Category: News

The Uncertain Future of IT Automation

While IT automation is growing, big challenges remain. Chris Hass, director of information security and research at Automox, discusses how the future looks.

Zero-Click Flaws in Widely Used UPS Devices Threaten Critical Infratructure

The ‘TLStorm’ vulnerabilities, found in APC Smart-UPS products, could allow attackers to cause both cyber and physical damage by taking down critical infrastructure.

Bug in the Linux Kernel Allows Privilege Escalation, Container Escape

A missing check allows unprivileged attackers to escape containers and execute arbitrary commands in the kernel.

Novel Attack Turns Amazon Devices Against Themselves

Researchers have discovered how to remotely manipulate the Amazon Echo through its own speakers.

Samsung Confirms Lapsus$ Ransomware Hit, Source Code Leak

The move comes just a week after GPU-maker NVIDIA was hit by Lapsus$ and every employee credential was leaked.

Nvidia’s Stolen Code-Signing Certs Used to Sign Malware

Nvidia certificates are being used to sign malware, enabling malicious programs to pose as legitimate and slide past security safeguards on Windows machines.

Critical Firefox Zero-Day Bugs Allow RCE, Sandbox Escape

Both vulnerabilities are use-after-free issues in Mozilla’s popular web browser.

Massive Meris Botnet Embeds Ransomware Notes from REvil

Notes threatening to tank targeted companies’ stock price were embedded into the DDoS ransomware attacks as a string_of_text directed to CEOs and webops_geeks in the URL.

Free HermeticRansom Ransomware Decryptor Released

Cruddy cryptography means victims whose files have been encrypted by the Ukraine-tormenting ransomware can break the chains without paying extortionists.

Phishing Campaign Targeted Those Aiding Ukraine Refugees

A military email address was used to distribute malicious email macros among EU personnel helping Ukrainians.