admins
-
Blog
WP3.XYZ malware attacks add rogue admins to 5,000+ WordPress sites
A new malware campaign has compromised more than 5,000 WordPress sites to create admin accounts, install a malicious plugin, and steal data. Researchers at webscript security company c/side discovered during an incident response engagement for one of their clients that the malicious activity uses the wp3[.]xyz domain to exfiltrate data but have yet to determine the initial infection vector. After compromising a…
Read More » -
Blog
Admins beware, these Microsoft 365 features are being cut in 2025
Microsoft 365 is in for a year of end-of-life (EOL) dates and feature terminations, posing potential challenges for IT admins and workers alike. Analysis from Microsoft service management firm, AdminDroid, shows over a dozen (14) changes are set to take effect in 2025, with the planned cuts representing a way for Microsoft to ensure users are accessing tools that are…
Read More » -
Blog
SonicWall urges admins to patch exploitable SSLVPN bug immediately
SonicWall is emailing customers urging them to upgrade their firewall’s SonicOS firmware to patch an authentication bypass vulnerability in SSL VPN and SSH management that is “susceptible to actual exploitation.” In an email sent to SonicWall customers and shared on Reddit, the firewall vendor says the patches are available as of yesterday, and all impacted customers should install them immediately to prevent exploitation.…
Read More » -
Blog
For Apple IT admins, the new year means it’s a good time to upskill – Computerworld
WWDC Let’s start with the one everyone knows about, which is Apple’s Worldwide Developers Conference (WWDC) held every June. The event has become an Apple keynote event in its own right, and while most of the content is intended for Apple developers, it always includes at least a few sessions for IT pros; the exact number varies each year, but the…
Read More » -
Blog
Police shuts down Rydox cybercrime market, arrests 3 admins
Albanian law enforcement has seized the Rydox cybercrime marketplace and arrested three administrators in collaboration with international partners. Kosovo nationals Ardit Kutleshi, Jetmir Kutleshi, and Shpend Sokoli were arrested on Thursday by Kosovo law enforcement and Albania’s Special Anti-Corruption Body (SPAK). The U.S. Justice Department indicted the first two for involvement in Rydox’s operations, and they’re awaiting extradition to the…
Read More » -
Blog
New Windows 11 recovery tool to let admins remotely fix unbootable devices
Microsoft is working on a new Windows “Quick Machine Recovery” feature that will allow IT administrators to use Windows Update “targeted fixes” to remotely fix systems rendered unbootable. This new feature is part of a new Windows Resiliency Initiative launched in response to a widespread July 2024 outage caused by a buggy CrowdStrike Falcon update that rendered hundreds of thousands…
Read More » -
Blog
Windows Server 2025 is now available – but Microsoft warns admins to watch out for three major bugs, including one that causes the dreaded blue screen of death
Microsoft has released the latest version of its server operating system, Windows Server 2025 — but it comes alongside a trio of bugs. Windows Server 2025 is Microsoft’s latest version of its server OS, following on from Windows Server 2022. The new version is arriving alongside System Center 2025, which Microsoft said means it’s possible to “make the most” of…
Read More » -
Blog
How IT admins should think about a more open Apple – Computerworld
What benefits exist? The idea that users might gain more browser actions and more opportunity for choice and customization is one thing, but it is a big thing. While consumer users might opt for whatever option they want, those users in the enterprise could inadvertently create problems. As a result, Apple admins “must account for potential compatibility issues, security vulnerabilities,…
Read More » -
Blog
Why you should always be wary of insider threats: A disgruntled employee at a US industrial firm deleted backups and locked IT admins out of workstations in a failed data extortion attempt
A disgruntled IT worker at a national industrial company in the US has been arrested after he launched an extortion campaign targeting his former employer in 2023. Daniel Rhyne was a core infrastructure engineer at an unnamed US-based industrial firm, and attempted to extort his company for $750,000 worth of Bitcoin. According to a press release issued by the US…
Read More » -
Blog
Admins of MFA bypass service plead guilty to fraud
Three men have pleaded guilty to running OTP.Agency, an online platform that provided social engineering help to obtain one-time passcodes from customers of various banks and services in the U.K. The codes – temporary passwords also known as OTPs, were part of multi-factor authentication protections and criminals subscribing to the illegal service could use them to access a victim’s bank account and…
Read More »