Category: News

PYSA Emerges as Top Ransomware Actor in November

Overtaking the Conti ransomware gang, PYSA finds success with government-sector attacks.

All in One SEO Plugin Bug Threatens 3M Websites with Takeovers

A critical privilege-escalation vulnerability could lead to backdoors for admin access nesting in web servers.

Critical Apache HTTPD Server Bugs Could Lead to RCE, DoS

Don’t freak: It’s got nothing to do with Log4Shell, except it may be just as far-reaching as Log4j, given HTTPD’s tendency to tiptoe into software projects.

Time to Ditch Big-Brother Accounts for Network Scanning

Yaron Kassner, CTO and co-founder of Silverfort, discusses why using all-seeing privileged accounts for monitoring is bad practice.

Four Bugs in Microsoft Teams Left Platform Vulnerable Since March

Attackers exploiting bugs in the “link preview” feature in Microsoft Teams could abuse the flaws to spoof links, leak an Android user’s IP address and launch a DoS attack.

Java Code Repository Riddled with Hidden Log4j Bugs; Here’s Where to Look

There are 17,000npatched Log4j packages in the Maven Central ecosystem, leaving massive supply-chain risk on the table from Log4Shell exploits.

Half-Billion Compromised Credentials Lurking on Open Cloud Server

A quarter-billion of those passwords were not seen in previous breaches that have been added to Have I Been Pwned.

Two Active Directory Bugs Lead to Easy Windows Domain Takeover

Microsoft is urging customers to patch two Active Directory domain controller bugs after a PoC tool was publicly released on Dec. 12.

FBI: Another Zoho ManageEngine Zero-Day Under Active Attack

APT attackers are using a security vulnerability in ManageEngine Desktop Central to take over servers, deliver malware and establish network persistence.

Conti Ransomware Gang Has Full Log4Shell Attack Chain

Conti has become the first professional-grade, sophisticated ransomware group to weaponize Log4j2, now with a full attack chain.