Intel Confirms Its Much-Loathed ME Feature Has A Kill Switch

A previously undocumented kill switch for a remote management feature baked into many Intel chips can be switched off. Source: Threadpost

Volkswagen Cars Open To Remote Hacking, Researchers Warn

Vulnerable in-vehicle infotainment systems have left some Volkswagen cars open to remote hacking, researchers warn. Source: Threadpost

ShadowBrokers Planning Monthly Exploit, Data Dump Service

The latest rant from the ShadowBrokers ends with news of a subscription service starting in June that will leak exploits and stolen data to paying customers. Source: Threadpost

Malvertising Campaigns Skirt Ad Blockers, Serve Up Mac Malware

The RIG exploit kit and Safari redirects are both in the adversaries' bag of tricks. Source: Threadpost

Black Friday alert

Banking Trojans traditionally target users of online financial services; looking for financial data to steal or building botnets out of hacked devices for future attacks. However, over time, several of these...

Cisco Warns of Three Critical Bugs in Digital Network Architecture Platform

The company urges customers to patch three vulnerabilities that received the highest severity rating of 10. Source: Threadpost

Roaming Mantis, part IV

One year has passed since we published the first blogpost about the Roaming Mantis campaign on securelist.com, and this February we detected new activities by the group. This blogpost is follow...

Hackers Take Aim at SSH Keys in New Attacks

SSH private keys are being targeted by hackers who have stepped up the scanning of thousands of WordPress website in search of private keys. Source: Threadpost

Google Play Boots Three Malicious Apps From Marketplace Tied to APTs

Researchers said three apps used to surveil Middle East targets were booted from the Google Play marketplace. Source: Threadpost

Google Chrome Bugs Open Browsers to Attack

Google's new release of Chrome 85.0.4183.121 for Windows, Mac, and Linux fixes 10 security flaws. Source: Threadpost
- Advertisement -

APLICATIONS

Critical SonicWall VPN Portal Bug Allows DoS, Worming RCE

The CVE-2020-5135 stack-based buffer overflow security vulnerability is trivial to exploit, without logging in. Source: Threadpost