Part 1 — A new wave of ongoing cyberattacks exploiting a new set of vulnerabilities to deploy Mirai variants and brute-forcers on compromised systems.
Part 2 — In a related development, a new Mirai-based botnet called ZHtrap has been spotted turning infected devices into honeypot to harvest additional infected devices.
Read details: https://thehackernews.com/2021/03/new-mirai-variant-and-zhtrap-botnet.html
Part 2 — In a related development, a new Mirai-based botnet called ZHtrap has been spotted turning infected devices into honeypot to harvest additional infected devices.
Read details: https://thehackernews.com/2021/03/new-mirai-variant-and-zhtrap-botnet.html
🔥 iOS 14.5 Beta code suggests Apple may soon start delivering security patches separately from other OS updates.
Details: https://thehackernews.com/2021/03/apple-may-start-delivering-security.html
It aims to deliver emergency patches without forcing users to re-re-downloading the entire 'heavily sized' OS updates each time.
Details: https://thehackernews.com/2021/03/apple-may-start-delivering-security.html
It aims to deliver emergency patches without forcing users to re-re-downloading the entire 'heavily sized' OS updates each time.
18-year-old hacker get 3 years in jail for masterminding the last year's massive Twitter hack.
Read: https://thehackernews.com/2021/03/18-year-old-hacker-gets-3-years-in.html
The attack involved hijacking several high-profile accounts—including of Barack Obama, Joe Biden, Bill Gates—to push a widespread cryptocurrency scam.
Read: https://thehackernews.com/2021/03/18-year-old-hacker-gets-3-years-in.html
The attack involved hijacking several high-profile accounts—including of Barack Obama, Joe Biden, Bill Gates—to push a widespread cryptocurrency scam.
Email security firm Mimecast revealed that the state-sponsored SolarWinds hackers who broke into its internal network also downloaded its source code out of a limited number of repositories.
Details: https://thehackernews.com/2021/03/mimecast-finds-solarwinds-hackers-stole.html
Details: https://thehackernews.com/2021/03/mimecast-finds-solarwinds-hackers-stole.html
Critical flaws reported in two highly popular WordPress plugins—Elementor and WP Super Cache—which, if successfully exploited, could allow attackers to take over unpatched website in certain scenarios. PATCH NOW!
https://thehackernews.com/2021/03/flaws-in-two-popular-wordpress-plugins.html
https://thehackernews.com/2021/03/flaws-in-two-popular-wordpress-plugins.html
🔥 Here's everything Google tracks about you!
Apple's App Tracking Transparency rule forced Google to reveal and clarify what personal data Chrome and other of its apps collect on you.
Read: https://thehackernews.com/2021/03/google-to-reveals-what-personal-data.html
Apple's App Tracking Transparency rule forced Google to reveal and clarify what personal data Chrome and other of its apps collect on you.
Read: https://thehackernews.com/2021/03/google-to-reveals-what-personal-data.html
The Hacker News
Google Reveals What Personal Data Chrome and Its Apps Collect On You
Apple App Tracking Transparency Feature Forces Google to Reveal What Personal Data Chrome and It’s Apps Collect on You
A pair of critical vulnerabilities have been found in the popular MyBB forum/bulletin software, which an unprivileged remote attacker can exploit to achieve RCE on targeted sites.
https://thehackernews.com/2021/03/critical-rce-flaw-reported-in-mybb.html
MyBB v1.8.26 released to patch reported issues. Update Now!
https://thehackernews.com/2021/03/critical-rce-flaw-reported-in-mybb.html
MyBB v1.8.26 released to patch reported issues. Update Now!
A new 'unpatched bug' in Zoom's screen-sharing feature could let other attendees in calls access restricted applications and leak sensitive information.
Read more: https://thehackernews.com/2021/03/new-zoom-screen-sharing-bug-lets-other.html
Read more: https://thehackernews.com/2021/03/new-zoom-screen-sharing-bug-lets-other.html
Watch Out—Hackers are leveraging trojanized Xcode projects in a newly spotted supply-chain attack to compromise macOS systems belonging to Apple platform developers with a backdoor.
Read: https://thehackernews.com/2021/03/hackers-infecting-apple-app-developers.html
Read: https://thehackernews.com/2021/03/hackers-infecting-apple-app-developers.html
👍1
U.S. Department of Justice announces updates on 2 separate hacking cases:
—a Swiss hacktivist charged for theft and fraud.
—a Russian who planned to plant ransomware in the Tesla company pleads guilty.
Details: https://thehackernews.com/2021/03/tesla-ransomware-hacker-pledges-guilty.html
—a Swiss hacktivist charged for theft and fraud.
—a Russian who planned to plant ransomware in the Tesla company pleads guilty.
Details: https://thehackernews.com/2021/03/tesla-ransomware-hacker-pledges-guilty.html
A critical vulnerability (CVE-2021-22986 / CVSS score: 9.8) affecting F5's BIG-IP and BIG-IQ products is UNDER ACTIVE ATTACKS after a PoC exploit was posted online.
Read details: https://thehackernews.com/2021/03/latest-f5-big-ip-bug-under-active.html
Read details: https://thehackernews.com/2021/03/latest-f5-big-ip-bug-under-active.html
A high severity RCE vulnerability (CVE-2021-26295) has been found in Apache OFBiz that could let unauthenticated, remote hackers seize control of the enterprise resource planning (ERP) systems.
Read details: https://thehackernews.com/2021/03/critical-rce-vulnerability-found-in.html
A patched version has now been released. Update your software immediately.
Read details: https://thehackernews.com/2021/03/critical-rce-vulnerability-found-in.html
A patched version has now been released. Update your software immediately.
Several critical vulnerabilities have been discovered in popular remote teaching and student monitoring software Netop Vision Pro that attackers could abuse to malicious to execute arbitrary code and take over students computers.
Read details: https://thehackernews.com/2021/03/popular-netops-remote-learning-software.html
Read details: https://thehackernews.com/2021/03/popular-netops-remote-learning-software.html
🔥BEWARE! Google warns of a newly discovered 0-day vulnerability affecting Android devices with Qualcomm chipsets that is being used by hackers to launch targeted attacks.
Read details: https://thehackernews.com/2021/03/warning-new-android-zero-day.html
Read details: https://thehackernews.com/2021/03/warning-new-android-zero-day.html
CISA warns of newly disclosed critical security vulnerabilities in GE's Universal Relay (UR) family of power management devices that pose a threat to the security of IEC Electrical Utilities.
Read: https://thehackernews.com/2021/03/critical-flaws-affecting-ges-universal.html
Read: https://thehackernews.com/2021/03/critical-flaws-affecting-ges-universal.html
Purple Fox rootkit malware gains wormable capabilities to spread itself to other Windows computers.
Details: https://thehackernews.com/2021/03/purple-fox-rootkit-can-now-spread.html
Details: https://thehackernews.com/2021/03/purple-fox-rootkit-can-now-spread.html
Facebook has smashed a network of hackers from China who used its social media platform to hack the Uyghur Muslims living abroad by tricking them into downloading malware designed to spy on their computers and smartphones.
Read details: https://thehackernews.com/2021/03/chinese-hackers-used-facebook-to-hack.html
Read details: https://thehackernews.com/2021/03/chinese-hackers-used-facebook-to-hack.html
WATCH OUT! Cisco Jabber messaging software for Windows, macOS, Android, and iOS contains critical vulnerabilities that could allow hackers to hijack your devices remotely.
Details on this, patches and 37 other Cisco advisories: https://thehackernews.com/2021/03/critical-cisco-jabber-bug-could-let.html
Details on this, patches and 37 other Cisco advisories: https://thehackernews.com/2021/03/critical-cisco-jabber-bug-could-let.html
Black Kingdom ransomware is hunting unpatched #Microsoft Exchange servers affected by ProxyLogon vulnerabilities.
Read: https://thehackernews.com/2021/03/black-kingdom-ransomware-hunting.html
Read: https://thehackernews.com/2021/03/black-kingdom-ransomware-hunting.html
The Hacker News
Black Kingdom Ransomware Hunting Unpatched Microsoft Exchange Servers
Black Kingdom Ransomware Is Now Hunting Unpatched Microsoft Exchange Servers
Warning — SolarWinds Orion Platform has been found vulnerable to a new critical remote code execution (RCE) vulnerability via JSON deserialization.
Read: https://thehackernews.com/2021/03/solarwinds-orion-vulnerability.html
Patches have been released for this and 3 other vulnerabilities.
#infosec #cybersecurity
Read: https://thehackernews.com/2021/03/solarwinds-orion-vulnerability.html
Patches have been released for this and 3 other vulnerabilities.
#infosec #cybersecurity
The Hacker News
Another Critical RCE Flaw Discovered in SolarWinds Orion Platform
A new critical vulnerability discovered in SolarWinds Orion Platform can be exploited to achieve remote code execution.
🔥 Researchers discover new vulnerabilities in 5G network slicing that could expose priority users (i.e., mission-critical sectors) to location tracking and service disruption attacks.
Read details: https://thehackernews.com/2021/03/new-5g-flaw-exposes-priority-networks.html
Read details: https://thehackernews.com/2021/03/new-5g-flaw-exposes-priority-networks.html
The Hacker News
New 5G Flaw Exposes Priority Networks to Location Tracking and Other Attacks
Researchers discover vulnerabilities in 5G Network Slicing feature that could expose priority users to location tracking and service disruption attack