Moobot has been exploiting a critical flaw in Hikvision products, which were sanctioned by the U.S. in the wake of human rights abuse. The botnet is based...
The threat group, first identified in June, focuses solely on data exfiltration and subsequent extortion, and has already targeted 40 victims since September. There is a...
As many as 1.6 million WordPress sites have been targeted by an active large-scale attack campaign originating from 16,000 IP addresses by exploiting weaknesses in four...
The crafty Qakbot trojan has added ransomware delivery to its malware building blocks. Qakbot, a top trojan for stealing bank credentials, has in the past year...
Key Takeaways Vulnerabilities in Microsoft and others’ popular OAuth2.0 implementations lead to redirection attacks that bypass most phishing detection solutions and email security solutions. Proofpoint has...
Mozilla this week released security updates for the Firefox browser and Thunderbird mail client to address multiple vulnerabilities, including several bugs rated high severity. Firefox 95 started...
Key U.S. allies supported the effort but did not sign on to a joint statement committing to the creation of a code of conduct on how...
Officials in the public and private sectors warned of the need to enact a robust cybersecurity posture at the federal level ahead of growing ransomware and...
A Russian national has been sentenced to 48 months in prison for operating a “crypting” service used to conceal the Kelihos malware from antivirus software, enabling...
UPDATED The maintainers of popular Java logging library Apache Log4j have rushed out a patch for a critical vulnerability that could lead to remote code execution (RCE)...