Recent Security News

  • Slug slimes aerospace biz AerCap with ransomware, brags about 1TB theft

    January 22, 2024 at 03:51PM AerCap, the world’s largest aircraft leasing company, reported a ransomware infection on January 17. Despite the intrusion by the Slug ransomware crew, the company claims to have not incurred financial losses. LoanDepot also disclosed a ransomware attack, affecting about 16.6 million individuals, prompting an ongoing investigation and restoration efforts. From…

    Read More

  • North Korea’s ScarCruft Attackers Gear Up to Target Cybersecurity Pros

    January 22, 2024 at 03:46PM ScarCruft, a North Korea-sponsored APT group, is preparing for targeted cyberattacks on threat intelligence professionals. They aim to steal nonpublic threat intel and enhance their offensive tactics. The innovative campaign involves using lure related to the Kimsuky APT group to target cybersecurity professionals, and the group is refining their malicious…

    Read More

  • German IT Consultant Fined Thousands for Reporting Security Failing

    January 22, 2024 at 03:31PM A security researcher in Germany was fined €3,000 for reporting a vulnerability in an e-commerce database that put customer information at risk. Modern Solution GmbH downplayed the data exposure, leading to a legal battle. Hendrik H. was initially vindicated by the District Court but was eventually fined and is planning…

    Read More

  • Apple Ships iOS 17.3, Warns of WebKit Zero-Day Exploitation

    January 22, 2024 at 03:24PM Apple has released iOS 17.3 and macOS Sonoma 14.3 updates to address 16 vulnerabilities including WebKit flaws exploited in zero-day attacks. Apple warns of code execution, denial-of-service, and data exposure threats and suspects recent exploitation. The updates also fix security issues in several other components. Apple hasn’t provided technical details…

    Read More

  • Malicious web redirect scripts stealth up to hide on hacked sites

    January 22, 2024 at 03:15PM Security researchers discovered the Parrot traffic direction system (TDS) to be rapidly evolving, enhancing its malicious capabilities. Targeting vulnerable WordPress and Joomla sites, it infects and redirects users to malicious locations, with 16,500 websites affected. The TDS operators sell the traffic to threat actors, who profile and redirect users to…

    Read More