North Korean hackers target Russian govt, defense orgs

[ad_1] Microsoft says North Korean hacking groups have breached multiple Russian government and defense targets since the start of the year. As the company claims in a report published today on threats from East Asia, the threat actors are taking…

ReadMore

Cisco BroadWorks impacted by critical authentication bypass flaw

[ad_1] A critical vulnerability impacting the Cisco BroadWorks Application Delivery Platform and Cisco BroadWorks Xtended Services Platform could allow remote attackers to forge credentials and bypass authentication. Cisco BroadWorks is a cloud communication services platform for businesses and consumers, while…

ReadMore

Iranian hackers breach US aviation org via Zoho, Fortinet bugs

[ad_1] Image: Midjourney State-backed hacking groups have breached a U.S. aeronautical organization using exploits targeting critical Zoho and Fortinet vulnerabilities, a joint advisory published by CISA, the FBI, and the United States Cyber Command (USCYBERCOM) revealed on Thursday. The threat…

ReadMore

Microsoft Paint in Windows 11 gets a background removal tool

[ad_1] Microsoft is rolling out a new version of the Paint application on Windows 11 Insider builds that can remove the background from any picture with the click of a button. The new version is currently rolling out to Windows…

ReadMore

CISA warns of critical Apache RocketMQ bug exploited in attacks

[ad_1] The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added to its catalog of known exploited vulnerabilities (KEV) a critical–severity issue tracked as CVE-2023-33246 that affects Apache’s RocketMQ distributed messaging and streaming platform. Multiple threat actors are possibly exploiting…

ReadMore

Google is enabling Chrome real-time phishing protection for everyone

[ad_1] Google announced today that it is deprecating the standard Google Chrome Safe Browsing feature and moving everyone to its Enhanced Safe Browsing feature in the coming weeks, bringing real-time phishing protection to all users while browsing the web. Since…

ReadMore

Apple zero-click iMessage exploit used to infect iPhones with spyware

[ad_1] Citizen Lab says two zero-days fixed by Apple today in emergency security updates were actively abused as part of a zero-click exploit chain to deploy NSO Group's Pegasus commercial spyware onto fully patched iPhones. The two bugs, tracked as…

ReadMore

Google Looker Studio abused in cryptocurrency phishing attacks

[ad_1] Cybercriminals are abusing Google Looker Studio to create counterfeit cryptocurrency phishing websites that phish digital asset holders, leading to account takeovers and financial losses. Google's Looker Studio (formerly Data Studio) is an online data conversion tool used for creating…

ReadMore

Apple discloses 2 new zero-days exploited to attack iPhones, Macs

[ad_1] Apple released emergency security updates to fix two new zero-day vulnerabilities exploited in attacks targeting iPhone and Mac users, for a total of 13 exploited zero-days patched since the start of the year. "Apple is aware of a report…

ReadMore

State hackers attack security researchers with new zero-day

[ad_1] Google's Threat Analysis Group (TAG) says North Korean state hackers are again targeting security researchers in attacks using at least one zero-day in an undisclosed popular software. Researchers attacked in this campaign are involved in vulnerability research and development,…

ReadMore