Researchers demonstrate the first microarchitectural side-channel attacks that leverage contention on the CPU ring interconnect against Intel CPUs, allowing malware to pilfer sensitive data from modern processors.
Read details: https://thehackernews.com/2021/03/malware-can-exploit-new-flaw-in-intel.html
  Read details: https://thehackernews.com/2021/03/malware-can-exploit-new-flaw-in-intel.html
Iranian hackers are leveraging another legitimate remote access software to actively spy on its targets from academia, government and tourism entities in the Middle East and neighboring regions.
Read more: https://thehackernews.com/2021/03/iranian-hackers-using-remote-utilities.html
  Read more: https://thehackernews.com/2021/03/iranian-hackers-using-remote-utilities.html
🔥 PATCH! Apple has released out-of-band security updates for billions of devices running iOS, macOS, watchOS, and Safari browser to address a high-severity vulnerability (CVE-2021-1844) that could allow remote attackers to run arbitrary code on affected devices via malicious web content only.
Read: https://thehackernews.com/2021/03/apple-issues-patch-for-remote-hacking.html
  Read: https://thehackernews.com/2021/03/apple-issues-patch-for-remote-hacking.html
European Banking Authority (EBA) disclosed it had also been targeted by hackers exploiting Microsoft Exchange server vulnerabilities.
Read details: https://thehackernews.com/2021/03/microsoft-exchange-hackers-also.html
The widespread cyberattack forced it to temporarily take its email systems offline as a precautionary measure.
  Read details: https://thehackernews.com/2021/03/microsoft-exchange-hackers-also.html
The widespread cyberattack forced it to temporarily take its email systems offline as a precautionary measure.
WARNING: A new malware dropper distributes AlienBot Banker and MRAT #malware via Android apps on Google Play store, designed to let attackers gain intrusive access to victims' financial accounts as well as full control of their devices.
Read: https://thehackernews.com/2021/03/9-android-apps-on-google-play-caught.html
  Read: https://thehackernews.com/2021/03/9-android-apps-on-google-play-caught.html
SolarWinds Hack — New Evidence Suggests Potential Links to Chinese Hackers
https://thehackernews.com/2021/03/solarwinds-hack-new-evidence-suggests.html
#infosec #cyberattack
  
  https://thehackernews.com/2021/03/solarwinds-hack-new-evidence-suggests.html
#infosec #cyberattack
The Hacker News
  
  SolarWinds Hack — New Evidence Suggests Potential Links to Chinese Hackers
  A web shell deployed on Windows PC by leveraging zero-day in SolarWinds network monitoring software may have been the work of a Chinese hacking group.
  After taking another year-and-a-half break, financially motivated FIN8 hackers have returned with a more powerful and stealthy version of BADHATCH backdoor, designed to steal payment card data from point-of-sale (POS) systems.
Read: https://thehackernews.com/2021/03/fin8-hackers-return-with-more-powerful.html
  Read: https://thehackernews.com/2021/03/fin8-hackers-return-with-more-powerful.html
Researchers unveil a new sophisticated backdoor, dubbed "RedXOR," targeting Linux endpoints and servers, believed to be the work of Chinese nation-state actors.
Read details: https://thehackernews.com/2021/03/researchers-unveil-new-linux-malware.html
  Read details: https://thehackernews.com/2021/03/researchers-unveil-new-linux-malware.html
A critical pre-auth RCE flaw (CVE-2021-22986) has been discovered in the F5's Big-IP and BIG-IQ software — Patch ASAP!
Read details: https://thehackernews.com/2021/03/critical-pre-auth-rce-flaw-found-in-f5.html
Besides this, a few other newly reported flaws also result in a denial of service (DoS) attack.
  Read details: https://thehackernews.com/2021/03/critical-pre-auth-rce-flaw-found-in-f5.html
Besides this, a few other newly reported flaws also result in a denial of service (DoS) attack.
WARNING — A public PoC exploit has been released for Microsoft Exchange ProxyLogon flaw, likely to fuel mass exploitation and more disruptive cyberattacks against thousands of unpatched servers.
Details: https://thehackernews.com/2021/03/proxylogon-exchange-poc-exploit.html
Situation is escalating. Patch your servers ASAP!
  Details: https://thehackernews.com/2021/03/proxylogon-exchange-poc-exploit.html
Situation is escalating. Patch your servers ASAP!
Researchers demonstrate a new Browser-based Side-Channel attack that can then be leveraged to track users online even when the #JavaScript is completely disabled.
The latest attack is also architecturally agnostic, resulting in microarchitectural website fingerprinting attacks that work across hardware platforms, including Intel Core, AMD Ryzen, Samsung Exynos 2100, and Apple M1 CPUs — making it the first known side-channel attack on the iPhone maker's new ARM-based chipsets.
Read details: https://thehackernews.com/2021/03/new-browser-attack-allows-tracking.html
  The latest attack is also architecturally agnostic, resulting in microarchitectural website fingerprinting attacks that work across hardware platforms, including Intel Core, AMD Ryzen, Samsung Exynos 2100, and Apple M1 CPUs — making it the first known side-channel attack on the iPhone maker's new ARM-based chipsets.
Read details: https://thehackernews.com/2021/03/new-browser-attack-allows-tracking.html
Watch Out! Cybercriminals are now leveraging the heavily exploited #ProxyLogon flaws to target unpatched Microsoft Exchange servers with a new strain of ransomware called #DearCry.
https://thehackernews.com/2021/03/icrosoft-exchange-ransomware.html
  https://thehackernews.com/2021/03/icrosoft-exchange-ransomware.html
Researchers have spotted a new malware, dubbed 'NimzaLoader,' written in Nim, a rare programming language, likely to avoid detection.
Read details: https://thehackernews.com/2021/03/researchers-spotted-malware-written-in.html
  Read details: https://thehackernews.com/2021/03/researchers-spotted-malware-written-in.html
🔥 WARNING — A second Google Chrome browser zero-day vulnerability (CVE-2021-21193) has been found actively exploited in-the-wild.
Read details: https://thehackernews.com/2021/03/another-google-chrome-0-day-bug-found.html
Update your browser for Windows, Mac, and Linux systems to 89.0.4389.90 or the latest available version.
  Read details: https://thehackernews.com/2021/03/another-google-chrome-0-day-bug-found.html
Update your browser for Windows, Mac, and Linux systems to 89.0.4389.90 or the latest available version.
🔥Deal : CompTIA Security Certification Prep — Get lifetime access to online program offering training for 4 cybersecurity certifications: Security+, CySA+, CASP, and PenTest.
Register now for taking benefit of a 🕒 limited-time 97% discount: https://thehackernews.com/2021/03/comptia-security-certification-prep.html
  
  Register now for taking benefit of a 🕒 limited-time 97% discount: https://thehackernews.com/2021/03/comptia-security-certification-prep.html
The Hacker News
  
  CompTIA Security Certification Prep — Lifetime Access for just $30
  The CompTIA Security Infrastructure Expert Bundle: Get lifetime access to all four courses for just $29.99.
  Microsoft has released a one-click mitigation software that applies all the necessary countermeasures to secure vulnerable environments against the ongoing widespread ProxyLogon Exchange server cyberattacks.
Find details here: https://thehackernews.com/2021/03/use-this-one-click-mitigation-tool-from.html
  Find details here: https://thehackernews.com/2021/03/use-this-one-click-mitigation-tool-from.html
Part 1 — A new wave of ongoing cyberattacks exploiting a new set of vulnerabilities to deploy Mirai variants and brute-forcers on compromised systems.
Part 2 — In a related development, a new Mirai-based botnet called ZHtrap has been spotted turning infected devices into honeypot to harvest additional infected devices.
Read details: https://thehackernews.com/2021/03/new-mirai-variant-and-zhtrap-botnet.html
  Part 2 — In a related development, a new Mirai-based botnet called ZHtrap has been spotted turning infected devices into honeypot to harvest additional infected devices.
Read details: https://thehackernews.com/2021/03/new-mirai-variant-and-zhtrap-botnet.html
🔥 iOS 14.5 Beta code suggests Apple may soon start delivering security patches separately from other OS updates.
Details: https://thehackernews.com/2021/03/apple-may-start-delivering-security.html
It aims to deliver emergency patches without forcing users to re-re-downloading the entire 'heavily sized' OS updates each time.
  Details: https://thehackernews.com/2021/03/apple-may-start-delivering-security.html
It aims to deliver emergency patches without forcing users to re-re-downloading the entire 'heavily sized' OS updates each time.
18-year-old hacker get 3 years in jail for masterminding the last year's massive Twitter hack.
Read: https://thehackernews.com/2021/03/18-year-old-hacker-gets-3-years-in.html
The attack involved hijacking several high-profile accounts—including of Barack Obama, Joe Biden, Bill Gates—to push a widespread cryptocurrency scam.
  Read: https://thehackernews.com/2021/03/18-year-old-hacker-gets-3-years-in.html
The attack involved hijacking several high-profile accounts—including of Barack Obama, Joe Biden, Bill Gates—to push a widespread cryptocurrency scam.
Email security firm Mimecast revealed that the state-sponsored SolarWinds hackers who broke into its internal network also downloaded its source code out of a limited number of repositories.
Details: https://thehackernews.com/2021/03/mimecast-finds-solarwinds-hackers-stole.html
  Details: https://thehackernews.com/2021/03/mimecast-finds-solarwinds-hackers-stole.html
Critical flaws reported in two highly popular WordPress plugins—Elementor and WP Super Cache—which, if successfully exploited, could allow attackers to take over unpatched website in certain scenarios. PATCH NOW!
https://thehackernews.com/2021/03/flaws-in-two-popular-wordpress-plugins.html
  https://thehackernews.com/2021/03/flaws-in-two-popular-wordpress-plugins.html