Author Archives: [email protected]

Windows 11 beta users can access Copilot by hovering, explains why “Show Desktop” was turned off

After we covered that the latest Windows 11 Beta channel will now document changes in two separate categories, the first being Gradual Rollout, where new features and updates will be released gradually to Beta Channel users, and the second being Opt-in for Early Access, where users who want to be among the first to try new features can enable […]

U.S. Cracks Down on Predatory Spyware Firm for Targeting Officials and Journalists

The U.S. Department of Treasury’s Office of Foreign Assets Control (OFAC) sanctioned two individuals and five entities associated with the Intellexa Alliance for their role in “developing, operating, and distributing” commercial spyware designed to target government officials, journalists, and policy experts in the country. “The proliferation of commercial spyware poses distinct and growing

VMware Issues Security Patches for ESXi, Workstation, and Fusion Flaws

VMware has released patches to address four security flaws impacting ESXi, Workstation, and Fusion, including two critical flaws that could lead to code execution. Tracked as CVE-2024-22252 and CVE-2024-22253, the vulnerabilities have been described as use-after-free bugs in the XHCI USB controller. They carry a CVSS score of 9.3 for Workstation and Fusion, and 8.4 for […]

Alert: GhostSec and Stormous Launch Joint Ransomware Attacks in Over 15 Countries

The cybercrime group called GhostSec has been linked to a Golang variant of a ransomware family called GhostLocker. “TheGhostSec and Stormous ransomware groups are jointly conducting double extortion ransomware attacks on various business verticals in multiple countries,” Cisco Talos researcher Chetan Raghuprasad said in a report shared with The Hacker News. “GhostLocker and

New APT Group ‘Lotus Bane’ Behind Recent Attacks on Vietnam’s Financial Entities

A financial entity in Vietnam was the target of a previously undocumented threat actor called Lotus Bane that was first detected in March 2023. Singapore-headquartered Group-IB described the hacking outfit as an advanced persistent threat group that’s believed to have been active since at least 2022. The exact specifics of the infection chain remain unknown as yet, […]

Apple: Forget about third-party app store app updates if you’re leaving the EU for “too long”

iPhone users in the European Union can now download apps from alternative app stores for the first time, thanks to the new iOS 17.4 update but mostly thanks to DMA). Digital Markets Act aims to promote fair competition in the digital market. However, there’s a catch: if you’re planning to go on a ‘longer’ vacation, […]

Urgent: Apple Issues Critical Updates for Actively Exploited Zero-Day Flaws

Apple has released security updates to address several security flaws, including two vulnerabilities that it said have been actively exploited in the wild. The shortcomings are listed below – CVE-2024-23225 – A memory corruption issue in Kernel that an attacker with arbitrary kernel read and write capability can exploit to bypass kernel memory protections CVE-2024-23296 – A […]

CISA issued a warning for a vulnerability in Microsoft Streaming; being exploited by malware attackers

The Cybersecurity and Infrastructure Security Agency (CISA) is urging all organizations, especially federal agencies of countries, to patch a critical vulnerability in the Microsoft Streaming Service (MSKSSRV.SYS) that attackers are actively and extensively exploiting. The vulnerability goes by the ID CVE-2023-29360. What it does is it allows local attackers to gain full control (SYSTEM privileges) […]

Microsoft Edge to deliver ads to users keeping their data safe, Privacy-Preserving Ads API coming

Third-party cookies have long been used for targeted advertising, but on the other hand, they also raise privacy concerns. And due to it, users often lack transparency about how their data is collected and shared. To address this, web browsers are moving away from third-party cookies altogether. The announcement of the new Privacy-Preserving Ads API […]

Cybersecurity top revenue driver for bulk of MSPs, Kaseya report finds

Kaseya, a provider of unified IT management and security software for managed service providers (MSPs) and small to midsize business (SMBs), today released its 2024 MSP Benchmark Report, which surveyed close to 1,000 MSPs from the Americas, EMEA (Europe, Middle East and Africa) and APAC (Asia Pacific) regions and includes responses from both IT professionals […]