Category: News

FIN7 Mailing Malicious USB Sticks to Drop Ransomware

The FBI warned that attackers are impersonating Health & Human Services and/or Amazon to mail BadUSB-poisoned USB devices to targets in transportation, insurance & defense.

‘Fully Undetected’ SysJoker Backdoor Malware Targets Windows, Linux & macOS

The malware establishes initial access on targeted machines, then waits for additional code to execute.

Critical SonicWall NAC Vulnerability Stems from Apache Mods

Researchers offer more detail on the bug, which can allow attackers to completely take over targets.

Millions of Routers Exposed to RCE by USB Kernel Bug

The high-severity RCE flaw is in the KCodes NetUSB kernel module, used by popular routers from Netgear, TP-Link, DLink, Western Digital, et al.

URL Parsing Bugs Allow DoS, RCE, Spoofing & More

Dangerous security bugs stemming from widespread inconsistencies among 16 popular third-party URL-parsing libraries could affect a wide swath of web applications.

Cyber-Spike: Orgs Suffer 925 Attacks per Week, an All-Time High

Cyberattacks increased 50 percent YoY in 2021 and peaked in December due to a frenzy of Log4j exploits, researchers found.

EoL Systems Stonewalling Log4j Fixes for Fed Agencies

End of life, end of support, pandemic-induced shipping delays and remote work, scanning failures: It’s a recipe for a patching nightmare, federal cyberserurity CTO Matt Keller says.

Cyberattackers Hit Data of 80K Fertility Patients

Fertility Centers of Illinois’ security measures protected electronic medical records, but the attackers still got at extremely intimate data in admin files.

3.7M FlexBooker Records Dumped on Hacker Forum

Attackers are trading millions of records from a trio of pre-holiday breaches on an online forum.

QNAP: Get NAS Devices Off the Internet Now

There are active ransomware and brute-force attacks being launched against internet-exposed, network-attached storage devices, the device maker warned.