New Phorpiex Botnet Variant Steals Half a Million Dollars in Cryptocurrency

Cryptocurrency users in Ethiopia, Nigeria, India, Guatemala, and the Philippines are being targeted by a new variant of the Phorpiex botnet called Twizt that has resulted in the theft of virtual coins amounting to $500,000 over the last one year.
Isra… Continue reading New Phorpiex Botnet Variant Steals Half a Million Dollars in Cryptocurrency

Posted in Uncategorized

Hackers Begin Exploiting Second Log4j Vulnerability as a Third Flaw Emerges

Web infrastructure company Cloudflare on Wednesday revealed that threat actors are actively attempting to exploit a second bug disclosed in the widely used Log4j logging utility, making it imperative that customers move quickly to install the latest v… Continue reading Hackers Begin Exploiting Second Log4j Vulnerability as a Third Flaw Emerges

Posted in Uncategorized

Facebook to Pay Hackers for Reporting Data Scraping Bugs and Scraped Datasets

Meta Platforms, the company formerly known as Facebook, has announced that it’s expanding its bug bounty program to start rewarding valid reports of scraping vulnerabilities across its platforms as well as include reports of scraping data sets that ar… Continue reading Facebook to Pay Hackers for Reporting Data Scraping Bugs and Scraped Datasets

Posted in Uncategorized

Hackers Using Malicious IIS Server Module to Steal Microsoft Exchange Credentials

Malicious actors are deploying a previously undiscovered binary, an Internet Information Services (IIS) webserver module dubbed “Owowa,” on Microsoft Exchange Outlook Web Access servers with the goal of stealing credentials and enabling remote command… Continue reading Hackers Using Malicious IIS Server Module to Steal Microsoft Exchange Credentials

Posted in Uncategorized

Second Log4j Vulnerability (CVE-2021-45046) Discovered — New Patch Released

UPDATE — The severity score of CVE-2021-45046, originally classified as a DoS bug, has since been revised from 3.7 to 9.0, to reflect the fact that an attacker could abuse the vulnerability to send a specially crafted string that leads to “information… Continue reading Second Log4j Vulnerability (CVE-2021-45046) Discovered — New Patch Released

Posted in Uncategorized

Microsoft Issues Windows Update to Patch 0-Day Used to Spread Emotet Malware

Microsoft has rolled out Patch Tuesday updates to address multiple security vulnerabilities in Windows and other software, including one actively exploited flaw that’s being abused to deliver Emotet, TrickBot, or Bazaloader malware payloads.
The lates… Continue reading Microsoft Issues Windows Update to Patch 0-Day Used to Spread Emotet Malware

Posted in Uncategorized

Hackers Exploit Log4j Vulnerability to Infect Computers with Khonsari Ransomware

Romanian cybersecurity technology company Bitdefender on Monday revealed that attempts are being made to target Windows machines with a novel ransomware family called Khonsari as well as a remote access Trojan named Orcus by exploiting the recently di… Continue reading Hackers Exploit Log4j Vulnerability to Infect Computers with Khonsari Ransomware

Posted in Uncategorized