Password manager utility KeePass has had to defend its reputation following the discovery of a potential vulnerability that could expose users’ secret data. However, the company states the issue only arises if an attacker already controls a compromised account. Additionally, OpenSSL project has released patches to address a variety of vulnerabilities, including a high-impact flaw. In related news, a system administrator on Reddit was victim of a phishing attack, gaining the attackers access to some internal documents and code.
Qualys uncovers large-scale Murdoc Botnet campaign
The Murdoc Botnet, a new element of the Mirai campaign, is targeting IoT devices worldwide. Uncovered by Qualys, the botnet targets vulnerabilities in AVTECH cameras