In a recent attack against a Ukrainian organization, Russian state-sponsored threat actor Turla leveraged legacy Andromeda malware likely deployed by other hackers via an infected USB drive, Mandiant reports.
User Documents Overwritten With Malicious Code in Recent Dridex Attacks on macOS
The cybercriminals behind the Dridex banking trojan have adopted a new tactic in recent attacks targeting macOS devices, overwriting the victim’s document files to deliver their malicious code, Trend Micro reports.
Ransomware Hit 200 US Gov, Education and Healthcare Organizations in 2022
More than 200 government, education, and healthcare organizations in the United States fell victim to ransomware in 2022, data gathered by cybersecurity firm Emsisoft shows.
Qualcomm UEFI Flaws Expose Microsoft, Lenovo, Samsung Devices to Attacks
Many devices made by Microsoft, Lenovo, Samsung and likely others are affected by potentially serious UEFI firmware vulnerabilities in Qualcomm Snapdragon chips.
Rackspace Completes Investigation Into Ransomware Attack
Cloud company Rackspace has completed its investigation into the recent ransomware attack and found that the hackers did access some customer resources.
France Regulator Raps Apple Over App Store Ads
France’s data regulator said Wednesday that it had fined Apple eight million euros ($8.5 million) for breaching privacy laws on its App Store.
The CNIL said the US tech giant had installed trackers on the devices of French users without directly asking their consent, allowing it to place targeted ads within the App Store.
More Political Storms for TikTok After US Government Ban
Predictions 2023: Big Tech’s Coming Security Shopping Spree
The SecurityWeek editorial team huddled over the holidays to look back at the stories that shaped 2022 and, more importantly, to stare into a shiny crystal ball to find the cybersecurity narratives that will dominate this year’s headlines.
Predictions 2023: Big Tech’s Coming Security Shopping Spree
The SecurityWeek editorial team huddled over the holidays to look back at the stories that shaped 2022 and, more importantly, to stare into a shiny crystal ball to find the cybersecurity narratives that will dominate this year’s headlines.
Zoho Urges ManageEngine Users to Patch Serious SQL Injection Vulnerability
Zoho this week announced patches for a high-severity SQL injection vulnerability in ManageEngine Password Manager Pro, PAM360, and Access Manager Plus.
ManageEngine is an enterprise software solution offering management capabilities for endpoints, enterprise services, identity and access, IT operations, and security information and events.













