Hackers Proxyjack & Cryptomine Selenium Grid Servers

A vendor honeypot caught two attacks intended to leverage the tens of thousands of exposed Selenium Grid Web app testing servers.

darkreading – ​Read More

Apple Vision Pro’s Eye Tracking Exposed What People Type

The Vision Pro uses 3D avatars on calls and for streaming. These researchers used eye tracking to work out the passwords and PINs people typed with their avatars.

Security Latest – ​Read More

Microsoft Discloses Four Zero-Days in September Update

Microsoft recently revealed four zero-day vulnerabilities in its September update, part of the Patch Tuesday release containing 79 vulnerabilities, making it the fourth-largest release of the year.

Cyware News – Latest Cyber News – ​Read More

ToneShell Backdoor Targets IISS Defence Summit Attendees in Latest Espionage Campaign

The ToneShell backdoor, attributed to the Mustang Panda cyber espionage group, has resurfaced in a new attack targeting attendees of the 2024 IISS Defence Summit in Prague.

Cyware News – Latest Cyber News – ​Read More

Healthcare Provider to Pay $65M Settlement Following Ransomware Attack

Lehigh Valley Health Network has agreed to pay a $65 million settlement in a class-action suit filed over a 2023 data breach.

The post Healthcare Provider to Pay $65M Settlement Following Ransomware Attack appeared first on SecurityWeek.

SecurityWeek – ​Read More

Exploiting CI/CD Pipelines for Fun and Profit

On September 8, 2024, a significant exploit chain was discovered, starting from a publicly exposed . git directory, leading to a full server takeover. The vulnerabilities stem from websites exposing their . git folders.

Cyware News – Latest Cyber News – ​Read More

Amateurish ‘CosmicBeetle’ Ransomware Stings SMBs in Turkey

With an immature codebase and a “rather chaotic encryption scheme” prone to failure, the group targets small businesses with custom malware.

darkreading – ​Read More

WordPress Mandates Two-Factor Authentication for Plugin and Theme Developers

WordPress.org has announced a new account security measure that will require accounts with capabilities to update plugins and themes to activate two-factor authentication (2FA) mandatorily.
The enforcement is expected to come into effect starting October 1, 2024.
“Accounts with commit access can push updates and changes to plugins and themes used by millions of WordPress sites worldwide,” the

The Hacker News – ​Read More

Criminal IP Teams Up with IPLocation.io to Deliver Unmatched IP Solutions to Global Audiences

Torrance, United States / California, 12th September 2024, CyberNewsWire

Hackread – Latest Cybersecurity, Tech, Crypto & Hacking News – ​Read More

Flipper Zero gets a big firmware upgrade, and some amazing new features

After three years of development, the portable hacking tool gets its first major firmware update – to version 1.0!

Latest stories for ZDNET in Security – ​Read More