Hackers Hijacked Notepad++ Plugin To Execute Malicious Code

ByGuru Baran: The AhnLab Security Intelligence Center (ASEC) has detected a sophisticated cyberattack targeting users of the popular text and code editor, Notepad++. Hackers have successfully manipulated a default plugin within the Notepad++ package, potentially compromising the security of countless systems. The plugin in question, “mimeTools.dll,” is a standard component of Notepad++ that provides encoding functionalities, such as Base64. It is automatically included and loaded when Notepad++ is run, which the […]

read more

500ms to midnight: XZ / liblzma backdoor

SAMIR BOUSSEADEN•MIKA AYENSON•JAKE KING: Elastic Security Labs is releasing an initial analysis of the XZ Utility backdoor, including YARA rules, osquery, and KQL searches to identify potential compromises. Key Takeaways On March 29, 2024, Andres Freund identified malicious commits to the command-line utility XZ, impacting versions 5.6.0 and 5.6.1 for Linux, and shared the information on the oss-security mailing list. Andres’ discovery was made after an increase of 500ms in latency was […]

read more

Google Confirms 97 Zero-Day Attacks And Points Finger At China For 12

Davey Winder Senior Contributor Veteran cybersecurity and tech analyst, journalist, hacker, author: There were 97 zero-day vulnerabilities seen in the wild in the past year, Google’s Threat Analysis Group and Mandiant have confirmed. When it comes to government-backed exploitation of zero-day vulnerabilities, there is one clear winner, according to Google: The People’s Republic of China was responsible for exploiting 12 of them in 2023, up from seven in 2022. The […]

read more

2M+ WordPress Sites Hit By Essential Addons For Elementor Vulnerability

SEJ STAFF-Roger Montti: XSS vulnerabilities in Essential Addons for Elementor could allow attackers to inject malicious scripts into WordPress websites Security researchers published an advisory on the popular Essential Addons For Elementor WordPress plugin which was discovered to contain a Stored Cross-Site Scripting vulnerability affecting over 2 million websites. Flaws in two different widgets that are a part of the plugin are responsible for the vulnerabilities. Two Widgets That Lead […]

read more

DHCP Hacked To Escalate Privileges In Windows Domains

ByBalaji: Security researchers have uncovered a sophisticated method of exploiting the Dynamic Host Configuration Protocol (DHCP) administrators group to escalate privileges within Windows domains. This technique, dubbed “DHCP Coerce,” leverages legitimate privileges to compromise entire networks potentially. The vulnerability centers around the DHCP (Dynamic Host Configuration Protocol) service, which is essential for network administration. It automates the assignment of IP addresses, simplifying the management of network connections. However, this convenience […]

read more
Trustpilot
The rating of livingsafeonline.com at Trustprofile Reviews is 9.1/10 based on 13 reviews.
A note to our visitors

This website has updated its privacy policy in compliance with changes to European Union data protection law, for all members globally. We’ve also updated our Privacy Policy to give you more information about your rights and responsibilities with respect to your privacy and personal information. Please read this to review the updates about which cookies we use and what information we collect on our site. By continuing to use this site, you are agreeing to our updated privacy policy.

Verified by MonsterInsights