Microsoft says Russian hackers are exploiting an ancient printer security flaw

Russian state-sponsored threat actors were observed abusing an old printer vulnerability to drop custom malware on target endpoints. The malware helped them exfiltrate sensitive data and login credentials. This is according to a new report from Microsoft Threat Intelligence, published earlier this week. As per the report, since mid-2019, a group known as Fancy Bear … Read more

A critical security flaw could affect thousands of WordPress sites

Hundreds of thousands of WordPress websites are vulnerable to a critical severity flaw which allows threat actors to upload malware to the site through a bug in a plugin.  As reported by BleepingComputer, Japan’s CERT recently found a critical severity flaw (9.8) in the Forminator plugin, built by WPMU DEV. The flaw, now tracked as … Read more

How to activate iPhone security feature

iPhone Stolen Device Protection offers increased safety for your accounts and financial information if someone steals your handset and its passcode. Here’s how to activate the security feature that debuted in iOS 17.3, and — more importantly — why you should do it now. Stolen Device Protection: How to activate You don’t have to take … Read more

Major Palo Alto security flaw is being exploited via Python zero-day backdoor

For weeks now, unidentified threat actors have been leveraging a critical zero-day vulnerability in Palo Alto Networks’ PAN-OS software, running arbitrary code on vulnerable firewalls, with root privilege.  Multiple security researchers have flagged the campaign, including Palo Alto Networks’ own Unit 42, noting a single threat actor group has been abusing a vulnerability called command … Read more

Cybersecurity teams suffer and need to improve security posture

Amid political headwinds and economic uncertainty, we find ourselves in a challenging time for business. The economy is being impacted by the combination of ongoing high inflation and limited GDP growth. Meanwhile, supply chains are being disrupted by international conflicts (e.g., Ukraine, Gaza and the Houthi insurgency) and the ongoing impact of Brexit. And so, … Read more

Google Messages could bring improved security measures for RCS

Last updated: April 10th, 2024 at 05:29 UTC+02:00 RCS is the successor to SMS and will soon see much broader adoption, as Apple is expected to bring RCS support to iPhones later this year. Ahead of its wider adoption, Google is adding some security measures to make RCS even more secure for users, and it … Read more

Thousands of Social Security numbers stolen from government firm

Hackers recently stole hundreds of thousands of social security numbers from an American consulting firm, with victims across the US possibly affected. Greylock McKinnon Associates (GMA) has filed a new report with the Office of the Maine Attorney General, and sent a breach notification email to affected individuals. In its filing, the company said that … Read more

Thousands of D-Link NAS devices have serious backdoor security issues

A high-severity vulnerability has been recently discovered in certain D-Link Network Attached Storage (NAS) instances which could be used to run malicious code, steal sensitive data, and mount denial-of-service (DoS) attacks. Cybersecurity researcher Netsecfish, who discovered the flaw, found multiple instances of D-Link’s NAS devices have an arbitrary command injection flaw in the “system” parameter, … Read more