CVE-2021-1078
NVIDIA Windows GPU Display Driver for Windows, all versions, contains a vulnerability in the kernel driver (nvlddmkm.sys) where a NULL pointer dereference may lead to system crash.
Endpoint Protection Platforms (EPP) , Endpoint Security Automatic Translation Bypasses Security Restrictions Prajeet Nair (@prajeetspeaks) • June 29, 2021 Microsoft recently released updates for the Edge browser, including a fix for a bypass vulnerability that could allow a remote attacker to bypass implemented security restrictions. See Also: Live Panel | Zero Trusts Given-…
According to cybersecurity specialists, unknown cybercriminals hacked the servers of Mongolian Certificate Authority (CA) MonPass and abused the company’s website in order to distribute malware. The organization analysis that started in April 2021 shows that a public web server hosted by MonPass was breached potentially eight separate times. Avast researchers discovered eight different webshells and…
Cybercrime , Cybercrime as-a-service , DDoS Protection Matthew Gatrel Offered Subscription-Based Computer Attack Platforms Prajeet Nair (@prajeetspeaks) • September 19, 2021 An Illinois man has been found guilty of running subscription-based distributed denial of service attacks that flood targeted computers with information and prevent them from being able to access the internet, reports…
Security researchers warn of three new zero-day vulnerabilities in the Kaseya Unitrends service and advise users not to expose the service to the Internet. Kaseya Unitrends is a cloud-based enterprise backup and disaster recovery solution that is offered as a stand-alone solution or as an add-on for the Kaseya VSA remote management platform. Last week,…
Cyberwarfare / Nation-State Attacks , Fraud Management & Cybercrime , Fraud Risk Management Microsoft: Russians Used Malicious Messages Portrayed as Coming From USAID Scott Ferguson (Ferguson_Writes) • May 28, 2021 Here’s an example of a phishing email masquerading as a message from USAID. (Source: Microsoft) A Russian group that was behind the massive…
Email Security & Protection , Endpoint Security , Fraud Management & Cybercrime Attack Code ‘Rudimentary and Amateurish’ but Still a Threat Mathew J. Schwartz (euroinfosec) • March 24, 2021 Ransom note left by Black Kingdom (Source: MalwareTech) Attackers gunning for an easy payday are continuing to target Microsoft Exchange servers that have not…