New exploit in Windows 10 makes everyone an admin
A new vulnerability in Windows 10 allows hackers to become administrators. Microsoft has fixed the vulnerability with a security update.
CVE-2022-21882 was discovered in December by security expert RyeLv. The vulnerability allows hackers to call the relevant user-level GUI API to make kernel cal... Read more
‘Social media fraudsters pocketed 690 million euros’
95,000 US residents fell victim to social media fraud in 2021. The total damage amounts to 770 million dollars (690 million euros).
The Federal Trade Commission (US market watchdog) shares the news in a report. One in four of all fraud victims was misled by an ad or post on social media. The com... Read more
Portnox raises $22 million in its Series A investment to fund growth
Portnox, a network security startup, officially known as Access Layers, announced on Thursday that it has closed a $22-million funding round. The Series A investment was led by Elsewhere partners and is going to fuel growth plans by the startup.
Large companies can have corporate networks spanni... Read more
Malware attacks via Excel XLL files rose by nearly 600 percent
Cyber attacks based on Microsoft Excel add-in files (.XLL) increased by nearly 600 percent in 2021. In a new report, security researchers at HP Wolf Security disclose how the file type is being exploited.
Excel add-in files (.XLL) allow DLL files to be opened within Excel sheets. Cybercriminals ... Read more
‘Log4j in VMware Horizon is being exploited by access brokers’
BlackBerry security researchers conclude that hacking group Prophet Spider is actively exploiting a Log4j vulnerability in unpatched VMware Horizon servers.
In December 2021, VMware published a patch to fix a Log4j vulnerability in VMware Horizon. A month later, a UK government security team war... Read more
Sophos introduces ZTNA for secure user and device connections
Sophos is introducing a Zero Trust Network Access (ZTNA) portfolio. Zero trust principles and far-reaching integration with Sophos Intercept X's endpoint security are key to the release.
With the arrival of Zero Trust Network Access (ZTNA), Sophos wants to offer a transparent and scalable securi... Read more
Critical Linux vulnerability affects all major distributions
Security researchers have found vulnerabilities in Linux PolicyKit (also known as Polkit). The vulnerabilities allow hackers to gain complete access to affected machines and upload malicious code. The issue has since been patched.
According to Qualys researchers, the so-called PwnKit exploit man... Read more
Log4J hackers continue targeting VMware Horizon servers
VMware is rushing to convince customers to apply the latest security guidance.
According to several cybersecurity companies monitoring the situation, attackers are still targeting VMware Horizon servers through Log4J vulnerabilities.
Two weeks ago, the UK's National Health Service (NHS)... Read more
Microsoft finds a new SolarWinds vulnerability during Log4j research
A Log4j investigation led Microsoft to a new vulnerability related to the infamous SolarWinds attack of 2020.
Microsoft states that the search for various Log4j vulnerabilities yielded a welcome byproduct. During a recent investigation, researchers stumbled upon a previously unknown vulnerabilit... Read more
WordPress plugins from AccessPress Themes have backdoors for hackers
Security specialist Jetpack discovered backdoors in legitimate WordPress plugins from AccessPress Themes, a WordPress dev. The backdoors allow hackers to take complete control of WordPress websites.
Jetpack's investigation shows that AccessPress Themes' WordPress plugins and themes feature a bac... Read more