Cybersecurity researchers at Reason Labs, the threat research arm of security solutions provider Reason Cybersecurity, today disclosed details of a vulnerability they recently discovered in the Facebook Messenger application for Windows.The vulnerability, which resides in Messenger version 460.16, could allow attackers to leverage the app to potentially execute malicious files … [Read more...] about A Bug in Facebook Messenger for Windows Could’ve Helped Malware Gain Persistence
windows
Apple iTunes and iCloud for Windows 0-Day Exploited in Ransomware Attacks
Watch out Windows users!The cybercriminal group behind BitPaymer and iEncrypt ransomware attacks has been found exploiting a zero-day vulnerability affecting a little-known component that comes bundled with Apple's iTunes and iCloud software for Windows to evade antivirus detection.The vulnerable component in question is the Bonjour updater, a zero-configuration implementation … [Read more...] about Apple iTunes and iCloud for Windows 0-Day Exploited in Ransomware Attacks
Smominru botnet attacks outdated Windows systems with EternalBlue
Active since 2017, Smominru has now become one of the most rapidly spreading computer malware, according to a publicly available report. In 2019, during August alone, it infected 90,000 machines worldwide, with an infection rate of up to 4,700 сcomputers per day. China, Taiwan, Russia, Brazil, and the US have seen the most attacks, but that doesn’t mean other countries are out … [Read more...] about Smominru botnet attacks outdated Windows systems with EternalBlue
New Malware Uses Windows BITS Service to Stealthy Exfiltrate Data
Cybersecurity researchers have discovered a new computer virus associated with the Stealth Falcon state-sponsored cyber espionage group that abuses a built-in component of the Microsoft Windows operating system to stealthily exfiltrate stolen data to attacker-controlled server.Active since 2012, Stealth Falcon is a sophisticated hacking group known for targeting journalists, … [Read more...] about New Malware Uses Windows BITS Service to Stealthy Exfiltrate Data
Google Discloses 20-Year-Old Unpatched Flaw Affecting All Versions of Windows
Update — With this month's patch Tuesday updates, Microsoft has finally addressed this vulnerability, tracked as CVE-2019-1162, by correcting how the Windows operating system handles calls to Advanced Local Procedure Call (ALPC). A Google security researcher has just disclosed details of a 20-year-old unpatched high-severity vulnerability affecting all versions of Microsoft … [Read more...] about Google Discloses 20-Year-Old Unpatched Flaw Affecting All Versions of Windows
FinSpy is spyware for Android, iOS, Windows, and macOS
What happens when spyware is developed not by underground malware coders, but by a serious IT firm? The result can be a nasty thing like FinSpy (also known as FinFisher), which has been developed and sold perfectly legally for quite some time now. Over the past year, we’ve detected this spyware on dozens of mobile devices. What FinSpy gets up to Although a desktop version of … [Read more...] about FinSpy is spyware for Android, iOS, Windows, and macOS
Hacker Discloses Second Zero-Day to Bypass Patch for Windows EoP Flaw
An anonymous security researcher going by the name of SandboxEscaper today publicly shared a second zero-day exploit that can be used to bypass a recently patched elevation of privilege vulnerability in the Microsoft Windows operating system.SandboxEscaper is known for publicly dropping zero-day exploits for unpatched Windows vulnerabilities. In the past year, the hacker has … [Read more...] about Hacker Discloses Second Zero-Day to Bypass Patch for Windows EoP Flaw
Unpatched Bug Let Attackers Bypass Windows Lock Screen On RDP Sessions
A security researcher today revealed details of a newly unpatched vulnerability in Microsoft Windows Remote Desktop Protocol (RDP).Tracked as CVE-2019-9510, the reported vulnerability could allow client-side attackers to bypass the lock screen on remote desktop (RD) sessions.Discovered by Joe Tammariello of Carnegie Mellon University Software Engineering Institute (SEI), the … [Read more...] about Unpatched Bug Let Attackers Bypass Windows Lock Screen On RDP Sessions
PoC Exploit For Unpatched Windows 10 Zero-Day Flaw Published Online
An anonymous hacker with an online alias "SandboxEscaper" today released proof-of-concept (PoC) exploit code for a new zero-day vulnerability affecting Windows 10 operating system—that's his/her 5th publicly disclosed Windows zero-day exploit [1, 2, 3] in less than a year.Published on GitHub, the new Windows 10 zero-day vulnerability is a privilege escalation issue that could … [Read more...] about PoC Exploit For Unpatched Windows 10 Zero-Day Flaw Published Online
Duet Display Update Now with Support for Windows
Duet Display has been updated with support for using the iPad as a secondary display for Windows computers. To celebrate the occasion, the app is 40% for today only. [appstore id=935754064] Duet Display allows you to use your iPad or iPhone as an extra display. Developed by a team of ex-Apple engineers, duet is the first high performance solution that has … [Read more...] about Duet Display Update Now with Support for Windows