The Hacker News reports that the suspected China-linked group Warlock is still…

The Hacker News reports that the suspected China-linked group Warlock is still exploiting Microsoft SharePoint vulnerabilities to target organizations in Portuguese- and Spanish-speaking countries. The attacks have hit critical infrastructure, government, and education organizations, so Windows users and small offices running SharePoint should patch and mitigate exposed servers and check for signs of web shells, disabled security tools, or unusual remote connections.

The Hacker NewsWarlock Exploits SharePoint Flaws to Disable Security Tools and Deploy Ransomware

Source: thehackernews.com

More in this rubric
all →

Malwarebytes Labs reports that attackers compromised infrastructure behind the .gh, .sl, and .as country-code domain namespaces and used it to obtain unauthorized HTTPS certificates for Google domains and other organizations. Google blocked the certificates in Chrome and worked with certificate authorities to revoke them. Windows users should keep their browser and operating system updated and never bypass certificate warnings.

Malwarebytes LabsAttackers hijack country-code domains to impersonate Google and other services

Source: malwarebytes.com

The Hacker News reports that 16 malicious Firefox extensions were found posing as Rabby and OKX Wallet tools to steal cryptocurrency wallet recovery phrases and private keys. The add-ons intercepted those secrets during wallet import flows and sent them to attacker-controlled Cloudflare Workers. Users who installed any of the extensions and entered a real recovery phrase or private key should assume compromise and move their assets from a clean system.

The Hacker News16 Malicious Firefox Extensions Pose as Rabby and OKX Wallets to Steal Recovery Phrases

Source: thehackernews.com

The FBI and Secret Service warn that the FortiBleed credential-harvesting campaign is still active and is targeting internet-facing Fortinet FortiGate firewalls and SSL VPN gateways. The agencies say attackers are scanning exposed devices, using stolen credentials, and may be passing access on to ransomware groups. Windows users in small offices should make sure their VPN and admin passwords are changed, active sessions are ended, and device logs are checked for suspicious activity.

The Hacker NewsFBI Warns FortiBleed Remains Active After Amassing 86,644 Fortinet Device Credentials

Source: thehackernews.com

5,441 members already hereReading, writing, commenting and voting. 0 verified · 166 joined this year