Critical Dahua Camera Flaws Enable Remote Hijack via ONVIF and File Upload Exploits: https://t.co/qUgnYrvpZq by The Hacker News #infosec #cybersecurity #technology #news
Infamous hacking collective Scattered Spider is evolving to grow even more dangerous. https://t.co/occKWp7sWd
Apple Patches Safari Vulnerability Also Exploited as Zero-Day in Google Chrome: https://t.co/yX8AaxTPqu by The Hacker News #infosec #cybersecurity #technology #news
The ransomware group Scattered Spider has advanced its tactics by hijacking VMware ESXi hypervisors through social engineering techniques, specifically by impersonating IT help desk administrators. This method allows them to reset passwords and deploy ransomware directly from the hypervisor, targeting critical U.S. infrastructure. Google has characterized the attacks as fast, stealthy, and highly disruptive. Additionally, other cybersecurity threats have emerged, including the exploitation of a critical SAP vulnerability used to breach Linux systems and deploy Auto-Color malware against U.S. companies. Apple has addressed a zero-day vulnerability linked to a Chrome exploit that allowed attackers to escape the browser sandbox, affecting devices such as iPhones, Macs, and iPads. Users are urged to update their systems promptly. Furthermore, critical security flaws in Dahua cameras have been identified, enabling remote hijacking through ONVIF and file upload exploits. These developments highlight an evolving and increasingly dangerous cybersecurity landscape.