Two new backdoors have been attributed to the Molerats advanced persistent threat (APT) group, which is believed to be associated with the Palestinian terrorist organization Hamas.
Microsoft has not said when or if it will patch the vulnerability, but the tech giant pointed out that “this technique requires an attacker to have already compromised the target machine to run malicious code.”
Bug bounty researcher “Tabahi” (ta8ahi) found the issue, described as a site-wide cross-site request forgery (CSRF) bug deserving of a 9 – 10 severity score. The vulnerability impacts the Glassdoor web domain.
Buggy firmware opens a number of D-Link VPN router models to zero-day attacks. The flaws, which lack a complete vendor fix, allow adversaries to launch root command injection attacks that can be executed remotely and allow for device takeover.
Unit 42 researchers uncovered a novel Linux-based cryptocurrency mining botnet that exploits a disputed PostgreSQL remote code execution (RCE) vulnerability that compromises database servers for cryptojacking.
A team at vpnMentor found the massive Instagram click farm operation thanks to a completely unsecured Elasticsearch database it was using, connected to the public-facing internet.
The European Council voted to locate the EU’s future cybersecurity research hub in Bucharest, Romania’s capital. Named the European Cybersecurity Industrial, Technology and Research Competence Centre,, the new hub is set to start operating next year.
A potential remote code execution (RCE) vulnerability has been patched in one of Starbucks’ mobile domains. A CVE has not been issued for the critical vulnerability but a severity score of 9.8 has been added to the report.
As per Palo Alto Networks’ Unit 42 cybersecurity team, njRAT is being used to download and execute secondary-stage payloads from Pastebin, scrapping the need to establish a traditional command-and-control (C2) server altogether.
Key lawmakers in the House and Senate celebrated the inclusion of cybersecurity provisions they shepherded into the final annual National Defense Authorization Act (NDAA).