Microsoft’s Emergency Patch Fails to Fully Fix PrintNightmare RCE Vulnerability

Blog WriterThe Hacker News - Original news source is thehackernews.com

Even as Microsoft expanded patches for the so-called PrintNightmare vulnerability for Windows 10 version 1607, Windows Server 2012, and Windows Server 2016, it has come to light that the fix for the …

Dozens of Vulnerable NuGet Packages Allow Attackers to Target .NET Platform

Blog WriterThe Hacker News - Original news source is thehackernews.com

An analysis of off-the-shelf packages hosted on the NuGet repository has revealed 51 unique software components to be vulnerable to actively exploited, high-severity vulnerabilities, once again underscoring the threat posed …

Microsoft Issues Emergency Patch for Critical Windows PrintNightmare Vulnerability

Blog WriterThe Hacker News - Original news source is thehackernews.com

Microsoft has shipped an emergency out-of-band security update to address a critical zero-day vulnerability — known as “PrintNightmare” — that affects the Windows Print Spooler service and can permit remote threat actors …

Interpol Arrests Moroccan Hacker Engaged in Nefarious Cyber Activities

Blog WriterThe Hacker News - Original news source is thehackernews.com

Law enforcement authorities with the Interpol have apprehended a threat actor responsible for targeting thousands of unwitting victims over several years and staging malware attacks on telecom companies, major banks, …

Kaseya Rules Out Supply-Chain Attack; Says VSA 0-Day Hit Its Customers Directly

Blog WriterThe Hacker News - Original news source is thehackernews.com

U.S. technology firm Kaseya, which is firefighting the largest ever supply-chain ransomware strike on its VSA on-premises product, ruled out the possibility that its codebase was unauthorizedly tampered with to distribute malware. …

TrickBot Botnet Found Deploying A New Ransomware Called Diavol

Blog WriterThe Hacker News - Original news source is thehackernews.com

Threat actors behind the infamous TrickBot malware have been linked to a new ransomware strain named “Diavol,” according to the latest research. Diavol and Conti ransomware payloads were deployed on different systems …

Microsoft Urges Azure Users to Update PowerShell to Patch RCE Flaw

Blog WriterThe Hacker News - Original news source is thehackernews.com

Microsoft is urging Azure users to update the PowerShell command-line tool as soon as possible to protect against a critical remote code execution vulnerability impacting .NET Core. The issue, tracked as CVE-2021-26701 (CVSS score: …