🚨 Heads up! New Zaraza bot credential-stealing malware is on the loose! Spotted on a Russian Telegram hacker channel, it targets 38 web browsers and steals login credentials for bank accounts, crypto wallets, and more.
Read details: https://thehackernews.com/2023/04/new-zaraza-bot-credential-stealer-sold.html
Read details: https://thehackernews.com/2023/04/new-zaraza-bot-credential-stealer-sold.html
😁10🔥7👍4⚡3🤔2👏1😱1
🔐 URGENT: Google releases out-of-band updates for a new actively exploited zero-day vulnerability (CVE-2023-2033) in Chrome browser.
Read details: https://thehackernews.com/2023/04/google-releases-urgent-chrome-update-to.html
First one addressed this year! Update to version 112.0.5615.121 ASAP!
Read details: https://thehackernews.com/2023/04/google-releases-urgent-chrome-update-to.html
First one addressed this year! Update to version 112.0.5615.121 ASAP!
🔥35👍11😁7⚡4😱3
Chinese nation-state group HOODOO targets Taiwanese media organization using open-source red teaming tool GC2, exploiting Google's infrastructure.
Read details: https://thehackernews.com/2023/04/google-uncovers-apt41s-use-of-open.html
Read details: https://thehackernews.com/2023/04/google-uncovers-apt41s-use-of-open.html
😱12🔥8👍7⚡6😁5🤔3🤯3
Cybercriminal syndicates FIN7 and ex-Conti members have teamed up to launch Domino malware attacks, which are being used to deliver information stealers and backdoors like Cobalt Strike.
Read details: https://thehackernews.com/2023/04/fin7-and-ex-conti-cybercrime-gangs-join.html
Read details: https://thehackernews.com/2023/04/fin7-and-ex-conti-cybercrime-gangs-join.html
👍17👏3⚡2😁2🤔2🤯1
Researchers have uncovered a new QBot malware campaign that is using hijacked business correspondence to lure unsuspecting victims into installing the banking trojan.
Learn more about this: https://thehackernews.com/2023/04/new-qbot-banking-trojan-campaign.html
The latest campaign has targeted users in several countries.
Learn more about this: https://thehackernews.com/2023/04/new-qbot-banking-trojan-campaign.html
The latest campaign has targeted users in several countries.
👍14😱6🔥3😁1
Israeli spyware vendor QuaDream is reportedly shutting down its operations after its REIGN hacking toolset was exposed by Citizen Lab and Microsoft.
Read details: https://thehackernews.com/2023/04/israeli-spyware-vendor-quadream-to-shut.html
Read details: https://thehackernews.com/2023/04/israeli-spyware-vendor-quadream-to-shut.html
👍38🔥9😁9🤯9😱5🤔4⚡1
A new LockBit ransomware operation has surfaced and this time, it's targeting Apple's macOS devices.
Read details: https://thehackernews.com/2023/04/lockbit-ransomware-now-targeting-apple.html
Read details: https://thehackernews.com/2023/04/lockbit-ransomware-now-targeting-apple.html
😁29🔥12🤯8👍7👏4
In a new twist to malware distribution, threat actors are using YouTube videos to distribute the Aurora information stealer via "highly evasive" in2al5d p3in4er loader.
Read on to learn more: https://thehackernews.com/2023/04/youtube-videos-distributing-aurora.html
Read on to learn more: https://thehackernews.com/2023/04/youtube-videos-distributing-aurora.html
🤯13⚡5👍2😁2
New malware strain, Goldoson, has been detected in over 60 Android apps with more than 100 million downloads from the Google Play Store.
Read details: https://thehackernews.com/2023/04/goldoson-android-malware-infects-over.html
Read details: https://thehackernews.com/2023/04/goldoson-android-malware-infects-over.html
👍21😱6⚡2🔥1🤔1
Iranian MuddyWater hacker group has been found using the legitimate SimpleHelp remote support software to maintain persistence on victim devices.
Read details: https://thehackernews.com/2023/04/iranian-hackers-using-simplehelp-remote.html
Read details: https://thehackernews.com/2023/04/iranian-hackers-using-simplehelp-remote.html
👍30😁6🔥5🤯4⚡3🤔2
Two critical flaws (CVE-2023-29199 / CVE-2023-30547) have been discovered in vm2 JavaScript library that could allow attackers to break out of sandbox protections, potentially leading to RCE attacks.
Read details: https://thehackernews.com/2023/04/critical-flaws-in-vm2-javascript.html
Read details: https://thehackernews.com/2023/04/critical-flaws-in-vm2-javascript.html
🔥29👍5😁4⚡3👏3
Iranian govt-linked hackers have been identified as responsible for cyberattacks on critical infrastructure in the United States — targeting energy companies, transit systems, as well as a major utility and gas companies.
Details: https://thehackernews.com/2023/04/iranian-government-backed-hackers.html
Details: https://thehackernews.com/2023/04/iranian-government-backed-hackers.html
👍20😁10🤯9🔥3😱3⚡2
U.K. and U.S. cybersecurity agencies have warned of Russian nation-state actors exploiting flaws affecting Cisco networking equipment to deploy malware and conduct reconnaissance.
Read details: https://thehackernews.com/2023/04/us-and-uk-warn-of-russian-hackers.html
Read details: https://thehackernews.com/2023/04/us-and-uk-warn-of-russian-hackers.html
🔥17👍6👏3🤯3🤔2😁1
🚨 Pakistan-based APT36 hackers are reportedly using a new Linux backdoor called Poseidon to target Indian government agencies, using a fake version of the govt-mandated 2FA software, Kavach, as a disguise.
Read details: https://thehackernews.com/2023/04/pakistani-hackers-use-linux-malware.html
Read details: https://thehackernews.com/2023/04/pakistani-hackers-use-linux-malware.html
👍24🤔13🔥10😁9😱4⚡2👏2
Google TAG identifies state-sponsored cyber actor FROZENLAKE (aka APT28, Fancy Bear, and more) conducting phishing campaigns to extract intelligence and influence public discourse related to the war in Ukraine.
Learn more: https://thehackernews.com/2023/04/google-tag-warns-of-russian-hackers.html
Learn more: https://thehackernews.com/2023/04/google-tag-warns-of-russian-hackers.html
👍25🤔8⚡4😁4🤯2
Israeli spyware maker NSO Group reportedly deployed at least 3 "zero-click" exploits against iPhones in 2022 to install Pegasus and spy on human rights defenders, journalists and others.
☠️ LATENTIMAGE
☠️ FINDMYPWN
☠️ PWNYOURHOME
Details: https://thehackernews.com/2023/04/nso-group-used-3-zero-click-iphone.html
☠️ LATENTIMAGE
☠️ FINDMYPWN
☠️ PWNYOURHOME
Details: https://thehackernews.com/2023/04/nso-group-used-3-zero-click-iphone.html
😁22😱21👍11⚡7🤔5🔥3👏2🤯2
China-linked hackers target African telecom service providers in a sophisticated campaign using previously unseen plugins from the MgBot malware framework.
Read details: https://thehackernews.com/2023/04/daggerfly-cyberattack-campaign-hits.html
Read details: https://thehackernews.com/2023/04/daggerfly-cyberattack-campaign-hits.html
👍18⚡11😁6👏5😱1
Alibaba Cloud's ApsaraDB RDS and AnalyticDB for PostgreSQL have been hit with critical vulnerabilities that could expose sensitive data belonging to other customers.
Learn more about the BrokenSesame flaws here: https://thehackernews.com/2023/04/two-critical-flaws-found-in-alibaba.html
Learn more about the BrokenSesame flaws here: https://thehackernews.com/2023/04/two-critical-flaws-found-in-alibaba.html
👏7👍4🔥4😱3😁2
Notorious Lazarus Group hackers strike again, this time leveraging fraudulent job offers to trick victims into downloading Linux malware.
Read details: https://thehackernews.com/2023/04/lazarus-group-adds-linux-malware-to.html
Read details: https://thehackernews.com/2023/04/lazarus-group-adds-linux-malware-to.html
🤯11🔥9👍8😁4😱2⚡1
Fortra sheds light on a zero-day remote code execution (RCE) vulnerability (CVE-2023-0669) in its GoAnywhere MFT tool, actively exploited by ransomware attackers.
Read details: https://thehackernews.com/2023/04/fortra-sheds-light-on-goanywhere-mft.html
Read details: https://thehackernews.com/2023/04/fortra-sheds-light-on-goanywhere-mft.html
🤯13👍8🔥4😁4⚡2
North Korean hackers demonstrate new levels of sophistication with the recent supply chain attack targeting 3CX. Researchers have revealed that it's the first time a software supply chain attack has led to another attack.
Read details: https://thehackernews.com/2023/04/nk-hackers-employ-matryoshka-doll-style.html
Read details: https://thehackernews.com/2023/04/nk-hackers-employ-matryoshka-doll-style.html
🔥17👍6😁5🤯5⚡4🤔1