Malware & Threats Cleo Patches Exploited Flaw as Security Firms Detail Malware Pushed in Attacks Cleo has released patches for the exploited vulnerability and security firms have detailed the malware delivered in attacks. Eduard KovacsDecember 12, 2024
Malware & Threats No Doughnuts Today? Cyberattack Puts Krispy Kreme in a Sticky Situation The doughnut and coffeehouse chain confirmed a cyberattack took out parts of its online ordering system in parts of the United States. SecurityWeek NewsDecember 11, 2024
Malware & Threats Google Pays $55,000 for High-Severity Chrome Browser Bug Google pushes out major Chrome browser updates to fix multiple serious security defects. Ionut ArghireDecember 11, 2024
Malware & Threats Microsoft Ships Urgent Patch for Exploited Windows CLFS Zero-Day Patch Tuesday: Redmond patches 71 security flaws and calls immediate attention to an exploited Windows zero-day reported by CrowdStrike. Ryan NaraineDecember 10, 2024
Malware & Threats Critical OpenWrt Flaw Exposes Firmware Update Server to Exploitation The CVE-2024-54143 vulnerability affects the OpenWrt sysupgrade server and exposes users to risks of installing malicious firmware images. Ryan NaraineDecember 9, 2024
Malware & Threats I-O Data Confirms Zero-Day Attacks on Routers, Full Patches Pending Japanese device maker confirms zero-day router exploitation and warn that full patches won’t be available for a few weeks. Ryan NaraineDecember 5, 2024
Malware & Threats ‘DroidBot’ Android Trojan Targets Banking, Cryptocurrency Applications The newly discovered DroidBot Android trojan targets 77 banks, cryptocurrency exchanges, and national organizations. Ionut ArghireDecember 5, 2024
Malware & Threats Spy v Spy: Russian APT Turla Caught Stealing From Pakistani APT Russia's Turla hackers hijacked 33 command servers operated by Pakistani hackers who had themselves breached Afghanistan and Indian targets. Ryan NaraineDecember 4, 2024
Malware & Threats Prototype UEFI Bootkit is South Korean University Project; LogoFAIL Exploit Discovered The 'Bootkitty' prototype UEFI bootkit contains an exploit for LogoFAIL and was created in a South Korea university program. Ryan NaraineDecember 2, 2024
Malware & Threats Source Code of $3,000-a-Month macOS Malware ‘Banshee Stealer’ Leaked The Banshee Stealer macOS malware operation, which emerged earlier this year, was reportedly shut down following a source code leak. Eduard KovacsNovember 27, 2024
Malware & Threats VMware Patches High-Severity Vulnerabilities in Aria Operations The company warns that malicious hackers can craft exploits to elevate privileges or launch cross-site scripting attacks. Ryan NaraineNovember 26, 2024
Malware & Threats In Other News: Nvidia Fixes Critical Flaw, Chinese Linux Backdoor, New Details in WhatsApp-NSO Lawsuit Noteworthy stories that might have slipped under the radar: Nvidia fixes vulnerability with rare ‘critical’ severity, Chinese APT’s first Linux backdoor, new details emerge... SecurityWeek NewsNovember 22, 2024