Forwarded from Hacker News
๐ฃ Oracle quietly confirms public cloud data breach, customer data stolen.
https://www.techradar.com/pro/security/oracle-quietly-confirms-public-cloud-data-breach-customer-data-stolen
The attacker exploited a vulnerability in Oracle Access Manager to breach Oracle-hosted servers. The vulnerability is tracked as CVE-2021-35587 and was assigned a critical severity score 9.8/10. It was patched in mid-January 2022, raising questions over whether Oracle kept its own servers vulnerable to a flaw it fixed more than three years ago.
CrowdStrike is investigating the incident along FBI.
https://www.techradar.com/pro/security/oracle-quietly-confirms-public-cloud-data-breach-customer-data-stolen
TechRadar
Oracle quietly confirms public cloud data breach, customer data stolen
Oracle has sent out breach notifications
โ โ โ โ โ ๐ Google fixes two Android zero-day bugs actively exploited likely by state sponsored hackers.
https://techcrunch.com/2025/04/08/google-fixes-two-android-zero-day-bugs-actively-exploited-by-hackers/
https://source.android.com/docs/security/bulletin/2025-04-01
CVE-2024-53197
CVE-2024-53150
https://techcrunch.com/2025/04/08/google-fixes-two-android-zero-day-bugs-actively-exploited-by-hackers/
https://source.android.com/docs/security/bulletin/2025-04-01
TechCrunch
Google fixes two Android zero-day bugs actively exploited by hackers | TechCrunch
The most severe security bug can be exploited without user interaction, per Google.
โ โ โ โ โ WhatsApp flaw can let attackers run malicious code on Windows PCs.
https://www.whatsapp.com/security/advisories/2025/
https://www.bleepingcomputer.com/news/security/whatsapp-flaw-can-let-attackers-run-malicious-code-on-windows-pcs/
https://www.whatsapp.com/security/advisories/2025/
https://www.bleepingcomputer.com/news/security/whatsapp-flaw-can-let-attackers-run-malicious-code-on-windows-pcs/
WhatsApp.com
WhatsApp Security Advisories 2025
WhatsApp Security Advisories 2025 - List of security fixes for WhatsApp products
โ โ โ โ โ CVE-2025-29810: Microsoft has disclosed a significant security vulnerability in Active Directory Domain Services that could allow attackers to elevate their privileges to the system level, potentially gaining complete control over affected systems.
https://cybersecuritynews.com/windows-active-directory-domain-vulnerability-let-attackers-escalate-privileges/
https://cybersecuritynews.com/windows-active-directory-domain-vulnerability-let-attackers-escalate-privileges/
Cyber Security News
Windows Active Directory Domain Vulnerability Let Attackers Escalate Privileges
Microsoft has disclosed a significant security vulnerability in Active Directory Domain Services that could allow attackers to elevate their privileges to the system level, potentially gaining complete control over affected systems. The vulnerability trackedโฆ
Forwarded from The Hacker News
๐จ Europol's Operation Endgame just busted 5+ SmokeLoader customers linked to ransomware, spyware, and crypto theft.
Meanwhile, new malware loaders like ModiLoader, GootLoader, and FakeUpdates are hitting users with phishing, fake installs, and drive-by attacks.
๐ Full story: https://thehackernews.com/2025/04/europol-arrests-five-smokeloader.html
Meanwhile, new malware loaders like ModiLoader, GootLoader, and FakeUpdates are hitting users with phishing, fake installs, and drive-by attacks.
๐ Full story: https://thehackernews.com/2025/04/europol-arrests-five-smokeloader.html
Forwarded from The Hacker News
๐ฅ Gamaredon (aka Shuckworm) hit a Western military mission in Ukraine with a new, stealthier GammaSteel malware, Symantec warns.
๐ Infected USBs โ Hidden shortcut traps โ Live exfil via Telegram & Telegraph.
๐ Full story: https://thehackernews.com/2025/04/gamaredon-uses-infected-removable.html
๐ Infected USBs โ Hidden shortcut traps โ Live exfil via Telegram & Telegraph.
๐ Full story: https://thehackernews.com/2025/04/gamaredon-uses-infected-removable.html
Forwarded from The Hacker News
๐ฒ 53% of #DevSecOps teams are gambling with open source security.
New 2025 report from ActiveState reveals:
โ Risky workflows
โ Sluggish MTTD/MTTR
โ Traditional tools are failing fast
Ready to fix fasterโwithout falling behind?
๐Read now โ https://thn.news/vuln-management-2025
New 2025 report from ActiveState reveals:
โ Risky workflows
โ Sluggish MTTD/MTTR
โ Traditional tools are failing fast
Ready to fix fasterโwithout falling behind?
๐Read now โ https://thn.news/vuln-management-2025
Forwarded from The Hacker News
๐จ New npm malware alert: pdf-to-office targets Atomic and Exodus wallets.
โก๏ธ Injects malicious code to hijack crypto transfers.
โก๏ธ Malware persists even after uninstalling.
โก๏ธ 334+ downloads so far.
Supply chain attacks are rising.
Full report: https://thehackernews.com/2025/04/malicious-npm-package-targets-atomic.html
โก๏ธ Injects malicious code to hijack crypto transfers.
โก๏ธ Malware persists even after uninstalling.
โก๏ธ 334+ downloads so far.
Supply chain attacks are rising.
Full report: https://thehackernews.com/2025/04/malicious-npm-package-targets-atomic.html
Forwarded from The Hacker News
AI agents arenโt just "tools" anymore โ they're your new workforce.
But behind every agent is a non-human identity (NHI) โ and that's where real risks live.
๐ Machine-speed attacks
๐ Invisible backdoors (Shadow AI)
๐ Cross-system breaches
Learn how to secure AI at the source โ https://thehackernews.com/2025/04/the-identities-behind-ai-agents-deep.html
But behind every agent is a non-human identity (NHI) โ and that's where real risks live.
๐ Machine-speed attacks
๐ Invisible backdoors (Shadow AI)
๐ Cross-system breaches
Learn how to secure AI at the source โ https://thehackernews.com/2025/04/the-identities-behind-ai-agents-deep.html
Forwarded from The Hacker News
CTM360 just uncovered 16,000+ malicious Android URLs tied to the evolving PlayPraetor campaign.
๐ก๏ธ 5 new variants (Phish, RAT, PWA, Phantom, Veil) now target banking, tech, and energy users globally.
The threat is expanding fast.
Read the full report: https://thehackernews.com/2025/04/playpraetor-reloaded-ctm360-uncovers.html
๐ก๏ธ 5 new variants (Phish, RAT, PWA, Phantom, Veil) now target banking, tech, and energy users globally.
The threat is expanding fast.
Read the full report: https://thehackernews.com/2025/04/playpraetor-reloaded-ctm360-uncovers.html
Forwarded from Gizchina.com
Next-Gen Chinese Phones To Feature 7,000 mAh Batteries or More
https://www.gizchina.com/2025/04/10/next-gen-chinese-phones-to-feature-7000-mah-batteries-or-more/
https://www.gizchina.com/2025/04/10/next-gen-chinese-phones-to-feature-7000-mah-batteries-or-more/