PROJET AUTOBLOG


The Hacker News

Site original : The Hacker News

⇐ retour index

2 New Chrome 0-Days Under Attack — Update Your Browser ASAP!

mercredi 14 avril 2021 à 07:48
Google on Tuesday released a new version of Chrome web-browsing software for Windows, Mac, and Linux with fixes for two security vulnerabilities, both of which it says are under active exploitation. One of the two flaws concerns an insufficient validation of untrusted input in its V8 JavaScript rendering engine (CVE-2021-21220), which was demonstrated by Dataflow Security's Bruno Keith and

NSA Discovers New Vulnerabilities Affecting Microsoft Exchange Servers

mercredi 14 avril 2021 à 06:58
In its April slate of patches, Microsoft rolled out fixes for a total of 114 security flaws, including an actively exploited zero-day and four remote code execution bugs in Exchange Server. Of the 114 flaws, 19 are rated as Critical, 88 are rated Important, and one is rated Moderate in severity. Chief among them is CVE-2021-28310, a privilege escalation vulnerability in Win32k that's said to be

New NAME:WRECK Vulnerabilities Impact Nearly 100 Million IoT Devices

mardi 13 avril 2021 à 14:24
Security researchers have uncovered nine vulnerabilities affecting four TCP/IP stacks impacting more than 100 million consumer and enterprise devices that could be exploited by an attacker to take control of a vulnerable system. Dubbed "NAME:WRECK" by Forescout and JSOF, the flaws are the latest in series of studies undertaken as part of an initiative called Project Memoria to study the security

Hackers Using Website's Contact Forms to Deliver IcedID Malware

mardi 13 avril 2021 à 13:51
Microsoft has warned organizations of a "unique" attack campaign that abuses contact forms published on websites to deliver malicious links to businesses via emails containing fake legal threats, in what's yet another instance of adversaries abusing legitimate infrastructure to mount evasive campaigns that bypass security protections. "The emails instruct recipients to click a link to review

Detecting the "Next" SolarWinds-Style Cyber Attack

mardi 13 avril 2021 à 13:01
The SolarWinds attack, which succeeded by utilizing the sunburst malware, shocked the cyber-security industry. This attack achieved persistence and was able to evade internal systems long enough to gain access to the source code of the victim. Because of the far-reaching SolarWinds deployments, the perpetrators were also able to infiltrate many other organizations, looking for intellectual