Skip to main content

Security News

Filter by:

Telegram Fixes Windows App Zero-Day Used to Launch Python Scripts

A proof of concept exploit was shared on the XSS hacking forum explaining that a typo in the source code for Telegram for Windows could be exploited to send Python .pyzw files that bypass security warnings when clicked.
Cyware News 13 Apr 2024 272 Views

Palo Alto Networks Warns Of Exploited Firewall Vulnerability

Packet Storm 12 Apr 2024 25895 Views

New Spectre v2 attack impacts Linux systems on Intel CPUs

Researchers have demonstrated the "first native Spectre v2 exploit" for a new speculative execution side-channel flaw that impacts Linux systems running on many modern Intel processors. [...]
Bleepingcomputer 11 Apr 2024 347 Views

Notepad++ wants your help in "parasite website" shutdown

The Notepad++ project is seeking the public's help in taking down a copycat website that closely impersonates Notepad++ but is not affiliated with the project. There is some concern that it could pose security threats—for example, if it starts...
Bleepingcomputer 8 Apr 2024 403 Views

Hackers Exploit Magento Bug to Steal Payment Data from E-commerce Websites

Threat actors have been found exploiting a critical flaw in Magento to inject a persistent backdoor into e-commerce websites. The attack leverages CVE-2024-20720 (CVSS score: 9.1), which has been described by Adobe as a case of "...
The Hacker News 6 Apr 2024 9584 Views

Over 92,000 exposed D-Link NAS devices have a backdoor account

A threat researcher has disclosed a new arbitrary command injection and hardcoded backdoor flaw in multiple end-of-life D-Link Network Attached Storage (NAS) device models. [...]
Bleepingcomputer 6 Apr 2024 396 Views

Hosting firm's VMware ESXi servers hit by new SEXi ransomware

Chilean data center and hosting provider IxMetro Powerhost has suffered a cyberattack at the hands of a new ransomware gang known as SEXi, which encrypted the company's VMware ESXi servers and backups.
Bleeping Computer 5 Apr 2024 663 Views

New HTTP/2 DoS attack can crash web servers with a single connection

Newly discovered HTTP/2 protocol vulnerabilities called "CONTINUATION Flood" can lead to denial of service (DoS) attacks, crashing web servers with a single TCP connection in some implementations.
Bleeping Computer 5 Apr 2024 526 Views

Parental control app exposes live GPS locations of kids on internet

KidSecurity, a popular parental control app, has leaked sensitive information about children for the second time, this time exposing GPS locations and private messages on minors’ devices.
CyberNews 5 Apr 2024 12280 Views

Google agrees to delete Chrome browsing data of 136 million users

Google has agreed to delete billions of data records collected from 136 million Chrome users in the United States, as part of a lawsuit settlement regarding alleged undisclosed browser data collection while in Incognito mode. [...]
Bleepingcomputer 3 Apr 2024 558 Views