Quantcast
Channel: PRSOL:CC
Browsing all 1816 articles
Browse latest View live

Image may be NSFW.
Clik here to view.

Hackers abuse WordPress MU-Plugins to hide malicious code

Hackers are utilizing the WordPress mu-plugins (“Must-Use Plugins”) directory to stealthily run malicious code on every page while evading detection. The technique was first observed by security...

View Article


Image may be NSFW.
Clik here to view.

Phishing platform ‘Lucid’ behind wave of iOS, Android SMS attacks

A phishing-as-a-service (PhaaS) platform named ‘Lucid’ has been targeting 169 entities in 88 countries using well-crafted messages sent on iMessage (iOS) and RCS (Android). Lucid, which has been...

View Article


Image may be NSFW.
Clik here to view.

Microsoft uses AI to find flaws in GRUB2, U-Boot, Barebox bootloaders

Microsoft used its AI-powered Security Copilot to discover 20 previously unknown vulnerabilities in the GRUB2, U-Boot, and Barebox open-source bootloaders. GRUB2 (GRand Unified Bootloader) is the...

View Article

Image may be NSFW.
Clik here to view.

Critical auth bypass bug in CrushFTP now exploited in attacks

Attackers are now targeting a critical authentication bypass vulnerability in the CrushFTP file transfer software using exploits based on publicly available proof-of-concept code. The security...

View Article

Image may be NSFW.
Clik here to view.

Apple backports zero-day patches to older iPhones and Macs

Apple has released security updates that backport fixes for actively exploited vulnerabilities that were exploited as zero-days to older versions of its operating systems. At the same time, the...

View Article


Image may be NSFW.
Clik here to view.

Google rolls out easy end-to-end encryption for Gmail business users

​Google has started rolling out a new end-to-end encryption (E2EE) model for Gmail enterprise users, making it easier to send encrypted emails to any recipient. While businesses also have the option...

View Article

Image may be NSFW.
Clik here to view.

Nearly 24,000 IPs behind wave of Palo Alto Global Protect scans

A significant spike in scanning activity targeting Palo Alto Network GlobalProtect login portals has been observed, with researchers concerned it may be a prelude to an upcoming attack or flaw being...

View Article

Image may be NSFW.
Clik here to view.

We Smell a (DC)Rat: Revealing a Sophisticated Malware Delivery Chain

The Acronis Threat Research Unit (TRU) was presented with an interesting threat chain and malware sample for analysis that involved a known cyberthreat along with some interesting twists in targeting...

View Article


Image may be NSFW.
Clik here to view.

North Korean IT worker army expands operations in Europe

​North Korea’s IT workers have expanded operations beyond the United States and are now increasingly targeting organizations across Europe. Also referred to as “IT warriors,” they hide their true...

View Article


Image may be NSFW.
Clik here to view.

Cisco warns of CSLU backdoor admin account used in attacks

Cisco has warned admins to patch a critical Cisco Smart Licensing Utility (CSLU) vulnerability, which exposes a built-in backdoor admin account now used in attacks. CSLU is a Windows app for managing...

View Article

Image may be NSFW.
Clik here to view.

The Reality Behind Security Control Failures—And How to Prevent Them

There’s a clear gap between expectation and reality when it comes to security controls. Despite deploying best-in-class security tools and building capable teams, many organizations discover the truth...

View Article

Image may be NSFW.
Clik here to view.

Counterfeit Android devices found preloaded with Triada malware

A new version of the Triada trojan has been discovered preinstalled on thousands of new Android devices, allowing threat actors to steal data as soon as they are set up. Kaspersky researchers report...

View Article

Image may be NSFW.
Clik here to view.

Police shuts down KidFlix child sexual exploitation platform

Kidflix, one of the largest platforms used to host, share, and stream child sexual abuse material (CSAM) on the dark web, was shut down on March 11 following a joint action coordinated by German law...

View Article


Image may be NSFW.
Clik here to view.

Royal Mail investigates data leak claims, no impact on operations

​Royal Mail is investigating claims of a security breach after a threat actor leaked over 144GB of data allegedly stolen from the company’s systems. When asked to confirm the authenticity of the...

View Article

Image may be NSFW.
Clik here to view.

GitHub expands security tools after 39 million secrets leaked in 2024

GitHub announced updates to its Advanced Security platform after it detected over 39 million leaked secrets in repositories during 2024, including API keys and credentials, exposing users and...

View Article


Image may be NSFW.
Clik here to view.

Microsoft adds hotpatching support to Windows 11 Enterprise

Microsoft has announced that hotpatch updates are now available for business customers using Windows 11 Enterprise 24H2 on x64 (AMD/Intel) systems, starting today. On devices where hotpatching is...

View Article

Image may be NSFW.
Clik here to view.

Verizon Call Filter API flaw exposed customers’ incoming call history

A vulnerability in Verizon’s Call Filter feature allowed customers to access the incoming call logs for another Verizon Wireless number through an unsecured API request. The flaw was discovered by...

View Article


Image may be NSFW.
Clik here to view.

Genetic data site openSNP to close and delete data over privacy concerns

The openSNP project, a platform for sharing genetic and phenotypic data, will shut down on April 30, 2025, and delete all user submissions over privacy concerns and the risk of misuse by authoritarian...

View Article

Image may be NSFW.
Clik here to view.

Recent GitHub supply chain attack traced to leaked SpotBugs token

A cascading supply chain attack on GitHub that targeted Coinbase in March has now been traced back to a single token stolen from a SpotBugs workflow, which allowed a threat actor to compromise...

View Article

Image may be NSFW.
Clik here to view.

Oracle privately confirms Cloud breach to customers

Oracle has finally acknowledged to some customers that attackers have stolen old client credentials after breaching a “legacy environment” last used in 2017, Bloomberg reported. However, while Oracle...

View Article
Browsing all 1816 articles
Browse latest View live