Skip to main content

Security News

Filter by:

Android SpyNote Attacks Electric and Water Public Utility Users in Japan

A smishing campaign is targeting Japanese Android users by posing as a power and water infrastructure company and luring victims to a phishing website to download the SpyNote malware.
Cyware News 21 Jul 2023 332 Views

Adobe emergency patch fixes new ColdFusion zero-day used in attacks

Adobe released an emergency ColdFusion security update that fixes critical vulnerabilities, including a fix for a new zero-day exploited in attacks. [...]
Bleepingcomputer 20 Jul 2023 5840 Views

Microsoft Relents, Offers Free Critical Logging to All 365 Customers

Industry pushback prompts Microsoft to drop premium pricing for access to cloud logging data.
Dark Reading 20 Jul 2023 383 Views

Cybersecurity firm Sophos impersonated by new SophosEncrypt ransomware

Cybersecurity vendor Sophos is being impersonated by a new ransomware-as-a-service called SophosEncrypt, with the threat actors using the company name for their operation. [...]
Bleepingcomputer 19 Jul 2023 408 Views

Hackers exploiting critical WordPress WooCommerce Payments bug

Hackers are conducting widespread exploitation of a critical WooCommerce Payments plugin to gain the privileges of any users, including administrators, on vulnerable WordPress installation. [...]
Bleepingcomputer 18 Jul 2023 375 Views

How AI-Augmented Threat Intelligence Solves Security Shortfalls

Researchers explore how overburdened cyber analysts can improve their threat intelligence jobs by using ChatGPT-like large language models (LLMs).
Dark Reading 18 Jul 2023 483 Views

Quick: Manually patch this Zimbra bug that's under attack

Smells like Russian cyber spies (again) A vulnerability in Zimbra's software is being exploited right now by miscreants to compromise systems and attack selected government organizations, experts reckon.…
The Register 18 Jul 2023 5530 Views

Chinese APT Cracks Microsoft Outlook Emails at 25 Government Agencies

Foreign state-sponsored actors likely had access to privileged state emails for weeks, thanks to a token validation vulnerability.
Dark Reading 13 Jul 2023 1054 Views

Critical RCE found in popular Ghostscript open-source PDF library

Ghostscript, an open-source interpreter for PostScript language and PDF files widely used in Linux, has been found vulnerable to a critical-severity remote code execution flaw. [...]
Bleepingcomputer 13 Jul 2023 1031 Views

Cisco Talos Reports Microsoft Windows Policy Loophole Being Exploited by Threat Actor

Learn how a malicious driver exploits a loophole in the Windows operating system to run at kernel level.
TechRepublic 12 Jul 2023 569 Views