Skip to main content

Security News

Filter by:

Ivanti discloses new critical auth bypass bug in MobileIron Core

IT software company Ivanti disclosed today a new critical security vulnerability in its MobileIron Core mobile device management software.
Bleepingcomputer 3 Aug 2023 491 Views

Russian hackers target govt orgs in Microsoft Teams phishing attacks

Microsoft says a hacking group tracked as APT29 and linked to Russia's Foreign Intelligence Service (SVR) targeted dozens of organizations worldwide, including government agencies, in Microsoft Teams phishing attacks.
Bleepingcomputer 3 Aug 2023 476 Views

Canon Inkjet Printers at Risk for Third-Party Compromise via Wi-Fi

Nearly 200 models are affected by vulnerability that may give wireless access to unauthorized third parties.
Dark Reading 2 Aug 2023 469 Views

Threat actors abuse Google AMP for evasive phishing attacks

Security researchers are warning of increased phishing activity that abuses Google Accelerated Mobile Pages (AMP) to bypass email security measures and get to inboxes of enterprise employees. [...]
Bleepingcomputer 2 Aug 2023 490 Views

Google: Android patch gap makes n-days as dangerous as zero-days

Google has published its annual -day vulnerability report, presenting in-the-wild exploitation stats from 2022 and highlighting a long-standing problem in the Android platform that elevates the value and use of disclosed flaws for extended periods. [...]
Bleepingcomputer 30 Jul 2023 534 Views

Israel's largest oil refinery website offline after DDoS attack

Website of Israel's largest oil refinery operator, BAZAN Group is inaccessible from most parts of the world as threat actors claim to have hacked the Group's cyber systems. [...]
Bleepingcomputer 30 Jul 2023 577 Views

Linux version of Abyss Locker ransomware targets VMware ESXi servers

The Abyss Locker operation is the latest to develop a Linux encryptor to target VMware's ESXi virtual machines platform in attacks on the enterprise. [...]
Bleepingcomputer 29 Jul 2023 496 Views

Hackers Target Apache Tomcat Servers for Mirai Botnet and Crypto Mining

Misconfigured and poorly secured Apache Tomcat servers are being targeted as part of a new campaign designed to deliver the Mirai botnet malware and cryptocurrency miners.
The Hacker News 28 Jul 2023 716 Views

New Malvertising Campaign Distributing Trojanized IT Tools via Google and Bing Search Ads

A new malvertising campaign has been observed leveraging ads on Google Search and Bing to target users seeking IT tools like AnyDesk, Cisco AnyConnect VPN, and WinSCP, and trick them into downloading trojanized installers with an aim to breach enterprise networks and likely carry out future ransomware...
The Hacker News 28 Jul 2023 712 Views

Zimbra patches zero-day vulnerability exploited in XSS attacks

Two weeks after the initial disclosure, Zimbra has released security updates that patch a zero-day vulnerability exploited in attacks targeting Zimbra Collaboration Suite (ZCS) email servers.
Bleeping Computer 28 Jul 2023 683 Views