Malwarebytes has discovered the Malsmoke group, whose malicious ads have infiltrated virtually all ad networks that partner with porn sites. Mostly IE and Adobe Flash Player users were affected. of the hackers injected their ads...
Security
Raccoon attack on TLS can be used to decrypt HTTPS traffic
The team of exerts has published a description of a theoretical Raccoon attack on TLS that can be used for decrypting HTTPS connections and reading traffic. , the researchers admit that the Raccoon attack is theoretical and...
BLURtooth vulnerability allows overwriting Bluetooth authentication keys
Experts from CERT and the Bluetooth Special Interest Group (SIG) have released information on the BLURtooth vulnerability, which poses a threat to all devices using Bluetooth from version 4.0 to version 5.0. 5.1 has features that...
Due to vulnerability in File Manager plugin attacked millions of WordPress sites
Last week we reported that in the File Manager plugin was found dangerous vulnerability for WordPress, which allows uploading malicious files to vulnerable sites. Manager plugin is used by more than 700,000 resources, and...
Cisco fixed critical vulnerability in Jabber for Windows
This week, Cisco engineers fixed a vulnerability in several versions of Jabber for Windows, video conferencing and messaging application. Fixed issues included an RCE bug that had the potential of a worm to execute arbitrary code...
Hackers attack vulnerability affecting over 350,000 WordPress sites
In the File Manager plugin has been discovered a dangerous vulnerability, which is used by over 700,000 WordPress-based resources and which allows executing commands and malicious scripts on vulnerable sites. Just hours after...
Attackers use a three-year-old RCE bug to install backdoors in Qnap NAS
Researchers from the Chinese company Qihoo 360 warn that attackers are still exploiting the RCE-bug in the firmware of Qnap NAS devices, which was fixed back in 2017. The vulnerability allows unauthenticated attackers to...
Researcher discovered critical vulnerabilities in Slack and received only $1,750 for it
Evolution Gaming specialist Oscar Vegeris described how at the beginning of 2020 he found a number of critical vulnerabilities in Slack, which made it possible to easily execute arbitrary code on the user’s machine. it...