Vulnerability

Google Chrome’s new post-quantum cryptography may break TLS connections

Some ​Google Chrome users report having issues connecting to websites, servers, and firewalls after Chrome 124 was released last week with the new quantum-resistant X25519Kyber768 encapsulation mechanism enabled by default. Google started testing the post-quantum secure TLS key encapsulation mechanism in August and has now enabled it in the latest Chrome version for all users. The new version utilizes the Kyber768 […]

Google Chrome’s new post-quantum cryptography may break TLS connections Read More »

US Post Office phishing sites get as much traffic as the real one

Security researchers analyzing phishing campaigns that target United States Postal Service (USPS) saw that the traffic to the fake domains is typically similar to what the legitimate site records and it is even higher during holidays. Phishing operations typically target people’s sensitive information (account credentials, card details) or try to trick users into making payments

US Post Office phishing sites get as much traffic as the real one Read More »

Japanese police create fake support scam payment cards to warn victims

Image: AI-generated via Midjourney Japanese police placed fake payment cards in convenience stores to protect the elderly targeted by tech support scams or unpaid money fraud. The cards are labeled “Virus Trojan Horse Removal Payment Card” and “Unpaid Bill Late Fee Payment Card,” and were created by the Echizen Police in the Fukui prefecture in Japan

Japanese police create fake support scam payment cards to warn victims Read More »

Okta warns of “unprecedented” credential stuffing attacks on customers

Okta warns of an “unprecedented” spike in credential stuffing attacks targeting its identity and access management solutions, with some customer accounts breached in the attacks. Threat actors use credential stuffing to compromise user accounts by trying out in an automated manner lists of usernames and passwords typically purchased from cybercriminals. In an advisory today, Okta says

Okta warns of “unprecedented” credential stuffing attacks on customers Read More »

WP Automatic WordPress plugin hit by millions of SQL injection attacks

Hackers have started to target a critical severity vulnerability in the WP Automatic plugin for WordPress to create user accounts with administrative privileges and to plant backdoors for long-term access. Currently installed on more than 30,000 websites, WP Automatic lets administrators automate content importing (e.g. text, images, video) from various online sources and publishing on

WP Automatic WordPress plugin hit by millions of SQL injection attacks Read More »

Over 1,400 CrushFTP servers vulnerable to actively exploited bug

​Over 1,400 CrushFTP servers exposed online were found vulnerable to attacks currently targeting a critical severity server-side template injection (SSTI) vulnerability previously exploited as a zero-day. While CrushFTP describes CVE-2024-4040 as a VFS sandbox escape in its managed file transfer software that enables arbitrary file reading, unauthenticated attackers can use it to gain remote code execution

Over 1,400 CrushFTP servers vulnerable to actively exploited bug Read More »

Telegram is down with “Connecting” error

It’s not just you: Telegram is down, and users report seeing a “Connecting” alert when they try to open messages, groups, or channels. The “Connecting” alert, typically used during slow internet connections, prevents users from accessing the messages.  BleepingComputer also observed Connecting” error when accessing the Telegram desktop client. We’re seeing similar reports from users

Telegram is down with “Connecting” error Read More »

Fake job interviews target developers with new Python backdoor

A new campaign tracked as “Dev Popper” is targeting software developers with fake job interviews in an attempt to trick them into installing a Python remote access trojan (RAT). The developers are asked to perform tasks supposedly related to the interview, like downloading and running code from GitHub, in an effort to make the entire process

Fake job interviews target developers with new Python backdoor Read More »

Patients’ data exposed in phishing attack

​The Los Angeles County Department of Health Services disclosed a data breach after thousands of patients’ personal and health information was exposed in a data breach resulting from a recent phishing attack impacting over two dozen employees. This integrated health system operates the public hospitals and clinics in L.A. County (the most populous county in

Patients’ data exposed in phishing attack Read More »

Data breach may impact 13.4 million patients

Healthcare service provider Kaiser Permanente disclosed a data security incident that may impact 13.4 million people in the United States. Kaiser Permanente is an integrated managed care consortium and one of the largest nonprofit health plans in the U.S. It operates 40 hospitals and 618 medical facilities in California, Colorado, the District of Columbia, Georgia, Hawaii, Maryland,

Data breach may impact 13.4 million patients Read More »

Scroll to Top