Hacking

Pierluigi Paganini January 09, 2021
Twitter has permanently suspended the account of President Donald Trump

Twitter has permanently suspended the account of President Donald Trump on Friday, due to the risk of further incitement of violence. Twitter has permanently suspended President Donald Trump’s account fearing his tweets may trigger a new wave of violence. In response to the attack on the U.S. Capitol, the President’s account was initially suspended for […]

Pierluigi Paganini January 08, 2021
Nvidia releases security updates for GPU display driver and vGPU flaws

Nvidia has released security updates to address high-severity vulnerabilities affecting the Nvidia GPU display driver and vGPU software.  Nvidia has addressed a total of 16 flaws, including high-severity vulnerabilities affecting the Nvidia GPU display driver and vGPU software.   The addressed flaws may lead to denial of service, escalation of privileges, data tampering, or information disclosure. […]

Pierluigi Paganini January 08, 2021
Welcome Bureau of Cyberspace Security and Emerging Technologies (CSET)

United States Department of State approved the creation of the Bureau of Cyberspace Security and Emerging Technologies (CSET). The United States Secretary of State Mike Pompeo approved the creation of the Bureau of Cyberspace Security and Emerging Technologies (CSET) that was first announced in 2019. The CSET Bureau was created to increase the resilience of […]

Pierluigi Paganini January 08, 2021
Unsecured Git server exposed Nissan North America

A misconfigured Git server is the root cause for the leak of source code of mobile apps and internal tools belonging to Nissan North America. A misconfigured Git server has caused the leak of the source code of mobile apps and internal software used by Nissan North America. The situation is embarrassing because the software […]

Pierluigi Paganini January 08, 2021
Ezuri memory loader used in Linux and Windows malware

Multiple threat actors have recently started using the Ezuri memory loader as a loader to executes malware directly into the victims’ memory. According to researchers from AT&T’s Alien Labs, malware authors are choosing the Ezuri memory loader for their malicious codes. The Ezuri memory loader tool allows to load and execute a payload directly into […]

Pierluigi Paganini January 07, 2021
Ryuk ransomware operations already made over $150M

The Ryuk ransomware had a disruptive impact on multiple industries around the world, operators already earned more than $150 million. The Ryuk ransomware gang is one of the most prolific criminal operations that caused destruction in multiple industries around the world. According to a joint report published by security firms Advanced-intel and HYAS, Ryuk operators […]

Pierluigi Paganini January 07, 2021
North Korea-linked APT37 targets South with RokRat Trojan

Experts spotted the RokRat Trojan being used by North Korea-linked threat actors in attacks aimed at the South Korean government. On December 7 2020 researchers from Malwarebytes uncovered a campaign targeting the South Korean government with a variant of the RokRat RAT. The experts found a malicious document uploaded to Virus Total related to a […]

Pierluigi Paganini January 07, 2021
Multiple flaws in Fortinet FortiWeb WAF could allow corporate networks to hack

An expert found multiple serious vulnerabilities in Fortinet’s FortiWeb web application firewall (WAF) that could expose corporate networks to hack. Andrey Medov, a security researcher at Positive Technologies, found multiple serious vulnerabilities in Fortinet’s FortiWeb web application firewall (WAF) that could be exploited by attackers to hack into corporate networks. The flaws, tracked as CVE-2020-29015, CVE-2020-29016, CVE-2020-29018, and […]

Pierluigi Paganini January 07, 2021
US Govt kicked off ‘Hack the Army 3.0’ bug bounty program

The U.S. government is going to launch the ‘Hack the Army 3.0’ bug bounty program in collaboration with the HackerOne platform. The U.S. government launched Hack the Army 3.0, the third edition of its bug bounty program, in collaboration with the HackerOne platform. The second Hack the Army bug bounty program ran between October 9 and November […]

Pierluigi Paganini January 06, 2021
SolarWinds hackers had access to roughly 3% of US DOJ O365 mailboxes

The US DoJ revealed that threat actors behind the SolarWinds attack have gained access to roughly 3% of the department’s O365 mailboxes. The US Department of Justice (DoJ) published a press release to confirm that the threat actors behind the SolarWinds supply chain attack were able to access thousands of mailboxes of its employees. “On […]