Topic: remote access

  • 7,000 DJI Robot Vacuums Hacked in Remote Camera Access

    7,000 DJI Robot Vacuums Hacked in Remote Camera Access

    A user discovered a major security flaw in DJI's Romo robot vacuum, allowing unauthorized global access to live camera feeds and location data from thousands of devices. The vulnerability stemmed from a fundamental authentication failure in DJI's servers, granting a single user token administrati...

    Read More »
  • Plex Ends Free Remote Streaming This Week

    Plex Ends Free Remote Streaming This Week

    Plex now requires a Plex Pass subscription for server owners to enable remote streaming from their personal media servers, ending free access for friends and family outside the home network. The subscription mandate, which started rolling out on April 29th, initially affects Roku users and will e...

    Read More »
  • WhatsApp phishing attack uses fake business docs to hack PCs

    WhatsApp phishing attack uses fake business docs to hack PCs

    A widespread phishing campaign is targeting WhatsApp users globally with malicious messages that trick recipients into downloading VBScript files, granting attackers remote access to compromised systems. The attackers use social engineering tactics, masquerading as official business communication...

    Read More »
  • Try NinjaOne Free: Unified IT Operations Platform

    Try NinjaOne Free: Unified IT Operations Platform

    NinjaOne is a unified IT operations platform that consolidates endpoint management, patching, backup, and remote access into a single cloud-native console, offering real-time control across various devices. The platform differentiates itself by being engineered as a single, cohesive system from t...

    Read More »
  • 5-Minute OT Cyber Resilience Guide

    5-Minute OT Cyber Resilience Guide

    Operational technology cybersecurity resilience is vital for protecting critical infrastructure, with identifying all remote access points and supply chain connections forming the foundation of a strong security strategy. Specialized monitoring sensors are essential in OT environments to detect a...

    Read More »
  • Android Malware Grants Attackers Remote Hands-On Control

    Android Malware Grants Attackers Remote Hands-On Control

    Klopatra is a new Android banking trojan that has infected over 3,000 devices in Europe by posing as a legitimate IPTV/VPN app, granting attackers full remote control to monitor screens and steal financial data. The malware, developed by a Turkish-speaking group, uses overlay attacks, VNC for hid...

    Read More »
  • 5 Plead Guilty in North Korean IT Job Fraud and ID Theft Scheme

    5 Plead Guilty in North Korean IT Job Fraud and ID Theft Scheme

    Five individuals pleaded guilty for helping North Korean nationals fraudulently obtain remote IT jobs at U.S. companies, generating over $2.2 million for the DPRK regime and compromising identities. The scheme was part of a state-sponsored effort by hacking groups like APT38 to fund weapons devel...

    Read More »
  • Microsoft Fixes 3 Actively Exploited Zero-Day Vulnerabilities

    Microsoft Fixes 3 Actively Exploited Zero-Day Vulnerabilities

    Microsoft patched three actively exploited zero-day vulnerabilities in its October 2025 Patch Tuesday, including flaws in a pre-installed modem driver, Windows Remote Access Connection Manager, and IGEL OS, requiring immediate updates. The vulnerabilities enable attackers to escalate privileges t...

    Read More »
  • Microsoft Teams Targeted by Fake IT Support Scams

    Microsoft Teams Targeted by Fake IT Support Scams

    A new wave of phishing attacks is exploiting Microsoft Teams, using fake IT support accounts to trick employees into installing malware that gives attackers full network control. Attackers are shifting from email to Teams due to its trusted role in business, impersonating IT staff to deploy remot...

    Read More »
  • What Attackers Do After a Break-In

    What Attackers Do After a Break-In

    A Huntress investigation revealed a post-breach attack where the intruder gained entry via SQL injection, then methodically established persistence by enabling RDP, creating an admin account, and disabling Windows Defender. The attacker weaponized the compromised server by installing BadIIS web m...

    Read More »
  • Urgent: Unpatched ScreenConnect Servers Vulnerable to Attack

    Urgent: Unpatched ScreenConnect Servers Vulnerable to Attack

    A critical vulnerability (CVE-2026-3564) in ScreenConnect allows attackers to hijack active sessions by exploiting weak cryptographic key handling in versions before 26.1. A successful attack could let unauthorized users remotely control the management instance, access employee computers, execute...

    Read More »
  • Critical Flaws Exposed in Major IP KVM Brands

    Critical Flaws Exposed in Major IP KVM Brands

    Inexpensive IP KVM hardware devices, used for remote system administration, pose a severe security risk by allowing access to foundational firmware, which can undermine even well-defended networks if compromised. These devices are often deployed with weak security settings, exposed online, or hav...

    Read More »
  • Microsoft Teams Phishing Attack Spreads A0Backdoor Malware

    Microsoft Teams Phishing Attack Spreads A0Backdoor Malware

    A sophisticated phishing campaign targets financial and healthcare employees by using Microsoft Teams to impersonate IT support, tricking users into granting remote access via Quick Assist to install malware. The attack deploys a novel backdoor called A0Backdoor through signed MSI installers that...

    Read More »
  • DJI Pays $30K to Hacker Who Exposed 7,000 Robovac Flaws

    DJI Pays $30K to Hacker Who Exposed 7,000 Robovac Flaws

    A security researcher discovered a major flaw in DJI's Romo robot vacuum network, exposing around 7,000 devices to potential remote access and viewing into private homes. DJI confirmed a $30,000 reward, has patched one vulnerability, and is implementing a broader system upgrade to address more se...

    Read More »
  • Plex Is Becoming the Very Thing It Replaced

    Plex Is Becoming the Very Thing It Replaced

    Plex's original appeal was its elegant automation for organizing personal media, but its evolution is alienating users who valued its self-hosted, subscription-free model. The platform now imposes frustrating limitations like unreliable remote access, geo-blocks, and a bloated interface filled wi...

    Read More »
  • Five Men Admit Plot to Infiltrate US Firms for North Korea

    Five Men Admit Plot to Infiltrate US Firms for North Korea

    Five individuals pleaded guilty for helping North Korean IT workers infiltrate over 100 U.S. companies by bypassing hiring checks and facilitating remote work under false identities, generating millions in fraudulent salaries. The schemes involved U.S. citizens and others providing their identiti...

    Read More »
  • Figma Opens Design Tools to AI Agents

    Figma Opens Design Tools to AI Agents

    Figma is integrating AI into its platform to enhance collaboration between designers and developers by giving AI models direct access to the core components of apps and prototypes. The expanded Model Context Protocol (MCP) server now allows AI to understand and interact with the actual code in Fi...

    Read More »
  • Trigona ransomware deploys custom tool to steal data

    Trigona ransomware deploys custom tool to steal data

    Trigona ransomware attackers are using a custom command-line data theft tool called "uploader_client.exe" to accelerate file exfiltration while evading detection, replacing commonly used public tools like Rclone and MegaSync. The tool features parallel uploads with up to five simultaneous connect...

    Read More »
  • Asus & Dell Launch New Mini PCs for Windows 365

    Asus & Dell Launch New Mini PCs for Windows 365

    Dell and Asus have launched new mini PCs specifically designed to access Microsoft's Windows 365 cloud service, shifting computational work from local hardware to remote servers. These devices, like the Dell Pro Desktop and Asus NUC 16, prioritize stable connectivity over powerful local processor...

    Read More »
  • Android Trojan Mirax Creates Residential Proxy Network

    Android Trojan Mirax Creates Residential Proxy Network

    A new Android banking trojan named Mirax is targeting users in Europe, having already compromised over 200,000 accounts, primarily through deceptive social media ads aimed at Spanish-speaking individuals. The malware grants attackers extensive remote control, deploying fake overlays on apps to st...

    Read More »