DDoS-for-hire services are abusing Plex Media Servers to amplify their attacks
The new attack vector doesn’t require the attackers to log into a Plex server, they only have to scan the internet for Plex Media Server instances with UDP port 32414 enabled.
February 8, 2021
Cybersecurity firm Stormshield says hackers stole source code for its SNS product
The company said the attackers possibly compromised personal and technical data for some of its customers.
February 8, 2021
Vulnerability summary for the week: February 5, 2021
A weekly vulnerability digest.
February 5, 2021
Google fixes Chrome zero day bug exploited in the wild
The flaw is described as a heap-based overflow issue in V8 JavaScript engine in Google Chrome.
February 5, 2021
Hackers used fake WhatsApp version to trick iPhone users
The researchers have linked the fake WhatApp version to an Italian surveillance company Cy4Gate.
February 5, 2021
New Matryosh botnet aimed at Android devices
The new botnet reuses the Mirai framework and hunts for Android devices that have ADB interface enabled and exposed on the internet.
February 4, 2021
Europol, US Secret Service, and Spanish police bust massive credit card fraud ring
The criminal network used shell companies to steal over €12 million from 50 US financial institutions.
February 4, 2021
Tiny Linux malware targets supercomputers across the globe
The malware is small, yet complex and is portable to many operating systems including Linux, BSD, Solaris, and possibly AIX and Windows.
February 4, 2021
Suspected Chinese hackers breach US payroll agency using SolarWinds vulnerability
The hackers used the vulnerability within SolarWinds software to compromise networks of US government agencies.
February 3, 2021
Hackers targeted gamers in Asia via tainted NoxPlayer update
ESET informed BigNox of a security breach, but the company denied it was hacked.
February 2, 2021