Cybersecurity

Actively exploited 0-days in Ivanti VPN are letting hackers backdoor networks

Enlarge Getty Images Unknown threat actors are actively targeting two critical zero-day vulnerabilities that allow them to bypass two-factor authentication and execute malicious code inside networks that use a widely used virtual private network appliance sold by Ivanti, researchers said Wednesday. Ivanti reported bare-bones details concerning the zero-days in posts published on Wednesday that urged […]

Cybersecurity

Hackers spent 2+ years looting secrets of chipmaker NXP before being detected

Enlarge Getty Images A prolific espionage hacking group with ties to China spent over two years looting the corporate network of NXP, the Netherlands-based chipmaker whose silicon powers security-sensitive components found in smartphones, smartcards, and electric vehicles, a news outlet has reported. The intrusion, by a group tracked under names including “Chimera” and “G0114,” lasted […]

Cybersecurity

Okta says hackers breached its support system and viewed customer files

Enlarge Getty Images Identity and authentication management provider Okta said hackers managed to view private customer information after gaining access to credentials to its customer support management system. “The threat actor was able to view files uploaded by certain Okta customers as part of recent support cases,” Okta Chief Security Officer David Bradbury said Friday. […]

Cybersecurity

Incomplete disclosures by Apple and Google create “huge blindspot” for 0-day hunters

Enlarge Getty Images Incomplete information included in recent disclosures by Apple and Google reporting critical zero-day vulnerabilities under active exploitation in their products has created a “huge blindspot” that’s causing a large number of offerings from other developers to go unpatched, researchers said Thursday. Two weeks ago, Apple reported that threat actors were actively exploiting […]