Unsecured MongoDB database servers allowed a "white-hat" hacker to access the account information for over 13 million MacKeeper users. MacKeeper is a program that supposedly optimizes your Mac so that it runs faster and safer..
A new version of TeslaCrypt was released on Tuesday that contains some minor changes such as new ransom note names, a new name for the autorun entry, and a slight change to how it removes the Shadow Volume Copies.
In protest of the arrests of over 200 protesters at the Global Climate March in Paris, Anonymous has leaked account information for over 1,400 UN officials. This information includes login credentials, phone numbers, email address, and names.
Microsoft released an advisory yesterday about an accidental leak of their xboxlive.com SSL certificate's private key. This would potentially allow an attacker to perform a man-in-the-middle attack to sniff the encrypted communication.
Not to be outdone by Adobe or Microsoft, Apple also released security updates today for all it's core products including Xcode, Safari, watchOS, tvOS, OS X El Capitan, and iOS. These updates resolve 80 different vulnerability ranging from remote code execution to the ability to access a user's keychain items. Any users of Apple produ
Adobe has released an update for Adobe Flash that resolves a whopping 78 vulnerabilities. This is a required update for anyone who has Flash installed as these vulnerabilities are known to be used in the wild to install malware and other attacks.
Today Microsoft released their October Patch Tuesday updates that consists of 12 security updates, with eight of them being marked as critical due to vulnerabilities allowing remote code execution. All Windows users should install these security updates immediately.
Heimdall Security has discovered that a large campaign utilizing the Angler Exploit kit is underway that is distributing CryptoWall 4.0 along with other malware. This campaign utilizes hacked websites that have been compromised to display the Angler exploit kit to unwitting visitors.
A security breach in VTech has allowed a hacker to get the personal information of about 5 million parents and over 200,000 children. To make matters worse, it was discovered this weekend that picture's of children who use the VTech service and their text messages with their parents were obtained as well.
A new version of the TeslaCrypt ransomware has been released that changes the ransom note filenames and uses the new .vvv extension for encrypted files. Unfortunately, at this time there is still no way of decrypting files encrypted by this version of TeslaCrypt.
CryptoWall 4.0 has been discovered being installed via the Nuclear Exploit kit. As an added twist, the malware payload is also being delivered as a NSIS installer that when executed installs the CryptoWall 4.0 ransomware.
A new file-encrypting ransomware has been floating around this past week called CryptInfinite or DecryptorMax. At first this ransomware looked secure, but with further analysis by Fabian Wosar, it was discovered that a decrypter could be made that would recover your files for free.
The Chimera Ransomware uses a new technique for distributing decryption keys through a peer-to-peer messaging application called Bitmessage. This method provides a very easy method of pushing decryption keys out to the victim while staying anonymous behind the peer-to-peer network.
A new variant of TeslaCrypt has been released that utilizes the same .CCC extension for encrypted files, but now uses the _how_recover_
Google has updated their Safe Browsing feature to warn visitors of sites that are considered deceptive. Google categorizes deceptive sites as ones that pretend to act, or try to look and feel, like a trusted company or ones that try to trick you into doing something like calling for tech support or installing software.
A new Ransomware as a Service has been discovered called the Cryptolocker Service. This service states it will go live in the next few days and allow affiliates to distribute their ransomware for a 10% commission.
Kaspersky has released 14,000 additional decryption keys for users infected with the CoinVault or BitCryptor ransomware infections. Using their decryption tool you may be able to recover your encrypted files for free.
Adobe releases security updates for Adobe Flash that fix 17 security vulnerabilities. Out of these 17 vulnerabilities, 16 of them could lead to remote code execution. It is important that everyone update Adobe Flash to the recommended versions so they are no longer affected by these security holes.
Today Microsoft released 12 security updates, with four of them being marked as critical. Microsoft updates are labeled critical when the vulnerability could be exploited by a remote user to execute code on the attacked machine.
Vssadmin.exe is a utility bundled with Windows that allows you to administer Shadow Volume Copies. Unfortunately, this tool is also being used by Ransomware developers to make it harder for you to recover your files. This article explains how Shadow Volume Copies work and why it is important for every user to disable vssadmin.exe.