Hackers Exploit Signal’s Linked Devices Feature to Hijack Accounts via Malicious QR Codes post, februari 19, 2025februari 24, 2025 Multiple Russia-aligned threat actors have been observed targeting individuals of interest via the privacy-focused messaging app Signal to gain unauthorized access to their accounts. “The most novel and widely used technique underpinning Russian-aligned attempts to compromise Signal accounts is the abuse of the app’s legitimate ‘linked devices’ feature that enables… Continue Reading
Single Right-Click Let Hackers Gain Access To System By Exploiting 0-Day post, november 14, 2024februari 24, 2025 A newly discovered 0-day vulnerability in Windows systems, CVE-2024-43451, has been actively exploited by suspected Russian hackers to target Ukrainian entities. This 0-day flaw, identified by security analysts at ClearSky Cyber Security in June 2024, allows attackers to gain unauthorized access to systems through minimal user interaction. Continue Reading
China Possibly Hacking US “Lawful Access” Backdoor post, oktober 8, 2024februari 24, 2025 The Wall Street Journal is reporting that Chinese hackers (Salt Typhoon) penetrated the networks of US broadband providers, and might have accessed the backdoors that the federal government uses to execute court-authorized wiretap requests. Those backdoors have been mandated by law—CALEA—since 1994. It’s a weird story. The first line of the article is: “A… Continue Reading
North Korean Hackers Using New VeilShell Backdoor in Stealthy Cyber Attacks post, oktober 3, 2024juli 3, 2025 Threat actors with ties to North Korea have been observed delivering a previously undocumented backdoor and remote access trojan (RAT) called VeilShell as part of a campaign targeting Cambodia and likely other Southeast Asian countries. The activity, dubbed SHROUDED#SLEEP by Securonix, is believed to be the handiwork of APT37, which is also known… Continue Reading
New Flaws in Microsoft macOS Apps Could Allow Hackers to Gain Unrestricted Access post, september 3, 2024februari 24, 2025 Eight vulnerabilities have been uncovered in Microsoft applications for macOS that an adversary could exploit to gain elevated privileges or access sensitive data by circumventing the operating system’s permissions-based model, which revolves around the Transparency, Consent, and Control (TCC) framework. “If successful, the adversary could gain any privileges already granted… Continue Reading
Hardcoded Credential Vulnerability Found in SolarWinds Web Help Desk post, augustus 22, 2024februari 24, 2025 SolarWinds has issued patches to address a new security flaw in its Web Help Desk (WHD) software that could allow remote unauthenticated users to gain unauthorized access to susceptible instances. “The SolarWinds Web Help Desk (WHD) software is affected by a hardcoded credential vulnerability, allowing [a] remote unauthenticated user to… Continue Reading
VMware ESXi flaw exploited post, juli 30, 2024februari 24, 2025 A recently patched security flaw impacting VMware ESXi hypervisors has been actively exploited by “several” ransomware groups to gain elevated permissions and deploy file-encrypting malware. The attacks involve the exploitation of CVE-2024-37085 (CVSS score: 6.8), an Active Directory integration authentication bypass that allows an attacker to obtain administrative access to the host. Continue Reading