Para iOS se descubrió un nuevo exploit, con la ayuda de la cual China rastreó a los uigures

Specialists of the information security company Volexity discovered a new exploit for iOS called Insomnia. Según los investigadores, the malware associated with the efforts of the Chinese authorities to trace the Muslim national minority, the Uyghurs, who live mainly in Xinjiang province. Researchers say that Insomnia works against iOS versions 12.3, 12.3.1 and 12.3.2.Seguir leyendo Para iOS se descubrió un nuevo exploit, con la ayuda de la cual China rastreó a los uigures

Conspiracy theorists accused Bill Gates in creating coronavirus

Microsoft founder Bill Gates fell victim of fake theories that he was allegedly involved in the creation of the coronavirus COVID-19. De hecho, conspiracy theorists accused Bill Gates in creation of a coronavirus and intention to achieve material benefits from the pandemic. At TED conference in 2015, Bill Gates argued that the greatest threat toSeguir leyendo Conspiracy theorists accused Bill Gates in creating coronavirus

GitHub warned users about phishing attack

Representatives of the GitHub web service warned users of a massive phishing attack called Sawfish. Recientemente, users more and more often receive phishing emails with fake warnings about suspicious activity of a recorded account or strange changes made to the repository or settings. “The links attached to such messages lead to a fake GitHub loginSeguir leyendo GitHub warned users about phishing attack

Más que 700 malicious libraries detected in RubyGems repository

Information security researchers at ReversingLabs reported the discovery of 725 malicious libraries that stole the contents of the clipboard in the official RubyGems repository. RubyGems is a package manager for the Ruby programming language. According to their own site statistics, the repository contains around 158 thousand packages (called gems) con casi 49 billion total downloads.Seguir leyendo Más que 700 malicious libraries detected in RubyGems repository

Hoaxcalls botnet attacks Grandstream devices

Palo Alto Networks experts warn that the Hoaxcalls botnet attacks the recently fixed vulnerability in the Grandstream UCM6200 series devices. The Hoaxcalls botnet is built on the source code of the Gafgyt/Bashlite malware and is mainly used for DDoS attacks. «The malware is built on the Gafgyt/Bashlite malware family codebase, which we have dubbed “Hoaxcalls”,… Seguir leyendo Hoaxcalls botnet attacks Grandstream devices

Due to the pandemic Google developers re-enabled FTP support for Chrome

Más reciente, I wrote that Firefox developers plan to remove from their browser support for the FTP protocol, as consider it to be unsafe. Al mismo tiempo, Google re-enabled FTP support for Chrome. Google developers have been talking about abandoning FTP since 2014, since very few browser users (0.1-0.2%) usa el protocolo. In 2018,Seguir leyendo Due to the pandemic Google developers re-enabled FTP support for Chrome

La pandemia de COVID-19 despertó el interés en los sitios pirateados

Actualmente, hundreds of millions of people remain at home and occur global changes in the Internet traffic trends. En particular, because of the COVID-19 pandemic, raised interest in pirated sites. The fact is that considerable part of the population now works from home, while other people also stay at home, but spend time online searchingSeguir leyendo La pandemia de COVID-19 despertó el interés en los sitios pirateados

Microsoft bought the domain Corp.com, so criminals would not do it

The well-known IS journalist Brian Krebs drew attention to an interesting fact: this week Microsoft bought the domain Corp.com, so that criminals would not do it. The sum of transaction is not disclosed. Krebs first turned his attention to this domain when a man named Mike O’Connor, who owned it for 26 años, put itSeguir leyendo Microsoft bought the domain Corp.com, so criminals would not do it

El personal de la NASA enfrenta un aumento exponencial en el número de ataques de piratas informáticos

Representatives of the space agency said that recently NASA staff and home-based agency contractors suffered from increase in the number of hacker attacks, and their devices are constantly trying to gain access to malicious sites. Por lo tanto, según cifras oficiales, En los días recientes, NASA personnel have been suffering from: doubling the number of phishing attacksSeguir leyendo El personal de la NASA enfrenta un aumento exponencial en el número de ataques de piratas informáticos

82.5% of Microsoft Exchange servers are still vulnerable

Information security experts from Rapid7 reported that more than 35,000 Internet-connected Microsoft Exchange servers are still vulnerable to the critical vulnerability CVE-2020-0688 that was fixed in February. The vulnerability affects the default Exchange Control Panel (ECP) component and allows an attacker to take control of a Microsoft Exchange server using previously stolen valid email credentials.Seguir leyendo 82.5% of Microsoft Exchange servers are still vulnerable