Zyxel Fixes 0day in Network Storage Devices

Credit to Author: BrianKrebs| Date: Mon, 24 Feb 2020 17:13:11 +0000

Networking hardware vendor Zyxel today released an update to fix a critical flaw in many of its network attached storage (NAS) devices that can be used to remotely commandeer them. The patch comes 12 days after KrebsOnSecurity alerted the company that precise instructions for exploiting the vulnerability were being sold for $20,000 in the cybercrime underground. Based in Taiwan, Zyxel Communications Corp. (a.k.a “ZyXEL”) is a maker of networking devices, including Wi-Fi routers, NAS products and hardware firewalls. The company has roughly 1,500 employees and boasts some 100 million devices deployed worldwide. While in many respects the class of vulnerability addressed in this story is depressingly common among Internet of Things (IoT) devices, the flaw is notable because it has attracted the interest of groups specializing in deploying ransomware at scale.

Read more

December Patch Tuesday blunts WizardOpium attack chain

Credit to Author: John E Dunn| Date: Thu, 12 Dec 2019 10:42:32 +0000

December 2019’s Patch Tuesday updates are, including a fix for the Windows flaw used in recently discovered WizardOpium attacks.<img src=”http://feeds.feedburner.com/~r/nakedsecurity/~4/PoQEqUB0h3I” height=”1″ width=”1″ alt=””/>

Read more

Server-squashing zero-day published for phpMyAdmin tool

Credit to Author: Danny Bradbury| Date: Fri, 20 Sep 2019 12:22:50 +0000

A researcher has just published a zero-day security bug in one of the web’s most popular database administration software packages.<img src=”http://feeds.feedburner.com/~r/nakedsecurity/~4/XxpMh0dUMaQ” height=”1″ width=”1″ alt=””/>

Read more

September 2019’s Patch Tuesday: 2 zero-days, 17 critical bugs

Credit to Author: John E Dunn| Date: Thu, 12 Sep 2019 11:33:58 +0000

Sometimes, a Patch Tuesday update arrives with a bang that sends users scrambling for cover – September’s update earns that description.<img src=”http://feeds.feedburner.com/~r/nakedsecurity/~4/lRHTsM8cImQ” height=”1″ width=”1″ alt=””/>

Read more

iPhone attack may have targeted Android and Windows too

Credit to Author: John E Dunn| Date: Tue, 03 Sep 2019 14:47:23 +0000

A sophisticated and sustained watering hole attack affecting iPhones may have targeted Windows and Android too.<img src=”http://feeds.feedburner.com/~r/nakedsecurity/~4/3wCw5XE352c” height=”1″ width=”1″ alt=””/>

Read more

Unprecedented new iPhone malware discovered

Credit to Author: Thomas Reed| Date: Fri, 30 Aug 2019 17:40:24 +0000

Google announced late last night that hacked websites have been used to drop iPhone malware on unsuspecting users over a two-year period. Thomas Reed investigates.

Categories:

Tags:

(Read more…)

The post Unprecedented new iPhone malware discovered appeared first on Malwarebytes Labs.

Read more