β οΈ North Korean hackers are using LinkedIn to spread RustDoor malware, posing as crypto recruiters to target professionals.
They trick victims into downloading booby-trapped coding tests, with macOS backdoor.
Read: https://thehackernews.com/2024/09/north-korean-hackers-target.html
They trick victims into downloading booby-trapped coding tests, with macOS backdoor.
Read: https://thehackernews.com/2024/09/north-korean-hackers-target.html
π€―27π15π₯5
π¨ PCI DSS v4 Deadline Approaching β Are You Ready?
PCI DSS v4.0 prioritizes monitoring payment page scripts. Sections 6.4.3 & 11.6.1 require vigilance on script integrity to block malicious injections.
https://thehackernews.com/2024/09/master-your-pci-dss-v4-compliance-with.html
β³ Donβt waitβenable real-time monitoring now.
PCI DSS v4.0 prioritizes monitoring payment page scripts. Sections 6.4.3 & 11.6.1 require vigilance on script integrity to block malicious injections.
https://thehackernews.com/2024/09/master-your-pci-dss-v4-compliance-with.html
β³ Donβt waitβenable real-time monitoring now.
π14π€―5π€4π3π1
SolarWinds just released critical patches for Access Rights Manager (ARM) vulnerabilities, including one rated 9.0/10 for remote code execution (CVE-2024-28991).
Read: https://thehackernews.com/2024/09/solarwinds-issues-patch-for-critical.html
If you're using ARM, patch now to prevent future attacks.
Read: https://thehackernews.com/2024/09/solarwinds-issues-patch-for-critical.html
If you're using ARM, patch now to prevent future attacks.
π₯12π2
π¨ Alert: Binance warns of a global clipper #malware threat targeting #cryptocurrency users, intercepting wallet addresses to divert funds to rogue wallets. Significant financial losses reported.
Read: https://thehackernews.com/2024/09/binance-warns-of-rising-clipper-malware.html
Be cautious when downloading apps or plugins!
Read: https://thehackernews.com/2024/09/binance-warns-of-rising-clipper-malware.html
Be cautious when downloading apps or plugins!
π€―15π6π3
24 BILLION leaked credentials are driving cyberattacks on SaaS apps, outpacing security teams. MFA isnβt enoughβattackers are bypassing it. Tailored SaaS threat intelligence is now essential.
Learn more: https://thehackernews.com/expert-insights/2024/09/how-does-threat-intelligence-apply-to.html
Act now before itβs too late!
Learn more: https://thehackernews.com/expert-insights/2024/09/how-does-threat-intelligence-apply-to.html
Act now before itβs too late!
π17π€―6π₯5π1π1
π¨ Meta will soon start using public Facebook and Instagram content from U.K. users to train its generative AI models. Users will be notified via in-app prompts and can opt out if they don't want their data used for AI training.
Read: https://thehackernews.com/2024/09/meta-to-train-ai-models-using-public-uk.html
Read: https://thehackernews.com/2024/09/meta-to-train-ai-models-using-public-uk.html
π±18π10π9π4
π The U.S. Department of the Treasury sanctions key Intellexa executives behind Predator #spyware, a tool reportedly targeting Angola, the DRC, and Saudi Arabia using new evasion tactics.
Learn more: https://thehackernews.com/2024/09/us-treasury-sanctions-executives-linked.html
Learn more: https://thehackernews.com/2024/09/us-treasury-sanctions-executives-linked.html
π8π€5π₯3π±1
Connecting your orgβs Google Drive to #ChatGPT grants broad permissions across shared drives, posing cybersecurity risks.
Learn how to track ChatGPT activity in Google Workspace and how Nudge Security can enhance visibility into genAI integrations.
Read: https://thehackernews.com/2024/09/how-to-investigate-chatgpt-activity-in.html
Learn how to track ChatGPT activity in Google Workspace and how Nudge Security can enhance visibility into genAI integrations.
Read: https://thehackernews.com/2024/09/how-to-investigate-chatgpt-activity-in.html
β‘15π5π€3π±1
π Google Chrome will switch from KYBER to ML-KEM for quantum-safe encryption in November 2024. As quantum computing becomes more feasible, the encryption landscape is shifting.
Also read about EUCLEAK vulnerability impacts YubiKey devices: https://thehackernews.com/2024/09/google-chrome-switches-to-ml-kem-for.html
Also read about EUCLEAK vulnerability impacts YubiKey devices: https://thehackernews.com/2024/09/google-chrome-switches-to-ml-kem-for.html
π21π€6π₯5π4β‘3π±2
β οΈ Critical VMware vCenter vulnerability (CVE-2024-38812) may allow remote code execution. Cybercriminals can exploit it with crafted packets, posing serious risks.
Learn more: https://thehackernews.com/2024/09/patch-issued-for-critical-vmware.html
Make sure youβre not the next victimβpatch your systems today.
Learn more: https://thehackernews.com/2024/09/patch-issued-for-critical-vmware.html
Make sure youβre not the next victimβpatch your systems today.
π16β‘5π±4π3
GSMA is bringing end-to-end encryption (E2EE) to the RCS protocol, ensuring secure messaging between Android and iOS users.
Read: https://thehackernews.com/2024/09/gsma-plans-end-to-end-encryption-for.html
Read: https://thehackernews.com/2024/09/gsma-plans-end-to-end-encryption-for.html
π22π6β‘4π€3
Google Chrome's latest update enhances user privacy and security with improved Safety Check, one-time permissions, and easier notification management.
Learn more: https://thehackernews.com/2024/09/chrome-introduces-one-time-permissions.html
Learn more: https://thehackernews.com/2024/09/chrome-introduces-one-time-permissions.html
π±12π7π€4π3
North Korean cyber-espionage group UNC2970 is now targeting aerospace and energy sectors using job-themed phishing lures to deliver a new backdoor, MISTPEN.
Learn more about the techniques: https://thehackernews.com/2024/09/north-korean-hackers-target-energy-and.html
Learn more about the techniques: https://thehackernews.com/2024/09/north-korean-hackers-target-energy-and.html
π₯12π9π€3β‘1π1
Pentesting is now automatedβmore affordable and efficient than traditional methods. Daily security checks at a fraction of the cost make strong cybersecurity accessible to all.
Is your org ready for automated PT?
Read: https://thehackernews.com/2024/09/why-pay-pentester.html
Is your org ready for automated PT?
Read: https://thehackernews.com/2024/09/why-pay-pentester.html
π€19π10π€―4π1
A Chinese engineer has been indicted for spear-phishing NASA and major universities in a multi-year cyberattack targeting aerospace software.
Read: https://thehackernews.com/2024/09/chinese-engineer-charged-in-us-for.html
Read: https://thehackernews.com/2024/09/chinese-engineer-charged-in-us-for.html
π€11π₯7π5β‘1π1
π Researchers have uncovered "Raptor Train," a botnet of over 200,000 compromised IoT devices, powered by a Chinese nation-state actor, Flax Typhoon.
Learn more: https://thehackernews.com/2024/09/new-raptor-train-iot-botnet-compromises.html
Learn more: https://thehackernews.com/2024/09/new-raptor-train-iot-botnet-compromises.html
π12π8π5β‘1
β οΈ GitLab has released urgent patches for a critical CVSS 10.0 #vulnerability in both CE and EE versions, targeting a flaw in the ruby-saml library that could enable an authentication bypass.
Read details here & act fast: https://thehackernews.com/2024/09/gitlab-patches-critical-saml.html
Read details here & act fast: https://thehackernews.com/2024/09/gitlab-patches-critical-saml.html
π15π±7π6π4β‘1
Microsoft warns of a new ransomware strain, INC, being used by financially motivated threat actor "Vanilla Tempest" to attack the U.S. healthcare sector.
Learn more: https://thehackernews.com/2024/09/microsoft-warns-of-new-inc-ransomware.html
If youβre working in cybersecurity, particularly in healthcare, stay informed.
Learn more: https://thehackernews.com/2024/09/microsoft-warns-of-new-inc-ransomware.html
If youβre working in cybersecurity, particularly in healthcare, stay informed.
π13π9β‘5π₯5
π¨ Cryptojacking Alert: TeamTNT is back, targeting CentOS-based VPS servers!
Their cryptojacking attacks steal resources, disable security features (SELinux, AppArmor), delete logs, and hide via the Diamorphine rootkit.
Details: https://thehackernews.com/2024/09/new-teamtnt-cryptojacking-campaign.html
Secure your systems now
Their cryptojacking attacks steal resources, disable security features (SELinux, AppArmor), delete logs, and hide via the Diamorphine rootkit.
Details: https://thehackernews.com/2024/09/new-teamtnt-cryptojacking-campaign.html
Secure your systems now
π₯13π6β‘1
Explore the growing threat of cyberattacks on healthcare, where poor cybersecurity hygiene risks patient safety.
Learn how ransomware halts critical care and strategies to improve healthcare cybersecurity and prevent breaches.
Read: https://thehackernews.com/2024/09/healthcares-diagnosis-is-critical-cure.html
Learn how ransomware halts critical care and strategies to improve healthcare cybersecurity and prevent breaches.
Read: https://thehackernews.com/2024/09/healthcares-diagnosis-is-critical-cure.html
π11π₯6β‘1
β οΈ SambaSpy, a new multifunctional RAT, targets Italian users in a phishing campaign by suspected Brazilian attackers.
This malware can control everything from file systems to webcams, making it a powerful tool for cybercriminals.
Details: https://thehackernews.com/2024/09/new-brazilian-linked-sambaspy-malware.html
This malware can control everything from file systems to webcams, making it a powerful tool for cybercriminals.
Details: https://thehackernews.com/2024/09/new-brazilian-linked-sambaspy-malware.html
π26π€―2β‘1