Named Pipes Under Attack: Securing Windows Interprocess Communication

Windows Named Pipes Under Attack: A Growing Security Concern In recent months, cybersecurity experts have sounded the alarm over a growing threat to Windows systems: unsecured named pipes. These pipes, used for communication between applications on the same computer, are increasingly being exploited by attackers. With potentially devastating consequences, it’s essential for administrators and developers … Read more

Named Pipes Under Attack: Securing Windows Interprocess Communication

Windows Named Pipes Under Attack: A Wake-Up Call for Developers and Admins Named pipes are a common communication mechanism between applications on the same Windows computer. They’re fast, reliable, and supported directly by the operating system. However, recent attacks have highlighted a disturbing trend: named pipes are not as secure as they seem. When a … Read more

Hackers infect Android car head units with proxy botnet malware

A sophisticated supply-chain attack has compromised thousands of Android-based car head units, turning them into proxy botnets or using them for ad fraud. The malware, attributed to the notorious MoYu group, was spread through a legitimate device-update app and allows attackers to remotely control infected devices. The target of the attack is DoFun, a Chinese … Read more

TikTok Agrees to $400 Million Settlement in U.S. Child Privacy Lawsuit

TikTok, a social media platform with over a billion active users worldwide, has agreed to pay $400 million in settlement fees to resolve a long-standing lawsuit filed by the U.S. Federal Trade Commission (FTC) and several state attorneys general. The lawsuit, which stems from allegations of violating the Children’s Online Privacy Protection Act (COPPA), marks … Read more

Banking Trojans Manic, Grandoreiro, ToxicPanda 2.0 in the Spotlight

Banking Trojans on the Rise: Manic, Grandoreiro, and ToxicPanda 2.0 Threaten Users Worldwide A new wave of sophisticated banking trojans has emerged, targeting users in various regions worldwide. These malware variants – Manic, Grandoreiro, and an updated version of ToxicPanda – are designed to phish credentials, steal sensitive data, and remotely control compromised devices, posing … Read more

Banking Trojans Manic, Grandoreiro, ToxicPanda 2.0 in the Spotlight

Cybersecurity companies have sounded the alarm about a trio of highly sophisticated banking trojans that are targeting users worldwide, with alarming ease. These malware programs can not only siphon sensitive user data and phish credentials but also grant their operators remote control over compromised devices. One of these trojans is called Manic, an Android malware … Read more

Who Got Missed in the MFA Rollout? More Powershell + Graph + Entra scripting!, (Fri, Aug 21st)

A Critical Oversight in Multi-Factor Authentication (MFA) Rollouts: PowerShell, Graph, and Entra Scripts Exposed Multi-factor authentication (MFA) is a crucial security control that adds an extra layer of protection to user logins. However, a recent discovery has highlighted a significant oversight in the MFA rollout process for many organizations, leaving them vulnerable to potential security … Read more

Lawmakers seek watchdog review of federal hacking of Americans

As lawmakers continue to scrutinize the use of hacking tools by the US government, two members of Congress are calling for a thorough investigation into how these powers are being used. Sen. Ron Wyden and Rep. Greg Casar have written to the Government Accountability Office (GAO) requesting a review of the federal government’s hacking activities, … Read more