PROJET AUTOBLOG


The Hacker News

Site original : The Hacker News

⇐ retour index

New Pingback Malware Using ICMP Tunneling to Evade C&C Detection

mardi 4 mai 2021 à 15:00
Researchers on Tuesday disclosed a novel malware that uses a variety of tricks to stay under the radar and evade detection, while stealthily capable of executing arbitrary commands on infected systems. Called 'Pingback,' the Windows malware leverages Internet Control Message Protocol (ICMP) tunneling for covert bot communications, allowing the adversary to utilize ICMP packets to piggyback

How Should the Service Desk Reset Passwords?

mardi 4 mai 2021 à 14:39
Ask the average helpdesk technician what they do all day, and they will probably answer by saying that they reset passwords. Sure, helpdesk technicians do plenty of other things too, but in many organizations, a disproportionate number of helpdesk calls are tied to password resets. On the surface, having a helpdesk technician reset a user’s password probably doesn’t seem like a big deal. After

Critical Patch Out for Month-Old Pulse Secure VPN 0-Day Under Attack

mardi 4 mai 2021 à 09:52
Ivanti, the company behind Pulse Secure VPN appliances, has released a security patch to remediate a critical security vulnerability that was found being actively exploited in the wild by at least two different threat actors. Tracked as CVE-2021-22893 (CVSS score 10), the flaw concerns "multiple use after free" issues in Pulse Connect Secure that could allow a remote unauthenticated attacker to

Apple Releases Urgent Security Patches For Zero‑Day Bugs Under Active Attacks

mardi 4 mai 2021 à 07:42
Apple on Monday released security updates for iOS, macOS, and watchOS to address three zero-day flaws and expand patches for a fourth vulnerability that the company said might have been exploited in the wild. <!--adsense--> The weaknesses all concern WebKit, the browser engine which powers Safari and other third-party web browsers in iOS, allowing an adversary to execute arbitrary code on target

Over 40 Apps With More Than 100 Million Installs Found Leaking AWS Keys

lundi 3 mai 2021 à 18:13
Most mobile app users tend to blindly trust that the apps they download from app stores are safe and secure. But that isn't always the case. To demonstrate the pitfalls and identify vulnerabilities on a large scale, cybersecurity and machine intelligence company CloudSEK recently provided a platform called BeVigil where individuals can search and check app security ratings and other security