article thumbnail

Almost 800,000 SonicWall VPN appliances online are vulnerable to CVE-2020-5135

Security Affairs

The Tripwire VERT security team spotted almost 800,000 SonicWall VPN appliances exposed online that are vulnerable to the CVE-2020-5135 RCE flaw. Security experts from the Tripwire VERT security team have discovered 795,357 SonicWall VPN appliances that were exposed online that are vulnerable to the CVE-2020-5135 RCE flaw.

article thumbnail

Experts warn of the exposure of thousands of Google Calendars online

Security Affairs

It is essential to point out that this isn’t a security vulnerability in Google Calendar, but an issue that could potentially impact anyone that has ever shared his Google Calendars. The security researcher Avinash Jain discovered more than 8000 Google Calendars exposed online that were indexed by Google search engine.

Insiders

Sign Up for our Newsletter

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

article thumbnail

Gootkit delivery platform Gootloader used to deliver additional payloads

Security Affairs

In its latest attempts to evade detection by endpoint security tools, Gootloader has moved as much of its infection infrastructure to a “fileless” methodology as possible.” The post Gootkit delivery platform Gootloader used to deliver additional payloads appeared first on Security Affairs. ” continues the analysis.

article thumbnail

Experts warn of a new malvertising campaign spreading the ChromeLoader

Security Affairs

. “However, ChromeLoader uses PowerShell to inject itself into the browser and add a malicious extension to it, a technique we don’t see very often (and one that often goes undetected by other security tools). Security Affairs is one of the finalists for the best European Cybersecurity Blogger Awards 2022 – VOTE FOR YOUR WINNERS.

article thumbnail

Facebook flaw could have exposed private info of users and their friends

Security Affairs

Security experts from Imperva reported a new Facebook flaw that could have exposed private info of users and their friends. A new security vulnerability has been reported in Facebook, the flaw could have been exploited by attackers to obtain certain personal information about users and their network of contacts. Pierluigi Paganini.

article thumbnail

Threat actors are attempting to exploit VMware vCenter CVE-2021-22005 flaw

Security Affairs

VMware has released patches that address a new critical security advisory, VMSA-2021-0020. Researchers from BleepingComputer also reported that threat actors have started to exploit CVE-2021-22005 using code released by security researcher Jang. deployments. The vulnerability is due to the way it handles session tokens.

article thumbnail

Unsecured Microsoft Bing Server Leaks Search Queries, Location Data

Threatpost

Data exposed included search terms, location coordinates, and device information - but no personal data.