A newly discovered Linux backdoor β dubbed "Kobalos" β targets high-performance computing clusters, allowing hackers to execute arbitrary commands remotely.
Details: https://thehackernews.com/2021/02/a-new-linux-malware-targeting-high.html
Details: https://thehackernews.com/2021/02/a-new-linux-malware-targeting-high.html
The Hacker News
A New Linux Malware Targeting High-Performance Computing Clusters
A New Linux Malware Targeting High-Performance Computing Clusters
Researchers disclose 3 new severe vulnerabilities impacting SolarWinds products, most severe of which could allow RCE attacks with elevated privileges.
Details β https://thehackernews.com/2021/02/3-new-severe-security-vulnerabilities.html
Details β https://thehackernews.com/2021/02/3-new-severe-security-vulnerabilities.html
The Hacker News
3 New Severe Security Vulnerabilities Found In SolarWinds Software
3 New Severe Security Vulnerabilities Found In SolarWinds Orion and Serv-U FTP Server Software
Experts disclose 6 critical flaws affecting popular Realtek Wi-Fi module for widely used in millions of embedded devicesβ2 can be exploited without requiring Wi-Fi password, and the other allows exploitation of Wi-Fi client and full takeover.
https://thehackernews.com/2021/02/critical-bugs-found-in-popular-realtek.html
https://thehackernews.com/2021/02/critical-bugs-found-in-popular-realtek.html
The Hacker News
Critical Bugs Found in Popular Realtek Wi-Fi Module for Embedded Devices
Critical Full Takeover Bugs Found in Popular Realtek Wi-Fi Module for Embedded Devices
π1
Researchers spotted a new 'Matryosh' botnet malware targeting Android-based devices with the primary purpose of carrying out DDoS attacks.
Read details β https://thehackernews.com/2021/02/beware-new-matryosh-ddos-botnet.html
Read details β https://thehackernews.com/2021/02/beware-new-matryosh-ddos-botnet.html
Multiple critical security flaws have been reported in Cisco VPN routers for businesses that could allow unauthenticated, remote attackers to execute arbitrary code as the root user on the affected devices.
Read details and patch ASAP β https://thehackernews.com/2021/02/critical-flaws-reported-in-cisco-vpn.html
Read details and patch ASAP β https://thehackernews.com/2021/02/critical-flaws-reported-in-cisco-vpn.html
WARNING βA new Google Chrome browser 0-day bug is under active Attack
Read details: https://thehackernews.com/2021/02/new-chrome-browser-0-day-under-active.html
Windows, Mac, and Linux users are advised to update the software to the latest available version immediately.
Read details: https://thehackernews.com/2021/02/new-chrome-browser-0-day-under-active.html
Windows, Mac, and Linux users are advised to update the software to the latest available version immediately.
Cybercriminals are now abusing Plex Media Servers to amplify DDoS traffic against various targets to take them offline.
Read details: https://thehackernews.com/2021/02/cybercriminals-now-using-plex-media.html
Read details: https://thehackernews.com/2021/02/cybercriminals-now-using-plex-media.html
π₯ WARNING β Hugely popular 'The Great Suspender' browser extension for Google Chrome contains malware, allowing rogue developers to execute malicious code on millions of computers.
Details: https://thehackernews.com/2021/02/warning-hugely-popular-great-suspender.html
Details: https://thehackernews.com/2021/02/warning-hugely-popular-great-suspender.html
Cybersecurity researchers reveal how the Iranian government spies on dissidents, opposition forces, and ISIS supporters, and Kurdish natives with the help of hackers and #malware.
Read more: https://thehackernews.com/2021/02/researchers-reveal-how-iran-spies-on.html
Read more: https://thehackernews.com/2021/02/researchers-reveal-how-iran-spies-on.html
π± Hacker broke into the computer controlling a water treatment facility in Florida and tried poisoning the supply by remotely changing a setting that drastically altered the levels of sodium hydroxide in the water.
Details: https://thehackernews.com/2021/02/hacker-tried-poisoning-water-supply.html
Details: https://thehackernews.com/2021/02/hacker-tried-poisoning-water-supply.html
The Hacker News
Hacker Tried Poisoning Water Supply After Breaking Into Florida's Treatment System
Hackers infiltrated a water treatment facility in the U.S. state of Florida and drastically altered the levels of sodium hydroxide (NaOH) in the water
π₯1
Ukraine authorities have shut down one of the world's largest phishing services β U-Admin β and arrested its author.
Read: https://thehackernews.com/2021/02/ukrainian-police-arrest-author-of.html
U-Admin kit was used to target financial institutions in 11 countries, causing tens of millions of dollars in losses.
Read: https://thehackernews.com/2021/02/ukrainian-police-arrest-author-of.html
U-Admin kit was used to target financial institutions in 11 countries, causing tens of millions of dollars in losses.
The Hacker News
Ukrainian Police Arrest Author of World's Largest Phishing Service U-Admin
Ukraine Law enforcement shut down U-Admin, one of the world's largest phishing services and arrested its author.
Microsoft Patch Tuesday β February 2021 Edition
β A critical Windows zero-day vulnerability has been spotted being exploited in the wild.
β Patches for a total of 56 new flaws have been issued, 11 of which are listed as critical.
Read: https://thehackernews.com/2021/02/microsoft-issues-patches-for-in-wild-0.html
β A critical Windows zero-day vulnerability has been spotted being exploited in the wild.
β Patches for a total of 56 new flaws have been issued, 11 of which are listed as critical.
Read: https://thehackernews.com/2021/02/microsoft-issues-patches-for-in-wild-0.html
Apple releases a security patch for 10-year-old macOS SUDO root privilege escalation vulnerability, tracked as CVE-2021-3156, and also called "Baron Samedit."
Read details β https://thehackernews.com/2021/02/apple-patches-10-year-old-macos-sudo.html
Read details β https://thehackernews.com/2021/02/apple-patches-10-year-old-macos-sudo.html
Windows LodaRAT malware with credential-stealing and espionage capabilities has now expanded its scope to set its sights on users of Android devices.
Read more: https://thehackernews.com/2021/02/lodarat-windows-malware-now-also.html
Read more: https://thehackernews.com/2021/02/lodarat-windows-malware-now-also.html
π₯ A novel dependency confusion supply-chain attack allowed a security researcher to breach over 35 high-profile companiesβincluding Microsoft, Apple, PayPal, Shopify, Netflix, Tesla, Uberβand achieve remote code execution.
Details: https://thehackernews.com/2021/02/dependency-confusion-supply-chain.html
Details: https://thehackernews.com/2021/02/dependency-confusion-supply-chain.html
In its latest cyber espionage attacks, Iranian hackers utilize a legit remote access tool, called ScreenConnect, to spy on UAE and Kuwait government agencies.
Read details: https://thehackernews.com/2021/02/iranian-hackers-utilize-screenconnect.html
Read details: https://thehackernews.com/2021/02/iranian-hackers-utilize-screenconnect.html
It turns out that poor #password security and outdated system lead to the recent cyberattack on Florida's water treatment facility, where an attacker tried to poison the water supply.
Read details here: https://thehackernews.com/2021/02/poor-password-security-lead-to-recent.html
Read details here: https://thehackernews.com/2021/02/poor-password-security-lead-to-recent.html
A researcher discovered a privacy flaw in the Telegram messenger that left media files shared over the self-destructible secret chat feature.
https://thehackernews.com/2021/02/secret-chat-in-telegram-left-self.html
In a separate issue, Telegram's macOS app stored local passcodes in plaintext.
https://thehackernews.com/2021/02/secret-chat-in-telegram-left-self.html
In a separate issue, Telegram's macOS app stored local passcodes in plaintext.
The Hacker News
Secret Chat in Telegram Left Self-Destructing Media Files On Devices
Privacy Flaw: Secret Chat in Telegram Left Self-Destructing Media Files On Devices
An Employee at Russia's leading technology company 'Yandex' caught selling unauthorized access to the users' mailboxes for personal gain.
Details: https://thehackernews.com/2021/02/yandex-employee-caught-selling-access.html
Yandex discloses 4,887 email accounts were compromised.
Details: https://thehackernews.com/2021/02/yandex-employee-caught-selling-access.html
Yandex discloses 4,887 email accounts were compromised.
As a new privacy feature, Apple will proxy Safe Browsing requests to preserve iOS users' privacy and hide IP addresses from Google.
Read: https://thehackernews.com/2021/02/apple-will-proxy-safe-browsing-requests.html
Read: https://thehackernews.com/2021/02/apple-will-proxy-safe-browsing-requests.html