Technology

Microsoft is urging customers to patch two security vulnerabilities in Active Directory domain controllers that it addressed in November following the availability of a proof-of-concept (PoC) tool on December 12. The two vulnerabilities — tracked as CVE-2021-42278 and CVE-2021-42287 — have a severity rating of 7.5 out of a maximum of 10 and concern a
0 Comments
Microsoft said it won’t be fixing or is pushing patches to a later date for three of the four security flaws uncovered in its Teams business communication platform earlier this March. The disclosure comes from Berlin-based cybersecurity firm Positive Security, which found that the implementation of the link preview feature was susceptible to a number
0 Comments
Realme 9i has been spotted on Chinese e-commerce website AliExpress as a placeholder listing, hinting at the specifications of the company’s upcoming smartphone. The company’s upcoming smartphone is expected to launch as part of the Realme 9 series in China in January, and was recently spotted on various certification websites. According to the smartphone’s listing,
0 Comments
Cybersecurity researchers have disclosed details of an evasive malware campaign that makes use of valid code signing certificates to sneak past security defenses and stay under the radar with the goal of deploying Cobalt Strike and BitRAT payloads on compromised systems. The binary, a loader, has been dubbed “Blister” by researchers from Elastic Security, with
0 Comments
Ransomware groups continue to evolve their tactics and techniques to deploy file-encrypting malware on compromised systems, notwithstanding law enforcement’s disruptive actions against the cybercrime gangs to prevent them from victimizing additional companies. “Be it due to law enforcement, infighting amongst groups or people abandoning variants altogether, the RaaS [ransomware-as-a-service] groups dominating the ecosystem at this
0 Comments
Apple recently fixed a security vulnerability in the macOS operating system that could be potentially exploited by a threat actor to “trivially and reliably” bypass a “myriad of foundational macOS security mechanisms” and run arbitrary code. Security researcher Patrick Wardle detailed the discovery in a series of tweets on Thursday. Tracked as CVE-2021-30853 (CVSS score:
0 Comments
Huawei P50 Pocket foldable phone has been launched in China. This is the first clamshell foldable phone from the Chinese tech giant. Huawei already has the Mate X series of foldable smartphones under its belt. The new Huawei P50 Pocket is equipped with a multi-dimensional hinge designed to unfold without any signs of creasing. This
0 Comments
Cybersecurity agencies from Australia, Canada, New Zealand, the U.S., and the U.K. on Wednesday released a joint advisory in response to widespread exploitation of multiple vulnerabilities in Apache’s Log4j software library by nefarious adversaries. “These vulnerabilities, especially Log4Shell, are severe,” the intelligence agencies said in the new guidance. “Sophisticated cyber threat actors are actively scanning
0 Comments
Samsung Galaxy S22 series have been part of leaks and rumours for quite a while now. The upcoming flagship smartphone lineup from the South Korean tech giant is expected to include the vanilla Samsung Galaxy S22 model, alongside Galaxy S22+ and Galaxy S22 Ultra. In a new update, an official marketing poster of Galaxy S22
0 Comments
A short-lived phishing campaign has been observed taking advantage of a novel exploit that bypassed a patch put in place by Microsoft to fix a remote code execution vulnerability affecting the MSHTML component with the goal of delivering Formbook malware. “The attachments represent an escalation of the attacker’s abuse of the CVE-2021-40444 bug and demonstrate
0 Comments
Samsung Galaxy S21 series recently received the company’s One UI 4 update based on Android 11, weeks after Google released the update for its Pixel smartphones. Despite being the first manufacturer after Google to release Android 12 for compatible devices, Samsung has reportedly paused the update rollout for its flagship Galaxy S21 series in South
0 Comments
China’s internet regulator, the Ministry of Industry and Information Technology (MIIT), has suspended a partnership with Alibaba Cloud, the cloud computing subsidiary of e-commerce giant Alibaba Group, for six months for failing to promptly report a critical security vulnerability affecting the broadly used Log4j logging library. The development was reported by Reuters and South China
0 Comments