Skip to main content

Security News

Filter by:

QNAP warns severe Linux bug affects most of its NAS devices

Taiwanese hardware vendor QNAP warns most of its Network Attached Storage (NAS) devices are impacted by a high severity Linux vulnerability dubbed 'Dirty Pipe' that allows attackers with local access to gain root privileges.
BleepingComputer 15 Mar 2022 495 Views

Russian Pushing New State-run TLS Certificate Authority to Deal With Sanctions

The Russian government has established its own TLS certificate authority (CA) to address issues with accessing websites that have arisen in the wake of sanctions imposed by the west following the country's unprovoked military invasion of Ukraine.
The Register 14 Mar 2022 463 Views

Corporate website contact forms used to spread BazarBackdoor malware

The stealthy BazarBackdoor malware is now being spread via website contact forms rather than typical phishing emails to evade detection by security software. [...]
Bleepingcomputer 11 Mar 2022 440 Views

Russia may try to dodge sanctions using ransomware payments, warns US Treasury

The Financial Crimes Enforcement Network has issued a statement for financial institutions to be aware of suspicious activity. The post Russia may try to dodge sanctions using ransomware payments, warns US Treasury appeared first on TechRepublic.
TechRepublic 11 Mar 2022 387 Views

WhatsApp emits extension to detect tampering with desktop web apps

Code Verify tool confers with Cloudflare to warn of any shenanigans WhatsApp and Cloudflare have teamed up to provide desktop users of WhatsApp's web client with a browser extension called Code Verify that checks the integrity of the software running in their browser.…
The Register 11 Mar 2022 7282 Views

Nearly 30% of critical WordPress plugin bugs don't get a patch

Patchstack, a leader in WordPress security and threat intelligence, has released a whitepaper to present the state of WordPress security in 2021, and the report paints a dire picture.
Bleepingcomputer 10 Mar 2022 411 Views

HP patches 16 UEFI firmware bugs allowing stealthy malware infections

HP has disclosed 16 high-impact UEFI firmware vulnerabilities that could allow threat actors to infect devices with malware that gain high privileges and remain undetectable by installed security software. [...]
Bleepingcomputer 9 Mar 2022 549 Views

TLStorm exploits expose more than 20 million UPS units to takeover. Was yours one of them?

APC-branded uninterruptible power supplies were found to be vulnerable to three zero day exploits that could let an attacker physically damage the UPS and attached assets, Armis said. The post TLStorm exploits expose more than 20 million UPS units to takeover. Was yours one of...
TechRepublic 9 Mar 2022 543 Views

Critical Bugs in TerraMaster TOS Could Open NAS Devices to Remote Hacking

Researchers have disclosed details of critical security vulnerabilities in TerraMaster network-attached storage (TNAS) devices that could be chained to attain unauthenticated remote code execution with the highest privileges.
The Hacker News 8 Mar 2022 475 Views

Leaked stolen Nvidia cert can sign Windows malware

An Nvidia code-signing certificate was among the mountain of files stolen and leaked online by criminals who ransacked the GPU giant's internal systems.
The Reg 7 Mar 2022 471 Views