Details have emerged about a now-patched security flaw in Windows Common Log File System (CLFS) that could be exploited by an attacker to gain elevated permissions on compromised machines. Tracked as CVE-2022-37969 (CVSS score: 7.8), the issue was addressed by Microsoft as part of its Patch Tuesday updates for September 2022, while also noting that it was being actively … [Read more...] about Researchers Reveal Detail for Windows Zero-Day Vulnerability Patched Last Month
Month
Out today: Defending against critical threats: A 12 month roundup
Today we launch our brand new publication, Defending Against Critical Threats: A 12 month roundup. Click to readDefending Against Critical Threats: A 12 month roundupInside, we take a retrospective look at cyber threats, and how they have evolved in the last 12 months. In something a little different to our previous reports, we’ve designed this in a magazine style format to … [Read more...] about Out today: Defending against critical threats: A 12 month roundup
Smominru Botnet Indiscriminately Hacked Over 90,000 Computers Just Last Month
Insecure Internet-connected devices have aided different types of cybercrime for years, most common being DDoS and spam campaigns. But cybercriminals have now shifted toward a profitable scheme where botnets do not just launch DDoS or spam—they mine cryptocurrencies as well.Smominru, an infamous cryptocurrency-mining and credential-stealing botnet, has become one of the rapidly … [Read more...] about Smominru Botnet Indiscriminately Hacked Over 90,000 Computers Just Last Month
Two Florida Cities Paid $1.1 Million to Ransomware Hackers This Month
In the last two weeks, Florida has paid more than $1.1 million in bitcoin to cybercriminals to recover encrypted files from two separate ransomware attacks—one against Riviera Beach and the other against Lake City.Lake City, a city in northern Florida, agreed on Monday to pay hackers 42 Bitcoin (equivalent to $573,300 at the current value) to unlock phone and email systems … [Read more...] about Two Florida Cities Paid $1.1 Million to Ransomware Hackers This Month
PoC Released for Outlook Flaw that Microsoft Patched 6 Month After Discovery
As we reported two days ago, Microsoft this week released an updated version of its Outlook app for Android that patches a severe remote code execution vulnerability (CVE-2019-1105) that impacted over 100 million users.However, at that time, very few details of the flaw were available in the advisory, which just revealed that the earlier versions of the email app contained a … [Read more...] about PoC Released for Outlook Flaw that Microsoft Patched 6 Month After Discovery