For iOS was discovered a new exploit, with the help of which China traced the Uyghurs

Specialists of the information security company Volexity discovered a new exploit for iOS called Insomnia. According to the researchers, the malware associated with the efforts of the Chinese authorities to trace the Muslim national minority, the Uyghurs, who live mainly in Xinjiang province. Researchers say that Insomnia works against iOS versions 12.3, 12.3.1 and 12.3.2.… Continue reading For iOS was discovered a new exploit, with the help of which China traced the Uyghurs

Conspiracy theorists accused Bill Gates in creating coronavirus

Microsoft founder Bill Gates fell victim of fake theories that he was allegedly involved in the creation of the coronavirus COVID-19. In fact, conspiracy theorists accused Bill Gates in creation of a coronavirus and intention to achieve material benefits from the pandemic. At TED conference in 2015, Bill Gates argued that the greatest threat to… Continue reading Conspiracy theorists accused Bill Gates in creating coronavirus

GitHub warned users about phishing attack

Representatives of the GitHub web service warned users of a massive phishing attack called Sawfish. Recently, users more and more often receive phishing emails with fake warnings about suspicious activity of a recorded account or strange changes made to the repository or settings. “The links attached to such messages lead to a fake GitHub login… Continue reading GitHub warned users about phishing attack

More than 700 malicious libraries detected in RubyGems repository

Information security researchers at ReversingLabs reported the discovery of 725 malicious libraries that stole the contents of the clipboard in the official RubyGems repository. RubyGems is a package manager for the Ruby programming language. According to their own site statistics, the repository contains around 158 thousand packages (called gems) with nearly 49 billion total downloads.… Continue reading More than 700 malicious libraries detected in RubyGems repository

Hoaxcalls botnet attacks Grandstream devices

Palo Alto Networks experts warn that the Hoaxcalls botnet attacks the recently fixed vulnerability in the Grandstream UCM6200 series devices. The Hoaxcalls botnet is built on the source code of the Gafgyt/Bashlite malware and is mainly used for DDoS attacks. “The malware is built on the Gafgyt/Bashlite malware family codebase, which we have dubbed “Hoaxcalls”,… Continue reading Hoaxcalls botnet attacks Grandstream devices

Due to the pandemic Google developers re-enabled FTP support for Chrome

Most recently, I wrote that Firefox developers plan to remove from their browser support for the FTP protocol, as consider it to be unsafe. At the same time, Google re-enabled FTP support for Chrome. Google developers have been talking about abandoning FTP since 2014, since very few browser users (0.1-0.2%) use the protocol. In 2018,… Continue reading Due to the pandemic Google developers re-enabled FTP support for Chrome

COVID-19 pandemic raised interest in pirated sites

Currently, hundreds of millions of people remain at home and occur global changes in the Internet traffic trends. In particular, because of the COVID-19 pandemic, raised interest in pirated sites. The fact is that considerable part of the population now works from home, while other people also stay at home, but spend time online searching… Continue reading COVID-19 pandemic raised interest in pirated sites

Microsoft bought the domain Corp.com, so criminals would not do it

The well-known IS journalist Brian Krebs drew attention to an interesting fact: this week Microsoft bought the domain Corp.com, so that criminals would not do it. The sum of transaction is not disclosed. Krebs first turned his attention to this domain when a man named Mike O’Connor, who owned it for 26 years, put it… Continue reading Microsoft bought the domain Corp.com, so criminals would not do it

NASA staff faces exponential increase in number of hacker attacks

Representatives of the space agency said that recently NASA staff and home-based agency contractors suffered from increase in the number of hacker attacks, and their devices are constantly trying to gain access to malicious sites. Therefore, according to official figures, in recent days, NASA personnel have been suffering from: doubling the number of phishing attacks… Continue reading NASA staff faces exponential increase in number of hacker attacks

82.5% of Microsoft Exchange servers are still vulnerable

Information security experts from Rapid7 reported that more than 35,000 Internet-connected Microsoft Exchange servers are still vulnerable to the critical vulnerability CVE-2020-0688 that was fixed in February. The vulnerability affects the default Exchange Control Panel (ECP) component and allows an attacker to take control of a Microsoft Exchange server using previously stolen valid email credentials.… Continue reading 82.5% of Microsoft Exchange servers are still vulnerable