Security researchers have spotted a malware strain targeting WordPress sites that includes some pretty clever self-preservation techniques, such as removing competing malware and updating the victim’s site. Named BabaYaga, this malware strain isn’t new, but recent updates have transformed this former low-key player into a considerable foe for WordPress site […]
Hacking
Russia-linked Sofacy APT group adopts new tactics and tools in last campaign
Sofacy APT group (APT28, Pawn Storm, Fancy Bear, Sednit, Tsar Team, and Strontium) continues to operate and thanks to rapid and continuously changes of tactics the hackers are able to remain under the radar. According to experts from Palo Alto Networks, the hackers also used new tools in recent attacks, recently the APT group has shifted focus in […]
Adobe fixed the CVE-2018-5002 Flash Zero-Day exploited in targeted attacks in the Middle East
Adobe has recently fixed several vulnerabilities, including the CVE-2018-5002 Flash Zero-Day exploited in targeted attacks in the Middle East Adobe has released security updates for Flash Player that address four vulnerabilities, including a critical issue (CVE-2018-5002) that has been exploited in targeted attacks mainly aimed at entities in the Middle […]
Are Wi-Fi hotspots in World Cup Russia host cities secure?
Experts at Kaspersky Lab have evaluated the security of 32,000 public Wi-Fi hotspots in the 11 Russian cities hosting the World Cup. The upcoming soccer World Cup represents a privileged target for crooks, hackers, and nation-state actors. It is essential for organizations to take care of any aspect related to […]
Prowli Operation – Crooks already compromised over 40,000 servers and IoT Devices
Crooks have infected over 40,000 web servers, modems, and other IoT devices with the Prowli malware as part of a cryptocurrency mining campaign and to redirect victims to malicious sites. The Prowli malware was spotted by researchers at GuardiCore, attackers composed the huge botnet by exploiting known vulnerabilities and brute-force […]
VPNFilter Can Also Infect ASUS, D-Link, Huawei, Ubiquiti, UPVEL, and ZTE Devices
The VPNFilter malware that infected over 500,000 routers and NAS devices across 54 countries during the past few months is much worse than previously thought. According to new research technical details published today by the Cisco Talos security team, the malware —which was initially thought to be able to infect […]
HR Software company PageUp victim of a Data Breach, experts fear a domino effect
HR Software Firm PageUp is the last victim of a data breach, the company has 2.6 million active users across over 190 countries. Another day another data breach makes the headlines, this time the victim is the HR Software Firm PageUp. PageUp is an Australian company with 2.6 million active users across […]
Hackers Target Travel Firm to Plunder Hundreds of Thousands from Clients
The Cyber criminals have now targeted a travel firm Booking.com in an offer to plunder hundreds and thousands of pounds from clients. The clients were sent WhatsApp and text messages asserting a security break that implied that they needed to change their password. Be that as it may, the link […]
The cyberattack on banks in Mexico: The challenges posed to cybersecurity
Toward the end of April 2018, it was revealed that Mexico’s financial system was the victim of a cyberattack in which cybercriminals stole over 300 million pesos. Initially, the Interbank Electronic Payment System (SPEI) of the Bank of Mexico began reporting some abnormalities in the interbank transfer service. And although initially it was not […]
‘Zip Slip’ arbitrary file overwrite vulnerability affects thousands of projects
Security experts from British software firm Snyk have discovered a critical vulnerability, dubbed ‘Zip Slip’ that affects thousands of projects across many industries. The flaw, that remained hidden for years, could be exploited by attackers to execute arbitrary code on the vulnerable systems. The Zip Slip is an arbitrary file overwrite […]