McMenamins Data Breach Affects 12 Years of Employee Info
The Pacific Northwest hospitality stalwart is also still operationally crippled by a Dec. 12 ransomware attack. Continue reading McMenamins Data Breach Affects 12 Years of Employee Info
Collaborate Disseminate
The Pacific Northwest hospitality stalwart is also still operationally crippled by a Dec. 12 ransomware attack. Continue reading McMenamins Data Breach Affects 12 Years of Employee Info
A look back at what was hot with readers in this second year of the pandemic. Continue reading The 5 Most-Wanted Threatpost Stories of 2021
The security vulnerability could expose passwords and access tokens, along with blueprints for internal infrastructure and finding software vulnerabilities. Continue reading 4-Year-Old Microsoft Azure Zero-Day Exposes Web App Source Code
A critical privilege-escalation vulnerability could lead to backdoors for admin access nesting in web servers. Continue reading All in One SEO Plugin Bug Threatens 3M Websites with Takeovers
There are 17,000npatched Log4j packages in the Maven Central ecosystem, leaving massive supply-chain risk on the table from Log4Shell exploits. Continue reading Java Code Repository Riddled with Hidden Log4j Bugs; Here’s Where to Look
A quarter-billion of those passwords were not seen in previous breaches that have been added to Have I Been Pwned. Continue reading Half-Billion Compromised Credentials Lurking on Open Cloud Server
Joker malware was found lurking in the Color Message app, ready to fleece unsuspecting users with premium SMS charges. Continue reading Malicious Joker App Scores Half-Million Downloads on Google Play
The discovery, which affects services running as localhost that aren’t exposed to any network or the internet, vastly widens the scope of attack possibilities. Continue reading Brand-New Log4Shell Attack Vector Threatens Local Hosts
“Owowa” stealthily lurks on IIS servers, waiting to harvest successful logins when an Outlook Web Access (OWA) authentication request is made. Continue reading Malicious Exchange Server Module Hoovers Up Outlook Credentials
December’s Patch Tuesday updates address six publicly known bugs and seven critical security vulnerabilities. Continue reading Actively Exploited Microsoft Zero-Day Allows App Spoofing, Malware Delivery