More than 200,000 MicroTik routers worldwide are controlled by botnet malware, described by cybersecurity researchers as one of the largest botnet-as-a-service cybercrime operations in recent years.
Details: https://thehackernews.com/2022/03/over-200000-microtik-routers-worldwide.html
Details: https://thehackernews.com/2022/03/over-200000-microtik-routers-worldwide.html
π2
A new variant of Gimmick malware has been spotted that's designed to target Apple macOS systems.
Read details: https://thehackernews.com/2022/03/new-variant-of-chinese-gimmick-malware.html
Read details: https://thehackernews.com/2022/03/new-variant-of-chinese-gimmick-malware.html
Hackers from the Chinese cyberespionage group "Mustang Panda" deploying a new variant of the Korplug malware, dubbed Hodur.
Read details: https://thehackernews.com/2022/03/chinese-mustang-panda-hackers-spotted.html
Read details: https://thehackernews.com/2022/03/chinese-mustang-panda-hackers-spotted.html
π1
VMware releases patches for critical vulnerabilities in Carbon Black App Control, including a command injection (CVE-2022-22951) and a file upload vulnerability (CVE-2022-22952).
Read details: https://thehackernews.com/2022/03/vmware-issues-patches-for-critical.html
Read details: https://thehackernews.com/2022/03/vmware-issues-patches-for-critical.html
Researchers identified over 200 malicious NPM packages distributed via official repositories that targeted Microsoft Azure developers.
Read: https://thehackernews.com/2022/03/over-200-malicious-npm-packages-caught.html
Read: https://thehackernews.com/2022/03/over-200-malicious-npm-packages-caught.html
Researchers have traced the LAPSUS$ cyberattacks to a 16-year-old hacker in England.
Read details: https://thehackernews.com/2022/03/researchers-trace-lapsus-cyber-attacks.html
Read details: https://thehackernews.com/2022/03/researchers-trace-lapsus-cyber-attacks.html
A 23-year-old Russian national has been indicted in the U.S. and added to the FBI's Cyber Most Wanted list for allegedly administering a cybercrime forum that sold stolen login credentials, personal and credit card data.
Read: https://thehackernews.com/2022/03/23-year-old-russian-hacker-wanted-by.html
Read: https://thehackernews.com/2022/03/23-year-old-russian-hacker-wanted-by.html
At least 2 distinct groups of North Korean state- sponsored hackers exploited a ZERO-DAY (CVE-2022-0609) vulnerability in Google Chrome to launch cyberattacks on the fintech, IT, and media industries.
Read details: https://thehackernews.com/2022/03/north-korean-hackers-exploited-chrome.html
Read details: https://thehackernews.com/2022/03/north-korean-hackers-exploited-chrome.html
British police have arrested seven suspected members, aged 16 to 21, of the cyber extortion and hacking gang LAPSUS$, which attacked Okta, Microsoft, and Nvidia.
Read details: https://thehackernews.com/2022/03/7-suspected-members-of-lapsus-hacker.html
Read details: https://thehackernews.com/2022/03/7-suspected-members-of-lapsus-hacker.html
How to Build a Custom Malware Analysis Sandbox
https://thehackernews.com/2022/03/how-to-build-custom-malware-analysis.html
https://thehackernews.com/2022/03/how-to-build-custom-malware-analysis.html
π₯1
Google has rolled out an urgent out-of-band update for the Chrome browser for millions of Windows, macOS, and Linux users to patch a new actively exploited zero-day vulnerability.
Read details: https://thehackernews.com/2022/03/google-issues-urgent-chrome-update-to.html
Read details: https://thehackernews.com/2022/03/google-issues-urgent-chrome-update-to.html
Another Chinese hacker group has entered the fray of the Ukraine conflict and is attacking victims with the HeaderTip backdoor.
Read details: https://thehackernews.com/2022/03/another-chinese-hacking-group-spotted.html
Read details: https://thehackernews.com/2022/03/another-chinese-hacking-group-spotted.html
U.S. Federal Communications Commission (FCC) has added Russian cybersecurity firm Kaspersky Lab and two Chinese telecom firms on its list of national security threats, saying they pose an "unacceptable risk" to the country's national security.
https://thehackernews.com/2022/03/fcc-adds-kaspersky-and-chinese-telecom.html
https://thehackernews.com/2022/03/fcc-adds-kaspersky-and-chinese-telecom.html
Muhstik botnet is targeting Redis servers using a recently disclosed highly critical vulnerability (CVE-2022-0543 / CVSS 10.0) in the database system.
Read details: https://thehackernews.com/2022/03/muhstik-botnet-targeting-redis-servers.html
Read details: https://thehackernews.com/2022/03/muhstik-botnet-targeting-redis-servers.html
"Purple Fox" hackers have been using a new FatalRAT variant in their recent malware distribution campaigns and have also improved evasion mechanisms to bypass security software.
Read details: https://thehackernews.com/2022/03/purple-fox-hackers-spotted-using-new.html
Read details: https://thehackernews.com/2022/03/purple-fox-hackers-spotted-using-new.html
Cybercriminals are exploiting unpatched Microsoft Exchange servers to hijack email reply chains, tricking victims into installing IceID info-stealing malware.
Read details: https://thehackernews.com/2022/03/hackers-hijack-email-reply-chains-on.html
Read details: https://thehackernews.com/2022/03/hackers-hijack-email-reply-chains-on.html
This Mandiant incident report for Okta's Lapsus$ breach details the entire timeline of events.
Read details: https://thehackernews.com/2022/03/new-report-on-okta-hack-reveals-entire.html
Read details: https://thehackernews.com/2022/03/new-report-on-okta-hack-reveals-entire.html
Researchers have uncovered a large-scale supply chain attack which exploited dependency confusion attacks on NPM repository by uploading more than 800 malicious packages.
Read details: https://thehackernews.com/2022/03/a-threat-actor-dubbed-red-lili-has-been.html
Read details: https://thehackernews.com/2022/03/a-threat-actor-dubbed-red-lili-has-been.html
Hackers using a "complex and powerful" malware loader with the goal of installing cryptocurrency miners on compromised systems and potentially enabling the theft of #Discord tokens.
Details: https://thehackernews.com/2022/03/new-malware-loader-verblecon-infects.html
Details: https://thehackernews.com/2022/03/new-malware-loader-verblecon-infects.html
π1
A group of academics has designed a new system called "Privid" that provides privacy-preserving surveillance video analytics to combat concerns about invasive tracking.
Read details: https://thehackernews.com/2022/03/privid-privacy-preserving-surveillance.html
Read details: https://thehackernews.com/2022/03/privid-privacy-preserving-surveillance.html
π1
Researchers have observed a new βTransparent Tribeβ hacking campaign targeting #Indian government and military entities.
Read details: https://thehackernews.com/2022/03/new-hacking-campaign-by-transparent.html
Read details: https://thehackernews.com/2022/03/new-hacking-campaign-by-transparent.html
π1