ConnectWise warns of new ScreenConnect flaw without patch

A Critical Vulnerability in ScreenConnect Exposes Thousands of Systems to Attack ConnectWise, a leading provider of IT management software, has identified a security flaw in its popular remote access platform, ScreenConnect. The vulnerability allows attackers to exploit file transfer behavior in support and access sessions, potentially giving them unauthorized access to sensitive data. What’s more … Read more

Hackers exploit new MikroTik RouterOS flaws to hijack routers

MikroTik Router Flaw Allows Hackers to Hijack Routers, Warns Polish CERT Agency A critical vulnerability in MikroTik routers has been exploited by hackers to take control of devices with SSH services exposed to the internet. The flaw, dubbed “MikroTrick” by Poland’s CERT agency, is a chain of two vulnerabilities that allows attackers to bypass SSH … Read more

ChatGPT can now connect to your personal apps to mimic writing style

A new feature in OpenAI’s ChatGPT chatbot has raised eyebrows among cybersecurity experts and everyday users alike. The company is testing a “Writing Style” feature that allows ChatGPT to learn how you write by referencing examples from your connected apps, including email services like Gmail and messaging platforms like Slack. This capability sounds similar to … Read more

PEEP Turns Chrome and Edge Into Post-Compromise Backdoors for Host Command Execution

A New Breed of Threats Lurks in Popular Browsers, Exposing Users to Command Execution Attacks Cybersecurity researchers have uncovered a sophisticated threat actor’s exploit dubbed “PEEP” that silently turns Google Chrome and Microsoft Edge browsers into post-compromise backdoors. This means that once compromised, these browsers can be used by attackers to execute arbitrary system commands … Read more

Trezor data breach impact now reaches 81,000 customers

A Cryptocurrency Hardware Wallet Maker’s Data Breach Expands to Affect Over 81,000 Customers Cryptocurrency hardware wallet maker Trezor has announced that a recent data breach at its shipping and logistics provider, ShipMonk, has expanded to affect an additional 67,000 US customers. This brings the total number of affected customers to over 81,000. The initial breach … Read more

Mathspace discloses data breach affecting over 1 million people

Over 1 Million People’s Data Stolen in Mathspace Breach, with Attackers Linked to ShinyHunters Extortion Gang Mathspace, a popular online maths learning platform used by thousands of schools across Australia, New Zealand, and other countries, has disclosed a massive data breach that exposed the personal information of over 1 million students, staff, and parents. The … Read more

BigBear Microsoft 365 phishing service bypassed MFA at 258 organizations

A sophisticated phishing-as-a-service framework called BigBear 2.0 has been used to compromise the security of 258 organizations and steal over 5,000 Microsoft 365 credentials by bypassing multi-factor authentication (MFA). Researchers at CloudSEK gained access to the control panel of this malicious service and found that it was targeting Microsoft 365 users with a configuration called … Read more

Magento StyleSmuggler zero-day exploited to deploy Linux backdoor

Magento’s StyleSmuggler Zero-Day Exploited to Deploy Linux Backdoor, Leaving Thousands of Sites Vulnerable A severe security vulnerability known as StyleSmuggler has been discovered affecting all versions of Magento and Adobe Commerce. This zero-day exploit allows attackers to deploy a backdoor on compromised servers, leaving thousands of websites exposed. According to e-commerce security company Sansec, the … Read more

PEEP Turns Chrome and Edge Into Post-Compromise Backdoors for Host Command Execution

As a sophisticated threat actor, PEEP has managed to turn Chrome and Edge browsers into post-compromise backdoors for executing malicious commands on compromised systems. The technique exploits vulnerabilities in these popular web browsers, allowing hackers to secretly maintain access to infected machines even after they’ve been cleaned or reinstalled. At the heart of this exploit … Read more

Trezor data breach impact now reaches 81,000 customers

A major cryptocurrency hardware wallet maker has revealed that a recent data breach at its shipping and logistics provider has affected an additional 67,000 U.S. customers, bringing the total number of impacted individuals to 81,000. The incident highlights the need for companies to prioritize data protection and vigilance in their supply chains. The breach occurred … Read more