This Week in Cyberspace (8-14 January 2022)
What happened in the cyber world this week? The prominent cyber security news of the week is with you...
Latest WordPress Security Release Fixes XSS, SQL Injection Bugs
The developers of WordPress have pushed out a security-focused update that addresses four significant security flaws in the content management software.
FBI: Hackers Use BadUSB to Target Defense Firms With Ransomware
The FBI has warned US companies that the financially motivated FIN7 cybercriminal group has packages containing malicious USB devices to distribute ransomware.
New ZLoader Malware Campaign Hit More Than 2000 Victims Across 111 Countries
A malware campaign is spreading ZLoader by exploiting a Windows vulnerability that was fixed in 2013 but Microsoft revised the fix in 2014.
Cyber-Spike: Orgs Suffer 925 Attacks per Week, an All-Time High
Cyberattacks increased 50 percent YoY in 2021 and peaked in December due to a frenzy of Log4j exploits, researchers found.
How the Pentagon Enlisted Ethical Hackers Amid the Log4j Crisis
The Pentagon has launched an ongoing bug bounty program to monitor Log4j vulnerabilities on thousands of potentially publicly available military websites.
Windows 10 KB5009543 & KB5009545 Updates Released
Microsoft has released two major cumulative updates for Windows 10 version 21H2, version 21H1 and version 20H2.
New SysJoker Espionage Malware Targeting Windows, macOS, and Linux Users
A new cross-platform backdoor named "SysJoker" has been observed targeting machines running Windows, Linux, and macOS operating systems.
Magniber Ransomware Using Signed APPX Files to Infect Systems
The Magniber ransomware has been spotted using Windows application package files (.APPX) signed with valid certificates to drop malware pretending to be Chrome and Edge web browser updates.
Apple Fixes doorLock Bug That Can Disable iPhones and iPads
Apple has released security updates to address a persistent denial of service (DoS) dubbed doorLock that would altogether disable iPhones and iPads running HomeKit on iOS 14.7 and later.
Mozilla Addresses High-Risk Firefox, Thunderbird Vulnerabilities
Mozilla addressed18 security vulnerabilities affecting the popular Firefox web browser and the Thunderbird mail program.
Chrome Will Limit Access to Private Networks, Citing Security Reasons
Google says that its Chrome browser will soon block internet websites from querying and interacting with devices and servers located inside local private networks, citing security reasons and past abuse from malware operations.
Cisco Releases Patch for Critical Bug Affecting Unified CCMP and Unified CCDM
Cisco Systems has rolled out security updates for a critical security vulnerability affecting Unified CCMP and Unified CCDM that could be exploited by a remote attacker to take control of an affected system.
Sign up for the e-mail list to be informed about the developments in the cyber world and to be informed about the weekly newsletter.