Mobile Security

Apple Patches Critical iOS Bugs; One Might Be Under Attack

On Monday and Tuesday, Apple released iOS 14.8.1, iPadOS 14.8.1, watchOS 8.1, and tvOS 15.1, patching 24 security vulnerabilities, including… Read More

3 years ago

AvosLocker Ransomware Allegedly Stole Senstive Files from Gigabyte

The AvosLocker ransomware gang is claiming that it breached Gigabyte and has leaked a sample of what it claims are… Read More

3 years ago

TA505 Gang Returns with Newly Polished FlawedGrace RAT in Malspam Campaign

The TA505 cybercrime group is upping its financially motivated attacks, shooting malware at a range of industries in a wave… Read More

3 years ago

CryptoRom Scam Rakes in $1.4M by Exploiting Apple Enterprise Features

Cryptocurrency scammers are exploiting Apple’s Enterprise Developer Program to get bogus trading apps onto their marks’ iPhones. Sophos Labs observed… Read More

3 years ago

Brizy WordPress Plugin Exploit Chains Allow Full Site Takeovers

Vulnerabilities in the Brizy Page Builder plugin for WordPress sites could be chained together to allow attackers to completely take… Read More

3 years ago

Flubot Malware Targets Androids With Fake Security Updates

The Flubot banking trojan keeps switching up its lies, trying to fool Android users into clicking on a fake Flubot-deleting… Read More

3 years ago

Google Releases Emergency Update to Fix Two Chrome Zero-Day Vulnerabilities Under Active Exploitation

Google pushed out an emergency Chrome update to fix two zero-days, the second pair this month, that are being exploited… Read More

3 years ago

New APT ChamelGang Uses Supply Chain Weaknesses to Target Russian Energy, Aviation Firms

The new APT group is specifically targeting the fuel and energy complex and aviation industry in Russia, exploiting known vulnerabilities… Read More

3 years ago

Baby's Death Alleged to Be Linked to Ransomware

A U.S. hospital paralyzed by a ransomware attack in 2019 will be defending itself in court in November over the… Read More

3 years ago

Credential Spear-Phishing Campaign Uses Spoofed Zix Encrypted Email to Target Nearly 75,000 People

The spoofed email has targeted close to 75,000 email inboxes, slipping past spam and security controls across Office 365, Google… Read More

3 years ago

REvil Affiliates Confirm Getting Screwed Out of Payments

REvil leadership did indeed create a backdoor that enabled them to cut off ransom negotiations between victims and the gang’s… Read More

3 years ago

Exchange/Outlook Autodiscover Bug Spills $100K+ Email Passwords

Guardicore security researcher Amit Serper has discovered a severe design bug in MIcrosoft Exchange’s autodiscover – a protocol that lets… Read More

3 years ago

How REvil May Have Ripped Off Its Own Affiliates

Malware specialists have found evidence of how REvil ransomware’s leadership may have hijacked chats with victims of their own affiliates… Read More

3 years ago

Hackers Are Going ‘Deep-Sea Phishing,’ So What Can You Do About It?

Hackers are upping their game, using an approach some experts call “Deep Sea Phishing,” which is the use of a… Read More

3 years ago

Microsoft MSHTML Flaw Exploited by Ryuk Ransomware Gang

Criminals behind the Ryuk ransomware were early exploiters of the Windows MSHTML flaw, actively leveraging the bug in campaigns ahead… Read More

3 years ago

Attackers Impersonate DoT in Two-Day Phishing Scam

Threat actors impersonated the USDOT in a phishing campaign that used a combination of tactics – including creating new domains… Read More

3 years ago