Malware deployed by North Korean hackers via VPN update exploit
Such exploitation was evident in a January attack by Kimsuky against a South Korean construction trade entity's website that lured employees into installing trojanized security software with a valid digital certificate.
A security vulnerability in Rockwell Automation's ControlLogix 1756 programmable logic controllers, tracked as CVE-2024-6242, could allow tampering with physical processes at plants.
Windows systems increasingly targeted by SnakeKeylogger trojan
Zero-day detection hits for SnakeKeylogger reached hundreds, with the trojan attempting communications with numerous outside servers, according to an alert from Fortinet's FortiGuard Labs.
The company, which was founded in 2021 by cybersecurity veterans Javed Hasan and Anand Revashetti, aims to detect and mitigate attacks targeting organizations' software supply chains as well as vulnerabilities, such as tampered or outdated open...
Congratulations to the MSRC 2024 Most Valuable Security Researchers!
The Microsoft Researcher Recognition Program offers public thanks and recognition to security researchers who help protect our customers through discovering and sharing security vulnerabilities under Coordinated Vulnerability Disclosure. Today, we...