Category: News

Log4J-Related RCE Flaw in H2 Database Earns Critical Rating

Critical flaw in the H2 open-source Java SQL database are similar to the Log4J vulnerability, but do not pose a widespread threat.

Activision Files Unusual Lawsuit over Call of Duty Cheat Codes

Activision is suing to shut down the EngineOwning cheat-code site and hold individual developers and coders liable for damages.

Google Voice Authentication Scam Leaves Victims on the Hook

The FBI is seeing so much activity around malicious Google Voice activity, where victims are associated with fraudulent virtual phone numbers, that it sent out an alert this week.

Partially Unpatched VMware Bug Opens Door to Hypervisor Takeover

ESXi version 7 users are still waiting for a full fix for a high-severity heap-overflow security vulnerability, but Cloud Foundation, Fusion and Workstation users can go ahead and patch.

Apple iPhone Malware Tactic Causes Fake Shutdowns to Enable Spying

The ‘NoReboot’ technique is the ultimate in persistence for iPhone malware, preventing reboots and enabling remote attackers to do anything on the device while remaining completely unseen.

Attackers Exploit Flaw in Google Docs’ Comments Feature

A wave of phishing attacks identified in December targeting mainly Outlook users are difficult for both email scanners and victims to flag, researchers said.

1.1M Compromised Accounts Found at 17 Major Companies

The accounts fell victim to credential-stuffing attacks, according to the New York State AG.

‘Elephant Beetle’ Lurks for Months in Networks

The group blends into an environment before loading up trivial, thickly stacked, fraudulent financial transactions too tiny to be noticed but adding up to millions of dollars.

Uber Bug, Ignored for Years, Casts Doubt on Official Uber Emails

A simple-to-exploit bug that allows bad actors to send emails from Uber’s official system — skating past email security — went unaddressed despite multiple flagging by researchers.

Broward Breach Highlights Healthcare Supply-Chain Problems

More than 1.3 million patient records were stolen in the just-disclosed breach, which occurred back in October.