Category: Bleeping Computer

Joomla fixes XSS flaws that could expose sites to RCE attacks
22
Feb
2024

Joomla fixes XSS flaws that could expose sites to RCE attacks

Five vulnerabilities have been discovered in the Joomla content management system that could be leveraged to execute arbitrary code on…

Apple
22
Feb
2024

Fraudsters tried to scam Apple out of 5,000 iPhones worth over $3 million

Two Chinese nationals face 20 years in prison after being caught and convicted of submitting over 5,000 fake iPhones worth…

Hacker water
21
Feb
2024

US govt shares cyberattack defense tips for water utilities

CISA, the FBI, and the Environmental Protection Agency (EPA) shared a list of defense measures U.S. water utilities should implement…

ScreenConnect critical bug now under attack as exploit code emerges
21
Feb
2024

ScreenConnect critical bug now under attack as exploit code emerges

Both technical details and proof-of-concept exploits are available for the two vulnerabilities ConnectWise disclosed earlier this week for ScreenConnect, its…

US State Department
21
Feb
2024

US offers $15 million bounty for info on LockBit ransomware gang

The U.S. State Department is now also offering rewards of up to $15 million to anyone who can provide information…

Critical infrastructure software maker confirms ransomware attack   Bill   16:29
21
Feb
2024

Critical infrastructure software maker confirms ransomware attack

PSI Software SE, a German software developer for complex production and logistics processes, has confirmed that the cyber incident it disclosed…

Data points
21
Feb
2024

Ransomware Groups, Targeting Preferences, and the Access Economy

How do ransomware groups pick their targets? It’s a rhetorical question: in the vast majority of cases they don’t. Ransomware-as-a-service…

Signal Messenger
21
Feb
2024

Signal rolls out usernames that let you hide your phone number

End-to-end encrypted messaging app Signal finally allows users to pick custom usernames to connect with others while protecting their phone number…

New Migo malware disables security features on Redis servers
21
Feb
2024

New Migo malware disables protection features on Redis servers

Security researchers discovered a new campaign that targets Redis servers on Linux hosts using a piece of malware called ‘Migo’…

VoltSchemer attacks use wireless chargers to inject voice commands, fry phones
21
Feb
2024

VoltSchemer attacks use wireless chargers to inject voice commands, fry phones

A team of academic researchers show that a new set of attacks called ‘VoltSchemer’ can inject voice commands to manipulate a smartphone’s…

VMware
21
Feb
2024

VMware urges admins to remove deprecated, vulnerable auth plug-in

VMware urged admins today to remove a discontinued authentication plugin exposed to authentication relay and session hijack attacks in Windows domain…

Hacker
20
Feb
2024

ConnectWise urges ScreenConnect admins to patch critical RCE flaw

ConnectWise warned customers to patch their ScreenConnect servers immediately against a maximum severity flaw that can be used in remote…