LockFile Ransomware Bypasses Protection Using Intermittent File Encryption

Blog WriterThe Hacker News - Original news source is thehackernews.com

A new ransomware family that emerged last month comes with its own bag of tricks to bypass ransomware protection by leveraging a novel technique called “intermittent encryption.” Called LockFile, the operators …

Kaseya Issues Patches for Two New 0-Day Flaws Affecting Unitrends Servers

Blog WriterThe Hacker News - Original news source is thehackernews.com

U.S. technology firm Kaseya has released security patches to address two zero-day vulnerabilities affecting its Unitrends enterprise backup and continuity solution that could result in privilege escalation and authenticated remote code execution. …

Microsoft, Google to Invest $30 Billion in Cybersecurity Over Next 5 Years

Blog WriterThe Hacker News - Original news source is thehackernews.com

Google and Microsoft said they are pledging to invest a total of $30 billion in cybersecurity advancements over the next five years, as the U.S. government partners with private sector companies to …

The Increased Liability of Local In-home Propagation

Blog WriterThe Hacker News - Original news source is thehackernews.com

Today I discuss an attack vector conducive to cross-organizational spread, in-home local propagation. Though often overlooked, this vector is especially relevant today, as many corporate employees remain working from home. …

Critical Cosmos Database Flaw Affected Thousands of Microsoft Azure Customers

Blog WriterThe Hacker News - Original news source is thehackernews.com

Cloud infrastructure security company Wiz on Thursday revealed details of a now-fixed Azure Cosmos database vulnerability that could have been potentially exploited to grant any Azure user full admin access …

F5 Releases Critical Security Patch for BIG-IP and BIG-IQ Devices

Blog WriterThe Hacker News - Original news source is thehackernews.com

Enterprise security and network appliance vendor F5 has released patches for more than two dozen security vulnerabilities affecting multiple versions of BIG-IP and BIG-IQ devices that could potentially allow an attacker to …

New Passwordless Verification API Uses SIM Security for Zero Trust Remote Access

Blog WriterThe Hacker News - Original news source is thehackernews.com

Forget watercooler conspiracies or boardroom battles. There’s a new war in the office. As companies nudge their staff to return to communal workspaces, many workers don’t actually want to – …

VMware Issues Patches to Fix New Flaws Affecting Multiple Products

Blog WriterThe Hacker News - Original news source is thehackernews.com

VMware on Wednesday shipped security updates to address vulnerabilities in multiple products that could be potentially exploited by an attacker to take control of an affected system. The six security weaknesses (from …

Critical Flaw Discovered in Cisco APIC for Switches — Patch Released

Blog WriterThe Hacker News - Original news source is thehackernews.com

Cisco Systems on Wednesday issued patches to address a critical security vulnerability affecting the Application Policy Infrastructure Controller (APIC) interface used in its Nexus 9000 Series Switches that could be …

Researchers Uncover FIN8’s New Backdoor Targeting Financial Institutions

Blog WriterThe Hacker News - Original news source is thehackernews.com

A financially motivated threat actor notorious for setting its sights on retail, hospitality, and entertainment industries has been observed deploying a completely new backdoor on infected systems, indicating the operators …