Microsoft says new SolarWinds zero-day was exploited by China-based threat actor
The DEV-0322 group was previously observed targeting entities in the U.S. Defense Industrial Base Sector and software companies.
The DEV-0322 group was previously observed targeting entities in the U.S. Defense Industrial Base Sector and software companies.
Some speculations suggest that REvil may have been targeted by authorities.
The security updates also fix a number of publicly disclosed but not exploited issues.
Customers' personal and financial information may have been compromised in the attack.
The company said the attacks exploiting CVE-2021-35211 affected only a small subset of its customers.
The malware abuses Open Broadcaster Software (OBS) Studio live streaming software to capture victims’ screens.
On Sunday, the company released VSA version 9.5.7a (9.5.7.2994) that fixes three security vulnerabilities - CVE-2021-30116, CVE-2021-30119, and CVE-2021-30120.
The attack disrupted the district’s IT operations leaving it unable to pay out welfare benefits.
It’s not clear who is behind the security incident as no group took responsibility for it.
The tech giant has released the clarified guidance after multiple security researchers reported that the security updates don’t fully address the vulnerability.
Showing elements 2951 - 2960