Cybercriminals Exploit Free Software to Deploy Malware
Threat actors are using free software as a bait to distribute malware, targeting unsuspecting consumers with pirated versions of popular software, deploying the Hijack Loader malware and Vidar Stealer information stealer through DLL side-loading techniques and AutoIt scripts, bypassing User Account Control and exploiting the CMSTPLUA COM interface for privilege escalation, ultimately adding itself to Windows Defender’s exclusion list for defense evasion, stealing sensitive credentials from web browsers, installing a bitcoin miner on compromised hosts, and utilizing ClearFake, TA571 malspam, ClickFix, Matanbuchus, DarkGate, SolarMarker, Lumma Stealer, Amadey Loader, XMRig miner, and clipper malware in various campaigns.
View full story…
VMware Addresses Critical Vulnerabilities in vSphere and Cloud Foundation Products
VMware has patched critical vulnerabilities in its vSphere and Cloud Foundation products, including heap-overflow flaws in the DCE/RPC protocol and a local privilege escalation issue in vCenter, with fixes released by Broadcom.
View full story…
Signal Foundation Criticizes EU’s Proposed “Upload Moderation” for Encrypted Chats
Signal Foundation’s Meredith Whittaker voices concerns over the EU’s “Chat Control” law, warning of potential impact on encryption and privacy.
View full story…
Latest Cybernews
Meta Pauses Training of AI Models Using Public Content in Europe Amid Privacy Concerns
Meta, the parent company of Facebook, Instagram, and WhatsApp, has decided to halt training its large language models with public content from adults in the EU and EEA due to regulatory pressure and privacy concerns.
View full story…
ASUS Issues Urgent Firmware Updates for Router Security Vulnerabilities
ASUS releases urgent firmware updates for multiple router models to address critical security vulnerabilities, including authentication bypass and buffer overflow flaws.
View full story…
Data Breach at Los Angeles County Department of Public Health Exposes Personal Information of Over 200,000 Individuals
A data breach at the Los Angeles County Department of Public Health compromised the personal information of over 200,000 individuals, including names, dates of birth, medical records, Social Security Numbers, and financial details, highlighting the importance of cybersecurity measures in protecting sensitive information.
View full story…
Hackers Exploit Legitimate Websites to Distribute BadSpace Windows Backdoor
A Windows backdoor known as BadSpace is being distributed through compromised websites posing as fake browser updates, posing a significant threat to user privacy and system security.
View full story…
Controversial Partnership Between JARI and Imperial College London Terminated Over Military Concerns
Partnership between JARI and Imperial College London, aimed at ocean modeling and machine learning, terminated due to concerns over potential military end-uses.
View full story…
Cyberattack on Synnovis Causes Disruption to NHS Services in South East London
Russian Qilin group orchestrates cyberattack on Synnovis, impacting over 800 operations and 700 appointments at NHS trusts in London.
View full story…
DataBee Introduces New Technologies for Enhanced Threat Monitoring and Zero Trust Implementation
DataBee, a product of Comcast Technology Solutions, has introduced new technologies and strategies to enhance threat monitoring and zero trust implementation in its DataBee Hive security platform.
View full story…
China-Linked Cyber Espionage Group Velvet Ant Targets Organizations in East Asia for Three Years
Velvet Ant, a cyber espionage group with ties to China, has been using legacy F5 BIG-IP devices to steal sensitive information from organizations in East Asia over a prolonged period.
View full story…
Latest Cybernews
Concerns raised about impact of deepfake content on UK general election integrity
Matthew Feeney, head of tech and innovation at the Centre for Policy Studies, warns of potential risks posed by deepfake content on social media platforms ahead of the upcoming UK general election.
View full story…
Kaspersky Report Reveals Critical Vulnerabilities in ZKTeco Biometric Access Systems
Kaspersky report identifies vulnerabilities in ZKTeco’s biometric access systems, allowing attackers to bypass verification processes, steal biometric data, and manipulate devices remotely.
View full story…