Critical Flaws Reported in Etherpad — a Popular Google Docs Alternative

Blog WriterThe Hacker News - Original news source is thehackernews.com

Cybersecurity researchers have disclosed new security vulnerabilities in the Etherpad text editor (version 1.8.13) that could potentially enable attackers to hijack administrator accounts, execute system commands, and even steal sensitive …

Chinese Hackers Exploit Latest SolarWinds 0-Day to Target U.S. Defense Firms

Blog WriterThe Hacker News - Original news source is thehackernews.com

Microsoft on Tuesday disclosed that the latest string of attacks targeting SolarWinds Serv-U managed file transfer service with a now-patched remote code execution (RCE) exploit is the handiwork of a …

Iranian Hackers Posing as Scholars Target Professors and Writers in Middle-East

Blog WriterThe Hacker News - Original news source is thehackernews.com

A sophisticated social engineering attack undertaken by an Iranian-state aligned actor targeted think tanks, journalists, and professors with an aim to solicit sensitive information by masquerading as scholars with the …

Trickbot Malware Returns with a new VNC Module to Spy on its Victims

Blog WriterThe Hacker News - Original news source is thehackernews.com

Cybersecurity researchers have opened the lid on the continued resurgence of the insidious Trickbot malware, making it clear that the Russia-based transnational cybercrime group is working behind the scenes to …

Critical RCE Flaw in ForgeRock Access Manager Under Active Attack

Blog WriterThe Hacker News - Original news source is thehackernews.com

Cybersecurity agencies in Australia and the U.S. are warning of an actively exploited vulnerability impacting ForgeRock’s OpenAM access management solution that could be leveraged to execute arbitrary code on an affected system …

Hackers Spread BIOPASS Malware via Chinese Online Gambling Sites

Blog WriterThe Hacker News - Original news source is thehackernews.com

Cybersecurity researchers are warning about a new malware that’s striking online gambling companies in China via a watering hole attack to deploy either Cobalt Strike beacons or a previously undocumented …

Kaseya Releases Patches for Flaws Exploited in Widespread Ransomware Attack

Blog WriterThe Hacker News - Original news source is thehackernews.com

Florida-based software vendor Kaseya on Sunday rolled out software updates to address critical security vulnerabilities in its Virtual System Administrator (VSA) software that was used as a jumping off point …

New SaaS Security Report Dives into the Concerns and Plans of CISOs in 2021

Blog WriterThe Hacker News - Original news source is thehackernews.com

For years, security professionals have recognized the need to enhance SaaS security. However, the exponential adoption of Software-as-a-Service (SaaS) applications over 2020 turned slow-burning embers into a raging fire.  Organizations …