Google introduces a new "Data Safety" section for Android apps in the Play Store to highlight the type of data that is collected and shared with third-parties.
Read details: https://thehackernews.com/2022/04/googles-new-safety-section-shows-what.html
Read details: https://thehackernews.com/2022/04/googles-new-safety-section-shows-what.html
WATCH OUT!!!
QNAP advises NAS device users to immediately mitigate new remote hacking flaws until patches are available.
Read details: https://thehackernews.com/2022/04/qnap-advises-to-mitigate-remote-hacking.html
QNAP advises NAS device users to immediately mitigate new remote hacking flaws until patches are available.
Read details: https://thehackernews.com/2022/04/qnap-advises-to-mitigate-remote-hacking.html
CloudFlare thwarts yet another record HTTP distributed denial-of-service (DDoS) attack, peaking at 15.3 million requests per second.
Read details: https://thehackernews.com/2022/04/cloudflare-thwarts-record-ddos-attack.html
Read details: https://thehackernews.com/2022/04/cloudflare-thwarts-record-ddos-attack.html
U.S. cybersecurity agency CISA has published a list of top 15 software vulnerabilities that were routinely exploited in 2021.
Read Details: https://thehackernews.com/2022/04/us-cybersecurity-agency-lists-2021s-top.html
Read Details: https://thehackernews.com/2022/04/us-cybersecurity-agency-lists-2021s-top.html
👍2
A new malware campaign leveraging an exploit kit has been observed infecting victims' computers with the RedLine stealer trojan.
Read details: https://thehackernews.com/2022/04/new-rig-exploit-kit-campaign-infecting.html
Read details: https://thehackernews.com/2022/04/new-rig-exploit-kit-campaign-infecting.html
Cybercriminals behind the BazaLoader and IcedID malware attacks now use a new multifunctional loader called Bumblebee that drops Cobalt Strike, shellcode, Sliver, and the Meterpreter backdoor on target computers.
Read: https://thehackernews.com/2022/04/cybercriminals-using-new-malware-loader.html
Read: https://thehackernews.com/2022/04/cybercriminals-using-new-malware-loader.html
Twitter's new owner, Elon Musk wants to make the platform's direct messages (DM) end-to-end encrypted, like Signal Messenger, "so no one can spy on or hack your messages."
Read: https://thehackernews.com/2022/04/twitters-new-owner-elon-musk-wants-dms.html
Read: https://thehackernews.com/2022/04/twitters-new-owner-elon-musk-wants-dms.html
Researchers detail three hacking teams working under the umbrella of the cyberespionage group TA410, named FlowingFrog, LookingFrog and JollyFrog, each with its own toolset and is known to target a variety of critical infrastructures.
Read: https://thehackernews.com/2022/04/experts-detail-3-hacking-teams-working.html
Read: https://thehackernews.com/2022/04/experts-detail-3-hacking-teams-working.html
Indian government has issued new guidelines that make it mandatory for service providers, intermediaries, data centers, and government agencies to report cybersecurity incidents to CERT-In within 6 hours.
Read: https://thehackernews.com/2022/04/indian-govt-orders-organisations-to.html
Read: https://thehackernews.com/2022/04/indian-govt-orders-organisations-to.html
A pair of security issues have been reported in the Microsoft Azure database for PostgreSQL Flexible Server that could have allowed unauthorized cross-account access to databases.
Read: https://thehackernews.com/2022/04/microsoft-azure-vulnerability-exposes.html
Read: https://thehackernews.com/2022/04/microsoft-azure-vulnerability-exposes.html
Russia has launched over 200 "destructive and relentless" cyberattacks on Ukraine since the war started, Microsoft says.
Read: https://t.co/1EyIw7acPJ
Read: https://t.co/1EyIw7acPJ
OpenSSF project has released a tool that scans popular open-source repositories for malicious packages. Named "Package Analysis," the tool identified more than 200 malicious packages in just one month of analysis.
Details: https://thehackernews.com/2022/05/heres-new-tool-that-scans-for-malicious.html
Details: https://thehackernews.com/2022/05/heres-new-tool-that-scans-for-malicious.html
Google has officially released the first developer preview for the Privacy Sandbox on Android 13, offering an "early look" at the SDK Runtime and Topics API to improve users' privacy online.
Read: https://thehackernews.com/2022/05/google-releases-first-developer-preview.html
Read: https://thehackernews.com/2022/05/google-releases-first-developer-preview.html
In a new campaign, Russian state-sponsored Cozy Bear (APT29) hackers have been spotted targeting diplomatic and government organizations in Europe, America, and Asia.
Read: https://thehackernews.com/2022/05/russian-hackers-targeting-diplomatic.html
Read: https://thehackernews.com/2022/05/russian-hackers-targeting-diplomatic.html
Chinese state-sponsored "Override Panda" hackers have resurfaced in recent weeks with new #cyberespionage attacks aimed at stealing sensitive information.
Read: https://thehackernews.com/2022/05/chinese-override-panda-hackers.html
Read: https://thehackernews.com/2022/05/chinese-override-panda-hackers.html
🤯1
GitHub describes the recent cyberattack campaign involving the abuse of OAuth access tokens issued to Heroku and Travis-CI as "highly targeted" in nature.
Read: https://thehackernews.com/2022/05/github-says-recent-attack-involving.html
Read: https://thehackernews.com/2022/05/github-says-recent-attack-involving.html
👍1
A newly discovered suspected espionage hacking group, dubbed UNC3524, is targeting the emails of employees involved in corporate development, mergers and acquisitions, and large corporate transactions.
Read: https://thehackernews.com/2022/05/new-hacker-group-pursuing-corporate.html
Read: https://thehackernews.com/2022/05/new-hacker-group-pursuing-corporate.html
A newly discovered UNPATCHED vulnerability (CVE-2022-05-02) affects the DNS implementation of two popular libraries (Clibc and uClibc-ng) used in a number of IoT devices, allowing attackers to perform DNS poisoning attacks on targeted devices.
https://thehackernews.com/2022/05/unpatched-dns-related-vulnerability.html
https://thehackernews.com/2022/05/unpatched-dns-related-vulnerability.html
👍1
China-aligned "Moshen Dragon" cyberespionage group has been caught using abusing popular antivirus products to sideload malware into telecommunications systems operating in Central Asia.
Read details: https://thehackernews.com/2022/05/chinese-hackers-caught-exploiting.html
Read details: https://thehackernews.com/2022/05/chinese-hackers-caught-exploiting.html
Researchers have detected a new variant of AvosLocker ransomware that uses a legitimate driver file to disable antivirus solutions and evade detection.
Read: https://thehackernews.com/2022/05/avoslocker-ransomware-variant-using-new.html
Read: https://thehackernews.com/2022/05/avoslocker-ransomware-variant-using-new.html
👍1
Researchers analyze dozens of communications between Conti and Hive ransomware operators and victims, revealing the actors' communication style, persuasion tactics, ransom negotiation techniques, operational and targeting details, and more.
https://thehackernews.com/2022/05/experts-analyze-conti-and-hive.html
https://thehackernews.com/2022/05/experts-analyze-conti-and-hive.html