Dan Goodin - Page 4

108 Posts
0 Comments

384,000 sites pull code from sketchy code library recently bought by Chinese firm

EnlargeGetty Images More than 384,000 websites are linking to a site that was caught last week performing a supply-chain attack that redirected...

3 million iOS and macOS apps were exposed to potent supply-chain attacks

EnlargeAurich Lawson Vulnerabilities that went undetected for a decade left thousands of macOS and iOS apps susceptible to supply-chain attacks. Hackers could...

Critical MOVEit vulnerability puts huge swaths of the Internet at severe risk

Enlarge A critical vulnerability recently discovered in a widely used piece of software is putting huge swaths of the Internet at risk...

Backdoor slipped into multiple WordPress plugins in ongoing supply-chain attack

EnlargeGetty Images WordPress plugins running on as many as 36,000 websites have been backdoored in a supply-chain attack with unknown origins, security...

Ransomware attackers quickly weaponize PHP vulnerability with 9.8 severity rating

EnlargeGetty Images Ransomware criminals have quickly weaponized an easy-to-exploit vulnerability in the PHP programming language that executes malicious code on web servers,...

China state hackers infected 20,000 Fortinet VPNs, Dutch spy service says

Enlarge Hackers working for the Chinese government gained access to more than 20,000 VPN appliances sold by Fortinet using a critical vulnerability...

Hackers steal “significant volume” of data from hundreds of Snowflake customers

EnlargeGetty Images As many as 165 customers of cloud storage provider Snowflake have been compromised by a group that obtained login credentials...

Nasty bug with very simple exploit hits PHP just in time for the weekend

Enlarge A critical vulnerability in the PHP programming language can be trivially exploited to execute malicious code on Windows devices, security researchers...

Ticketmaster hacked in what’s believed to be a spree hitting Snowflake customers

EnlargeGetty Images Cloud storage provider Snowflake said that accounts belonging to multiple customers have been hacked after threat actors obtained credentials through...

US sanctions operators of “free VPN” that routed crime traffic through user PCs

EnlargeGetty Images The US Treasury Department has sanctioned three Chinese nationals for their involvement in a VPN-powered botnet with more than 19...

Latest articles