Skip to content
Security matters
Security matters
  • APTs
  • Tijdlijn
  • Kill chain
  • Uitgelicht
  • Privacy
Security matters

Tag: 2024

Chrome Security Vulnerabilities Let Attackers Execute Arbitrary Code

post, oktober 3, 2024

Google has released a critical security update for its Chrome browser, addressing multiple high-severity vulnerabilities that could potentially allow attackers to execute arbitrary code on users’ systems. The latest stable channel update, version 129.0.6668.89/.90 for Windows and Mac and 129.0.6668.89 for Linux, is being rolled out to users worldwide.

Continue Reading

PoC Exploit Released for Microsoft Office 0-day Flaw – CVE-2024-38200

post, oktober 3, 2024

Security researchers have released a proof-of-concept (PoC) exploit for the recently disclosed Microsoft Office vulnerability CVE-2024-38200, which could allow attackers to capture users’ NTLMv2 hashes. This high-severity flaw affects multiple versions of Microsoft Office, including Office 2016, Office 2019, Office LTSC 2021, and Microsoft 365 Apps for Enterprise.

Continue Reading

Three Iranian Hackers Charged for Influencing Trump Election Campaign

post, september 30, 2024

The U.S. Department of Justice has unsealed an indictment against three Iranian nationals linked to the Islamic Revolutionary Guard Corps (IRGC) for their alleged involvement in a “hack-and-leak” operation aimed at influencing the 2024 U.S. presidential election. The accused, Masoud Jalili, Seyyed Ali Aghamiri, and Yaser Balaghi, are charged with a…

Continue Reading

Chinese Hackers Infiltrate U.S. Internet Providers in Cyber Espionage Campaign

post, september 26, 2024september 26, 2024

Nation-state threat actors backed by Beijing broke into a “handful” of U.S. internet service providers (ISPs) as part of a cyber espionage campaign orchestrated to glean sensitive information, The Wall Street Journal reported Wednesday. The activity has been attributed to a threat actor that Microsoft tracks as Salt Typhoon, which is also…

Continue Reading

Chinese Hackers Exploit GeoServer Flaw to Target APAC Nations with EAGLEDOOR Malware

post, september 23, 2024

A suspected advanced persistent threat (APT) originating from China targeted a government organization in Taiwan, and possibly other countries in the Asia-Pacific (APAC) region, by exploiting a recently patched critical security flaw impacting OSGeo GeoServer GeoTools. “They used advanced techniques like GeoServer exploitation, spear-phishing, and customized malware (Cobalt Strike and…

Continue Reading

Move over, Cobalt Strike. Splinter’s the new post-exploit menace in town

post, september 23, 2024februari 24, 2025

Attackers are using Splinter, a new post-exploitation tool, to wreak havoc in victims’ IT environments after initial infiltration, utilizing capabilities such as executing Windows commands, stealing files, collecting cloud service account info, and downloading additional malware onto victims’ systems. Then the malicious code self-deletes, according to Palo Alto Networks’ Unit…

Continue Reading

Apple’s latest macOS release is breaking security software, network connections

post, september 23, 2024september 23, 2024

Something’s wrong with macOS Sequoia, and it’s breaking security software installed on some updated Apple systems. Sequoia, aka macOS 15, was released on Monday of last week. By Thursday, reports of problems with security products – from vendors including CrowdStrike and Microsoft – had begun to pile up with no…

Continue Reading

Planned Parenthood confirms cyberattack as RansomHub claims breach

post, september 5, 2024

Planned Parenthood has confirmed it suffered a cyberattack affecting its IT systems, forcing it to take parts of its infrastructure offline to contain the damage. Planned Parenthood is a New York-based nonprofit organization that provides a range of reproductive health care services, education, and advocacy for birth control. It is…

Continue Reading

White House seizes 32 domains, issues criminal charges in massive election-meddling crackdown

post, september 5, 2024

The Biden administration on Wednesday seized 32 websites and charged two employees of a state-owned media outlet connected to a $10 million scheme to distribute pro-Kremlin propaganda, and claimed the actions were necessary to counter Russia’s attempts to influence the upcoming US presidential election. This is all part of the…

Continue Reading

New Flaws in Microsoft macOS Apps Could Allow Hackers to Gain Unrestricted Access

post, september 3, 2024februari 24, 2025

Eight vulnerabilities have been uncovered in Microsoft applications for macOS that an adversary could exploit to gain elevated privileges or access sensitive data by circumventing the operating system’s permissions-based model, which revolves around the Transparency, Consent, and Control (TCC) framework. “If successful, the adversary could gain any privileges already granted…

Continue Reading
  • Previous
  • 1
  • …
  • 3
  • 4
  • 5
  • …
  • 12
  • Next

2020 2023 2024 2025 2026 China Iran North Korea Russia ShinyHunters

©2026 Security matters | WordPress Theme by SuperbThemes