Malicious actors are using the massive supply of previously stolen login credentials to help brute force their way into high-profile cloud-based business systems that cannot easily use two-factor authentication for security. Proofpoint researchers found the availability of these tools has powered a massive increase in the number of cloud attacks taking place which in turn enable the attackers to possibly ...
Read More »Cyber Security News
RSAC 2019: For Domestic Abuse, IoT Devices Pose New Threat
When it comes to domestic abuse, smart products around the house are turning into new threats, a panel of experts said at RSA. SAN FRANCISCO – The influx of connected products in the home – from smart thermometers to connected locks – presents a disturbing new threat surface for victims of domestic abuse. That’s what Lisa Green, senior director of ...
Read More »Software maker Citrix hacked, business documents removed
Acting on a tip from the FBI, Citrix has investigated and confirmed that its network has been penetrated and data had been exfiltrated by an outside force. Neither the extent of nor the specifics of what has been removed has been determined, but in a statement Citrix said business documents have been accessed and downloaded by malicious actors. The FBI contacted Citrix ...
Read More »Another Windows zero-day vulnerability revealed by Google
The security vulnerability is said to affect Windows 7 systems particularly those with the 32-bit version. This flaw leads to a privilege escalation in the Windows kernel driver allowing malicious components to evade security sandbox. Right after a Chrome security flaw was fixed by Google, another vulnerability existing in Microsoft’s Windows was disclosed by the tech giant. According to Google’s ...
Read More »Minnesota man admits to hacking government databases
A man from Minnesota, Cameron Thomas Crowley, admitted on March 7, 2019, that he hacked state government databases in 2017. Crowley also admitted that he hacked databases belonging to the Minnesota government, a second university, and an unnamed school district. What is the issue – A man from Minnesota, Cameron Thomas Crowley, admitted on March 7, 2019, that he hacked state ...
Read More »End of the Line for Windows 7: Open Road for Hackers
Microsoft has been urging customers to upgrade from its Windows 7 operating system, while attempting to ease the transition with several options for extended support. It will stop providing routine fixes and security patches effective January 2020. Regular support for Windows Server 2008 also is scheduled to end at that time. Windows 7 enterprise customers can subscribe to Extended Security ...
Read More »Google reveals Chrome zero-day vulnerability was under active attacks at the time of patch
The vulnerability is a use-after-free vulnerability, a type of memory error that allows an app to access memory after it has been deleted from Chrome’s allocated memory. Google Chrome users are advised to update to Google Chrome version 72.0.3626.121. Google disclosed that the zero-day vulnerability that was patched on March 1, 2019, was under active attacks at the time of ...
Read More »Hackers Revive Microsoft Office Equation Editor Exploit
Hackers used specially-crafted Microsoft Word documents during the last few months to abuse an Integer Overflow bug that helped them bypass sandbox and anti-malware solutions and exploit the Microsoft Office Equation Editor vulnerability patched 15 months ago. According to Microsoft’s security advisory, this memory corruption vulnerability tracked as CVE-2017-11882 impacts unpatched Microsoft Office 2007 Service Pack 3, Microsoft Office 2010 Service Pack 2, Microsoft Office 2013 Service Pack 1, ...
Read More »Security bug in Joomla hands cybercriminals a playground for attack campaigns
Joomla is believed to still contain an old remote code execution (RCE) flaw in its platform. An attacker exploited this flaw and used malicious PHP code to compromise websites as well as bypassed the CMS’ mail service. Popular content management system (CMS) Joomla has been hit with new spam campaigns recently. As per a report by Check Point Research, a ...
Read More »Google revealed yesterday that a patch for Chrome last week was actually a fix for a zero-day that was under active attacks.
The attacks exploited CVE-2019-5786, a security flaw and the only patch included in the Chrome 72.0.3626.121 version, released last Friday, March 1, 2019. According to an update to its original announcement and a tweet from Google Chrome’s security lead, the patched bug was under active attacks at the time of the patch. Google described the security flaw as a memory management error in Google ...
Read More »