information security news

Iran-linked Seedworm APT targets Telecoms organizations across the Middle East and AsiaIran-linked Seedworm APT targets Telecoms organizations across the Middle East and Asia

Iran-linked Seedworm APT targets Telecoms organizations across the Middle East and Asia

Researchers uncovered a new Seedworm campaign targeting telecommunication and IT service providers in the Middle East and Asia. Iran-linked APT…

4 years ago
DHS announces its ‘Hack DHS’ bug bounty programDHS announces its ‘Hack DHS’ bug bounty program

DHS announces its ‘Hack DHS’ bug bounty program

The DHS has launched a new bug bounty program dubbed 'Hack DHS' to discover security vulnerabilities in external DHS systems.…

4 years ago
Adobe addresses over 60 vulnerabilities in multiple productsAdobe addresses over 60 vulnerabilities in multiple products

Adobe addresses over 60 vulnerabilities in multiple products

Adobe warns of threat actors that could exploit critical vulnerabilities in multiple products running on Windows and macOS systems. Adobe…

4 years ago
Hackers exploit Log4Shell to drop Khonsari Ransomware on Windows systemsHackers exploit Log4Shell to drop Khonsari Ransomware on Windows systems

Hackers exploit Log4Shell to drop Khonsari Ransomware on Windows systems

Bitdefender researchers discovered that threat actors are attempting to exploit the Log4Shell flaw to deliver the new Khonsari ransomware on Windows…

4 years ago
US CISA orders federal agencies to fix Log4Shell by December 24thUS CISA orders federal agencies to fix Log4Shell by December 24th

US CISA orders federal agencies to fix Log4Shell by December 24th

US CISA ordered federal agencies to address the critical Log4Shell vulnerability in the Log4j library by December 24th, 2021. US…

4 years ago
Google fixed the 17th zero-day in Chrome since the start of the yearGoogle fixed the 17th zero-day in Chrome since the start of the year

Google fixed the 17th zero-day in Chrome since the start of the year

Google has released Chrome 96.0.4664.110 to address a high-severity zero-day vulnerability, tracked as CVE-2021-4102, exploited in the wild. Google released security updates to address…

4 years ago
TinyNuke banking malware targets French organizationsTinyNuke banking malware targets French organizations

TinyNuke banking malware targets French organizations

The TinyNuke malware is back and now was used in attacks aimed at French users working in manufacturing, technology, construction, and…

4 years ago
Practical coexistence attacks on billions of WiFi chips allow data theft and traffic manipulationPractical coexistence attacks on billions of WiFi chips allow data theft and traffic manipulation

Practical coexistence attacks on billions of WiFi chips allow data theft and traffic manipulation

Boffins discovered bugs in WiFi chips that can be exploited to extract passwords and manipulate traffic by targeting a device's…

4 years ago
Log4Shell was in the wild at least nine days before public disclosureLog4Shell was in the wild at least nine days before public disclosure

Log4Shell was in the wild at least nine days before public disclosure

Threat actors are already abusing Log4Shell vulnerability in the Log4j library for malicious purposes such as deploying malware. A few…

4 years ago
Two Linux botnets already exploit Log4Shell flaw in Log4jTwo Linux botnets already exploit Log4Shell flaw in Log4j

Two Linux botnets already exploit Log4Shell flaw in Log4j

Immediately after the disclosure of the Log4Shell flaw in Log4j library threat actors started including the exploit code in Linux…

4 years ago