April 22, 2021 Bloomberg Clients Targeted in Phishing Campaign Distributing Remote Access Trojans Remote Access Trojans (RATs) according to a new report published by researchers at Cisco Talos. The relatively few emails that have been intercepted have made ... Read more
April 21, 2021 Actively Exploited Zero Day Vulnerability Identified in Pulse Secure Connect VPN A critical zero-day vulnerability has been identified in Pulse Secure VPN appliances that is being actively exploited by a Chinese advanced persistent threat group. The ... Read more
April 20, 2021 Patch These Actively Exploited SonicWall Vulnerabilities Now! SonicWall has released patches to correct three actively exploited vulnerabilities in its on-premises and hosted email security solutions. The vulnerabilities can be exploited remotely to ... Read more
April 19, 2021 Google Project Zero Adds 30-Day Grace Period to Vulnerability Disclosure Policy Google Project Zero has added a new grace period to its zero-day vulnerability disclosure policy and will now provide an additional 30 days after a ... Read more
April 12, 2021 IcedID Malware Distribution Increases as it Vies to Become the New Emotet A massive malspam campaign is underway distributing the IcedID banking Trojan. The malicious emails have Microsoft Excel attachments, which use Excel 4 macros to deliver ... Read more
April 9, 2021 Collaboration Platforms Increasingly Abused by Threat Actors for Data Exfiltration and Malware Delivery Teleworking has been growing in popularity over the past few years, but the national lockdowns imposed by governments to limit the spread of COVID-19 forced ... Read more
April 8, 2021 New Malware Variant with Worm-Like Capabilities Spoofs Netflix and Spreads via WhatsApp A new malware variant has been discovered by security researchers at Check Point that has been added to a fake Netflix application – FlixOnline – ... Read more
March 26, 2021 Purple Fox Malware Now Has Worm Capabilities for Propagating Across Windows Machines A new variant of Purple Fox malware has been detected by researchers at Guardicore Labs that has achieved far greater success at infecting systems thanks ... Read more
March 23, 2021 Adobe Issues Out-of-Band Patch for Critical ColdFusion Vulnerability A patch has been issued to correct a critical vulnerability – CVE-2021-21087 – in Adobe ColdFusion that could be exploited by a remote attacker to ... Read more
March 16, 2021 Google Fixes Actively Exploited Zero Day Vulnerability in the Chrome Browser Google has patched a zero-day vulnerability in its Chrome browser for Mac, Windows, and Linux. The vulnerability, which is the second zero-day to be patched ... Read more
March 12, 2021 TrickBot Becomes Biggest Malware Threat Following Emotet Takedown The Emotet botnet was the biggest malware threat until a joint law enforcement operation succeeded in taking the botnet down. Emotet was primarily used as ... Read more
March 9, 2021 Microsoft Fixes 82 Vulnerabilities on March 2021 Patch Tuesday Including One Actively Exploited 0Day Flaw March 2021 Patch Tuesday saw Microsoft deliver patches for 82 vulnerabilities across its product range, including fixes for 10 critical flaws and 2 zero-day vulnerabilities ... Read more
March 4, 2021 Multiple Threat Groups Now Exploiting Microsoft Exchange Server Zero-Day Flaws Multiple threat groups have been observed exploiting the four zero-day vulnerabilities in Microsoft Exchange Server that were patched earlier this week. Microsoft announced the four ... Read more
March 3, 2021 Microsoft Releases Out of Band Security Updates to Fix Actively Exploited Microsoft Exchange Server Flaws Microsoft has released patches to correct four zero-day vulnerabilities in Microsoft Exchange Server that are currently being chained together and exploited by a sophisticated Chinese ... Read more
March 2, 2021 Spear Phishing Campaign by Lazarus APT Group Targeting Defense Companies Security researchers at Kaspersky ICS CERT have identified a spear phishing campaign targeting defense companies that delivers an advanced malware dubbed ThreatNeedle. The campaign has ... Read more
February 17, 2021 Malvertising Gang Exploited WebKit Zero Day to Redirect Web Visitors to Scam Sites An unpatched zero-day vulnerability in WebKit-based browsers has been exploited by a threat group to redirect website visitors to scam sites for at least 8 ... Read more
February 10, 2021 Adobe Patches 50 Vulnerabilities Including 1 Actively Exploited Adobe Reader Bug On February 2021 Patch Tuesday Adobe released patches to correct 50 vulnerabilities across its range of products, including 34 critical severity flaws, one of which ... Read more
January 27, 2021 Europol Announces Takedown of the Emotet Botnet Europol has announced that following a global operation by law enforcement and judicial authorities, the Emotet botnet has been disrupted and law enforcement agencies have ... Read more
January 26, 2021 UK Residents Warned of COVID-19 Vaccine Phishing Emails Seeking Financial Information UK residents are being warned about a new phishing campaign that spoofs the National Health Service (NHS) and asks recipients to confirm that they want ... Read more
January 22, 2021 Mistake with Phishing Campaign Saw Stolen Credentials Accessible Through Google Searches A mistake by the operators of a phishing campaign has resulted in stolen credentials being accessible through Google searches. Compromised WordPress sites were used to ... Read more
January 20, 2021 FreakOut Malware Campaign Targets Linux Devices A new malware variant is being used in attacks on Linux devices that sees the devices added to a botnet and used for cryptocurrency mining ... Read more
January 13, 2021 Microsoft Releases Patch for Actively Exploited Windows Defender Zero Day and 9 Other Critical Flaws The first Patch Tuesday of 2021 has seen Microsoft release patches to fix 83 vulnerabilities across its range of products, including one zero-day vulnerability in ... Read more
January 7, 2021 Hardcoded Password Vulnerability in Zyxel Devices Being Actively Exploited Cybercriminals have started exploiting the hardcoded credential vulnerability (CVE-2020-29583) in Zyxel networking products that was announced by Zyxel on December 23, 2020. The vulnerability, identified ... Read more
January 5, 2021 New PayPal Phishing Scam Advises Users via SMS that their Account has been Limited A new PayPal phishing scam is being conducted via SMS messages that informs users that their PayPal account has been permanently set to ‘limited’ status, ... Read more
December 21, 2020 More Than 3 Million Chrome and Edge Users Have Malware-Infected Browser Extensions Approximately 3 million users of Google Chrome and Microsoft Edge have been infected with malware that has been hidden in browser extensions, according to a ... Read more
December 18, 2020 Contact Form 7 Vulnerability Places 5 Million WordPress Sites at Risk of Takeover A critical vulnerability has been identified in the popular WordPress plugin, Contact Form 7, which has been installed on approximately 5 million websites. The vulnerability, ... Read more
December 15, 2020 Document Delivery Lure Used in Large Scale Spear Phishing Campaign Targeting Enterprise Employees Last week, researchers at Abnormal Security identified a coordinated phishing attack targeting enterprise employees that attempts to steal their Microsoft Office 365 credentials. The emails ... Read more
December 10, 2020 Spear Phishing Campaign Spoofing Microsoft.Com Sees Emails Delivered to Office 365 Inboxes Researchers at Israeli cybersecurity firm Ironscales have identified a spear phishing campaign targeting Office 365 users that spoofs the Microsoft.com domain. Several thousand Office 365 ... Read more
November 25, 2020 Patch MobileIron Vulnerability Immediately, Warns NCSC The UK National Cyber Security Centre (NCSC) has issued an alert that confirms Advanced Persistent Threat (APT) groups and cybercriminals are currently exploiting the MobileIron ... Read more
November 17, 2020 Malsmoke Campaign Delivers ZLoader Malware via Popups on High Traffic Adult Websites A malware distribution campaign identified by security researchers at Malwarebytes is now distributing a ZLoader malware variant via popups on popular adult websites. The campaign ... Read more