Hackers Targeting Servers Running Database Services for Mining Cryptocurrency

Security researchers have discovered multiple attack campaigns conducted by an established Chinese criminal group that operates worldwide, targeting database servers for mining cryptocurrencies, exfiltrating sensitive data and building a DDoS botnet.

Continue reading Hackers Targeting Servers Running Database Services for Mining Cryptocurrency

Hidden Backdoor Found In WordPress Captcha Plugin Affects Over 300,000 Sites

Buying popular plugins with a large user-base and using it for effortless malicious campaigns have become a new trend for bad actors.

One such incident happened recently when the renowned developer BestWebSoft sold a popular Captcha WordPress plugin t… Continue reading Hidden Backdoor Found In WordPress Captcha Plugin Affects Over 300,000 Sites

Kaspersky Lab Sues U.S. Government Over Software Ban

Moscow-based cyber security firm Kaspersky Lab has taken the United States government to a U.S. federal court for its decision to ban the use of Kaspersky products in federal agencies and departments.

In September 2017, the United States Department of… Continue reading Kaspersky Lab Sues U.S. Government Over Software Ban

Two Critical 0-Day Remote Exploits for vBulletin Forum Disclosed Publicly

Security researchers have discovered and disclosed details of two unpatched critical vulnerabilities in a popular internet forum software—vBulletin—one of which could allow a remote attacker to execute malicious code on the latest version of vBulletin … Continue reading Two Critical 0-Day Remote Exploits for vBulletin Forum Disclosed Publicly

Pre-Installed Password Manager On Windows 10 Lets Hackers Steal All Your Passwords

If you are running Windows 10 on your PC, then there are chances that your computer contains a pre-installed 3rd-party password manager app that lets attackers steal all your credentials remotely.

Starting from Windows 10 Anniversary Update (Version 1… Continue reading Pre-Installed Password Manager On Windows 10 Lets Hackers Steal All Your Passwords

Zero-Day Remote ‘Root’ Exploit Disclosed In AT&T DirecTV WVB Devices

Security researchers have publicly disclosed an unpatched zero-day vulnerability in the firmware of AT&T DirecTV WVB kit after trying to get the device manufacturer to patch this easy-to-exploit flaw over the past few months.

The problem is with a… Continue reading Zero-Day Remote ‘Root’ Exploit Disclosed In AT&T DirecTV WVB Devices

Password Stealing Apps With Over A Million Downloads Found On Google Play Store

Even after so many efforts by Google like launching bug bounty program and preventing apps from using Android accessibility services, malicious applications somehow manage to get into Play Store and infect people with malicious software.

The same happ… Continue reading Password Stealing Apps With Over A Million Downloads Found On Google Play Store

ROBOT Attack: 19-Year-Old Bleichenbacher Attack On Encrypted Web Reintroduced

A 19-year-old vulnerability has been re-discovered in the RSA implementation from at least 8 different vendors—including F5, Citrix, and Cisco—that can give man-in-the-middle attackers access to encrypted messages.

Dubbed ROBOT (Return of Bleichenbach… Continue reading ROBOT Attack: 19-Year-Old Bleichenbacher Attack On Encrypted Web Reintroduced

Google Researcher Releases iOS Exploit—Could Enable iOS 11 Jailbreak

As promised last week, Google’s Project Zero researcher Ian Beer now publicly disclosed an exploit that works on almost all 64-bit Apple devices running iOS 11.1.2 or earlier, which can be used to build an iOS jailbreak, allowing users to run apps from… Continue reading Google Researcher Releases iOS Exploit—Could Enable iOS 11 Jailbreak