Cybersecurity

‘Snatch’ Ransom Group Exposes Visitor IP Addresses – Krebs on Security

The victim shaming site operated by the Snatch ransomware group is leaking data about its true online location and internal operations, as well as the Internet addresses of its visitors, KrebsOnSecurity has found. The leaked data suggest that Snatch is one of several ransomware groups using paid ads on Google.com to trick people into installing […]

Cybersecurity

macOS 14 Sonoma Patches 60 Vulnerabilities

Apple on Tuesday announced the release of macOS 14 Sonoma. A security advisory published by the tech giant shows that the latest version of the operating system patches more than 60 vulnerabilities. The flaws can be exploited to obtain potentially sensitive information (location, calendar, contacts, photos, credentials), execute arbitrary code with elevated privileges, escape the […]

Cybersecurity

China-Linked Budworm Targeting Middle Eastern Telco and Asian Government Agencies

Sep 28, 2023THNMalware / Cyber Threat Government and telecom entities have been subjected to a new wave of attacks by a China-linked threat actor tracked as Budworm using an updated malware toolset. The intrusions, targeting a Middle Eastern telecommunications organization and an Asian government, took place in August 2023, with the adversary deploying an improved […]

Cybersecurity

RICO class-action data privacy lawsuit filed against H&R Block, Google, Meta

A trial lawyer who secured a nearly $90 million verdict against Monsanto filed suit against H&R Block on Wednesday, alleging the tax preparation firm collaborated with Meta and Google to embed “spyware” on its website to make money from scraped tax return data. The class-action suit alleges the three companies’ joint conduct should be considered […]

Cybersecurity

Simple Membership Plugin Flaws Expose WordPress Sites

Two new security flaws in the popular Simple Membership plugin for WordPress, affecting versions 4.3.4 and below, have been identified, leading to potential privilege escalation issues.  With over 50,000 active installations, the plugin developed by smp7 and wp.insider is widely used for custom membership management on WordPress sites. The flaws identified by Patchstack security researchers include […]

Cybersecurity

Network Flight Simulator: Open-source adversary simulation tool – Help Net Security

Network Flight Simulator is a lightweight utility that generates malicious network traffic and helps security teams evaluate security controls and network visibility. The tool performs tests to simulate DNS tunneling, DGA traffic, requests to known active C2 destinations, and other suspicious traffic patterns. “There’s so much snake oil within the security industry regarding threat detection […]

Cybersecurity

Update Chrome Now: Google Releases Patch for Actively Exploited Zero-Day Vulnerability

Sep 28, 2023THNZero Day / Vulnerability Google on Wednesday rolled out fixes to address a new actively exploited zero-day in the Chrome browser. Tracked as CVE-2023-5217, the high-severity vulnerability has been described as a heap-based buffer overflow in the VP8 compression format in libvpx, a free software video codec library from Google and the Alliance […]