PROJET AUTOBLOG


The Hacker News

Site original : The Hacker News

⇐ retour index

VMware Patches Important Bug Affecting ESXi, Workstation and Fusion Products

jeudi 6 janvier 2022 à 07:17
VMWare has shipped updates to Workstation, Fusion, and ESXi products to address an "important" security vulnerability that could be weaponized by a threat actor to take control of affected systems. The issue relates to a heap-overflow vulnerability — tracked as CVE-2021-22045 (CVSS score: 7.7) — that, if successfully exploited, results in the execution of arbitrary code. The company credited

Google Releases New Chrome Update to Patch Dozens of New Browser Vulnerabilities

jeudi 6 janvier 2022 à 06:47
Google has rolled out the first round of updates to its Chrome web browser for 2022 to fix 37 security issues, one of which is rated Critical in severity and could be exploited to pass arbitrary code and gain control over a victim's system. Tracked as CVE-2022-0096, the flaw relates to a use-after-free bug in the Storage component, which could have devastating effects ranging from corruption of

Researchers Uncover Hacker Group Behind Organized Financial-Theft Operation

mercredi 5 janvier 2022 à 14:40
Cybersecurity researchers have taken the wraps of an organized financial-theft operation undertaken by a discreet actor to target transaction processing systems and siphon funds from entities primarily located in Latin America for at least four years. The malicious hacking group has been codenamed Elephant Beetle by Israeli incident response firm Sygnia, with the intrusions aimed at banks and

New Zloader Banking Malware Campaign Exploiting Microsoft Signature Verification

mercredi 5 janvier 2022 à 12:00
An ongoing ZLoader malware campaign has been uncovered exploiting remote monitoring tools and Microsoft's digital signature verification to siphon user credentials and sensitive information. Israeli cybersecurity company Check Point Research, which has been tracking the sophisticated infection chain since November 2021, attributed it to a cybercriminal group dubbed Malsmoke, citing similarities

Hackers Target Real Estate Websites with Skimmer in Latest Supply Chain Attack

mercredi 5 janvier 2022 à 08:08
Threat actors leveraged a cloud video hosting service to carry out a supply chain attack on more than 100 real estate websites operated by Sotheby's Realty that involved injecting malicious skimmers to steal sensitive personal information. "The attacker injected the skimmer JavaScript codes into video, so whenever others import the video, their websites get embedded with skimmer codes as well,"