Cybersecurity News

Critical Root RCE Bug Affects Multiple Netgear SOHO Router Models
Networking equipment company Netgear has released yet another round of patches to remediate a high-severity remote code execution vulnerability affecting multiple routers that could be exploited by remote attackers to take control of an affected system. Tracked as CVE-2021-34991 (CVSS score: 8.8), the pre-authentication buffer overflow flaw in small office and home office (SOHO) routers can lead to

FBI Issues Flash Alert on Actively Exploited FatPipe VPN Zero-Day Bug
The U.S. Federal Bureau of Investigation (FBI) has disclosed that an unidentified threat actor has been exploiting a previously unknown weakness in the FatPipe MPVPN networking devices at least since May 2021 to obtain an initial foothold and maintain persistent access into vulnerable networks, making it the latest company to

11 Malicious PyPI Python Libraries Caught Stealing Discord Tokens and Installing Shells
Cybersecurity researchers have uncovered as many as 11 malicious Python packages that have been cumulatively downloaded more than 41,000 times from the Python Package Index (PyPI) repository, and could be exploited to steal Discord access tokens, passwords, and even stage dependency confusion attacks. The Python packages have since been removed

The FBI’s email system was hacked to send out fake cybersecurity warnings
Hackers targeted the Federal Bureau of Investigation’s (FBI) email servers, sending out thousands of phony messages that say its recipients have become the victims of a “sophisticated chain attack,” first reported by Bleeping Computer. The emails were initially uncovered by The Spamhaus Project, a nonprofit organization that investigates email spammers.

New bill sets ransomware attack response rules for US financial orgs
New legislation introduced this week by US lawmakers aims to set ransomware attack response “rules of road” for US financial institutions. The Ransomware and Financial Stability Act (H.R.5936) was introduced this week by the top Republican on the House Financial Services Committee, Congressman Patrick McHenry. If signed into law, the

Russian ‘King of Fraud’ sentenced to 10 years for Methbot botnet
The U.S. Department of Justice (DOJ) sentenced a Russian man for operating a large-scale digital advertising fraud scheme called ‘Methbot’ (‘3ve’) that stole at least $7 million from American companies. Aleksandr Zhukov, aka the “King of Fraud,” was sentenced to 10 years of imprisonment in the U.S. and ordered to