587 Views

35,000 code repos not hacked—but clones flood GitHub to serve malware

Thousands of GitHub repositories were forked (copied) with their clones altered to include malware, a software engineer discovered today.
BleepingComputer 4 Aug 2022 1094 Views

Critical RCE Bug in DrayTek Routers Opens SMBs to Zero-Click Attacks

SMBs should patch CVE-2022-32548 now to avoid a host of horrors, including complete network compromise, ransomware, state-sponsored attacks, and more.
DARKReading 4 Aug 2022 1102 Views

Microsoft accounts targeted with new MFA-bypassing phishing kit

A new large-scale phishing campaign targeting credentials for Microsoft email services use a custom proxy-based phishing kit to bypass multi-factor authentication.
BleepingComputer 4 Aug 2022 1169 Views

VirusTotal Reveals Most Impersonated Software in Malware Attacks

Threat actors are increasingly mimicking legitimate applications like Skype, Adobe Reader, and VLC Player as a means to abuse trust relationships and increase the likelihood of a successful social engineering attack.
The Hacker News 4 Aug 2022 984 Views

VMware urges admins to patch critical auth bypass bug immediately

VMware has warned admins today to patch a critical authentication bypass security flaw affecting local domain users in multiple products and enabling unauthenticated attackers to gain admin privileges.
Bleepingcomputer 3 Aug 2022 1147 Views

Bot army risk as 3,000+ apps found spilling Twitter API keys

Please stop leaving credentials where miscreants can find them Want to build your own army? Engineers at CloudSEK have published a report on how to do just that in terms of bots and Twitter, thanks to API keys leaking from applications.…
The Register 2 Aug 2022 2824 Views

Facebook ads push Android adware with 7 million installs on Google Play

Several adware apps promoted aggressively on Facebook as system cleaners and optimizers for Android devices are counting millions of installations on Google Play store. [...]
Bleepingcomputer 30 Jul 2022 1351 Views