Category: News

Working Exploit Is Out for VMware vCenter CVE-2021-22005 Flaw

The unredacted RCE exploit allows unauthenticated, remote attackers to upload files to the vCenter Server analytics service.

SolarWinds Attackers Hit Active Directory Servers with FoggyWeb Backdoor

Microsoft is warning that the Nobelium APT is compromising single-sign-on servers to install a post-exploitation backdoor that steals data and maintains network persistence.

Credential Spear-Phishing Uses Spoofed Zix Encrypted Email

The spoofed email has targeted close to 75K inboxes, slipping past spam and security controls across Office 365, Google Workspace, Exchange, Cisco ESA and more.

5 Steps to Securing Your Network Perimeter

Ekaterina Kilyusheva, head of the Information Security Analytics Research Group at Positive Technologies, offers a blueprint for locking up the fortress.

Women, Minorities Are Hacked More Than Others

Income level, education and being part of a disadvantaged population all contribute to cybercrime outcomes, a survey suggests.

EU: Russia Behind ‘Ghostwriter’ Campaign Targeting Germany

It’s not the first time that the disinformation/spearphishing campaign, which originally smeared NATO, has been linked to Russia.

3.8 Billion Users’ Combined Clubhouse, Facebook Data Up for Sale

Combined cache of data likely to fuel rash of account takeover, smishing attacks, experts warn.  

Exchange/Outlook Autodiscover Bug Spills $100K+ Email Passwords

Hundreds of thousands of email credentials, many of which double as Active Directory domain credentials, came through to credential-trapping domains in clear text.

TangleBot Malware Reaches Deep into Android Device Functions

The mobile baddie grants itself access to almost everything, enabling spying, data-harvesting, stalking and fraud attacks, among others.

Critical Cisco Bugs Allow Code Execution on Wireless, SD-WAN

Unauthenticated cyberattackers can also wreak havoc on networking device configurations.