17 Jan

From Email to RAT: Deciphering a VBS Script-Driven Campaign

Authored by Preksha Saxena and Yashvi Shah McAfee Labs has been tracking a sophisticated VBS campaign characterized by obfuscated Visual Basic Scripting (VBS). Initially delivering

Author rabih
17 Jan

What’s worse than paying an extortion bot that auto-pwned your database?

Publicly exposed PostgreSQL and MySQL databases with weak passwords are being autonomously wiped out by a malicious extortion bot – one that marks who pays

Author rabih
17 Jan

Windows Server 2022 patch is breaking apps for some users

The latest Windows Server 2022 patch has broken the Chrome browser, and short of uninstalling the update, a registry hack is the only way to

Author rabih
17 Jan

Is Temu safe? What to know before you ‘shop like a billionaire’

Scams, Digital Security Here are some scams you may encounter on the shopping juggernaut, plus a few simple steps you can take to help safeguard

Author rabih
17 Jan

Home improvement marketers dial up trouble from regulator

Another week and yet another couple of pesky cold callers face fines from the UK’s data privacy watchdog for “bombarding” unsuspecting households with marketing messages

Author rabih
17 Jan

Combination of cheap .cloud domains and fake Shark Tank news fuel unhealthy wellness scams

Scammers are buying up cheap domain names to host sites that sell dodgy health products using fake articles, according to cybercrime disruption outfit Netcraft. The

Author rabih
17 Jan

Nokia walks the walk about its RAN to play on Uncle Sam’s China fears

Comment A vendor establishing a business unit dedicated to government sales is not new or unusual. But Finnish telecommunications giant Nokia’s decision to do so

Author rabih
17 Jan

FBI: Beware of thieves building Androxgh0st botnets using stolen creds

Crooks are exploiting years-old vulnerabilities to deploy Androxgh0st malware and build a cloud-credential stealing botnet, according to the FBI and the Cybersecurity and Infrastructure Security

Author rabih
16 Jan

Patch now: Critical VMware, Atlassian flaws found

VMware and Atlassian today disclosed critical vulnerabilities and, while neither appear to have been exploited by miscreants yet, admins should patch now to avoid disappointment.

Author rabih
16 Jan

Double trouble for VMware and Atlassian admins – critical flaws to fix

VMware and Atlassian today disclosed critical vulnerabilities and, while neither appear to have been exploited by miscreants yet, admins should patch now to avoid disappointment.

Author rabih
16 Jan

More than 178,000 SonicWall firewalls are exposed to old denial of service bugs

More than 178,000 SonicWall firewalls are still vulnerable to years-old vulnerabilities, an infosec reseacher claims. A study by Jon Williams, senior security engineer at Bishop

Author rabih
16 Jan

Ivanti zero-day exploits explode as bevy of attackers get in on the act

There’s a “reasonable chance” that Ivanti Connect Secure (ICS) VPN users are already compromised if they didn’t apply the vulnerability mitigation released last week, experts

Author rabih
16 Jan

The 7 deadly cloud security sins and how SMBs can do things better

Business Security By eliminating these mistakes and blind spots, your organization can take massive strides towards optimizing its use of cloud without exposing itself to

Author rabih
16 Jan

China’s gambling crackdown spawned wave of illegal online casinos and crypto-crime in Asia

Global crime networks have set up shop in autonomous territories run by armed gangs across Southeast Asia, and are using them to host physical and

Author rabih
15 Jan

Thousands of Juniper Networks devices vulnerable to critical RCE bug

More than 11,500 Juniper Networks devices are exposed to a new remote code execution (RCE) vulnerability, and infosec researchers are pressing admins to urgently apply

Author rabih
15 Jan

Patch time: Critical GitLab vulnerability exposes 2FA-less users to account takeovers

GitLab admins should apply the latest batch of security patches pronto given the new critical account-bypass vulnerability just disclosed. Tracked as CVE-2023-7028, the maximum-severity bug

Author rabih
15 Jan

FTC secures first databroker settlement banning sale of sensitive location data

Infosec in brief The US Federal Trade Commission has secured its first data broker settlement agreement, prohibiting X-Mode Social from sharing or selling sensitive location

Author rabih
15 Jan

Honoring Martin Luther King Jr.’s Legacy with McAfee’s African Heritage Community

Today, we celebrate the life and legacy of Dr. Martin Luther King Jr. Dr. King diligently dedicated his life to dismantling systemic racism affecting marginalized

Author rabih
Load moreLoadingAll items loaded