20 Sep, 2024

Clever ‘GitHub Scanner’ campaign abusing repos to push malware

A clever threat campaign is abusing GitHub repositories to distribute the Lumma Stealer password-stealing malware targeting users who frequent an open source project repository or are subscribed to email notifications from it. A malicious GitHub user opens a new “issue” on an open source repository falsely claiming that the project contains a “security vulnerability” and urges […]

4 mins read

Unexplained ‘Noise Storms’ flood the Internet, puzzle experts

Internet intelligence firm GreyNoise reports that it has been tracking large waves of “Noise Storms” containing spoofed internet traffic since January 2020. However, despite extensive analysis, it has not concluded its origin and purpose. These Noise Storms are suspected to be covert communications, DDoS attack coordination signals, clandestine command and control (C2) channels of malware operations, or the result […]

2 mins read

Temu denies breach after hacker claims theft of 87 million data records

Temu denies it was hacked or suffered a data breach after a threat actor claimed to be selling a stolen database containing 87 million records of customer information. The threat actor put the alleged data up for sale yesterday on the BreachForums hacking forum, along with a small sample to serve as proof of the stolen […]

3 mins read

PKfail Secure Boot bypass remains a significant risk two months later

Roughly nine percent of tested firmware images use non-production cryptographic keys that are publicly known or leaked in data breaches, leaving many Secure Boot devices vulnerable to UEFI bootkit malware attacks. Known as ‘PKfail,’ and now tracked as CVE-2024-8105, the supply chain attack is caused by test Secure Boot master key (Platform Key “PK”), which computer […]

2 mins read

Windows vulnerability abused braille “spaces” in zero-day attacks

A recently fixed “Windows MSHTML spoofing vulnerability” tracked under CVE-2024-43461 is now marked as previously exploited after it was used in attacks by the Void Banshee APT hacking group. When first disclosed as part of the September 2024 Patch Tuesday, Microsoft had not marked the vulnerability as previously exploited. However, on Friday, Microsoft updated the CVE-2024-43461 advisory to indicate it […]

4 mins read

iOS 18 AI Features: Full List of iPhones Supporting Apple Intelligence

iOS 18 is here, bringing new AI features to Apple’s iPhone lineup. The iPhone 16 series and iPhone 15 Pro / iPhone 15 Pro Max iPhones will support all the integrated Ai functions of iOS 18 (including Apple Intelligence), but all other models will have limited to no functionality when it comes to Apple Ai. The reason […]

5 mins read

FBI tells public to ignore false claims of hacked voter data

The Federal Bureau of Investigation (FBI) and the Cybersecurity and Infrastructure Security Agency (CISA) are alerting the public of false claims that the U.S. voter registration data has been compromised in cyberattacks. The two agencies note that malicious actors are spreading disinformation to manipulate public “opinion and undermine confidence in U.S. democratic institutions.” According to […]

3 mins read

How to Fix Preparing Automatic Repair Loop

If a Windows 10 or Windows 11 computer encounters a startup error, it may activate an automatic repair process called “Preparing Automatic Repair.” This function is designed to identify and resolve problems that are preventing the operating system from starting correctly. However, sometimes the repair process itself can get stuck in a loop when the […]

14 mins read

Reasons Why You Should Skip The iPhone 16 And Wait For Next Year’s iPhone 17

Apple brings some new iterations every year when it launches a new model for the iPhone lineup. The iPhone 16 has been long hyped even before it was showcased, and with the series finally being rolled out, we noticed the changes brought ahead this time around, especially with the Apple Intelligence being an integral part […]

4 mins read

RansomHub claims Kawasaki cyberattack, threatens to leak stolen data

Kawasaki Motors Europe has announced that it’s recovering from a cyberattack that caused service disruptions as the RansomHub ransomware gang threatens to leak stolen data. The company says the attack targeted its EU headquarters, and it is currently analyzing and cleaning any “suspicious material,” such as malware, that may still be lurking on systems. “At the […]

3 mins read