‘Raspberry Robin’ Windows Worm Abuses QNAP Devices

‘raspberry-robin’-windows-worm-abuses-qnap-devices

A recently discovered Windows worm is abusing compromised QNAP network-attached storage (NAS) devices as stagers to spread to new systems, according to Cybereason.

Dubbed Raspberry Robin, the malware was initially spotted in September 2021, spreading mainly via removable devices, such as USB drives.

read more

OpenSSL Patches Remote Code Execution Vulnerability

openssl-patches-remote-code-execution-vulnerability

OpenSSL has issued an urgent advisory to warn of a memory corruption vulnerability that exposes servers to remote code execution attacks.

The vulnerability, tracked as CVE-2022-2274, was introduced in OpenSSL 3.0.4 and could potentially allow malicious hackers to launch remote code attacks on unpatched SSL/TLS server side devices.

read more