Newly discovered critical vulnerabilities in Cisco vManage and HyperFlex HX could allow hackers to remotely execute commands as root on affected devices or even create unauthorized administrators.
Read details: https://thehackernews.com/2021/05/critical-flaws-hit-cisco-sd-wan-vmanage.html
Read details: https://thehackernews.com/2021/05/critical-flaws-hit-cisco-sd-wan-vmanage.html
The Hacker News
Critical Flaws Hit Cisco SD-WAN vManage and HyperFlex Software
Newly discovered critical vulnerabilities in Cisco vManage and HyperFlex HX could allow hackers to execute commands as root on affected devices.
A newly discovered stealth ROOTKIT malware—active since at least 2018—has infiltrated the networks of several high-profile organizations, helping hackers gain control of remote hosts as well as facilitate lateral movement.
Read details: https://thehackernews.com/2021/05/new-stealthy-rootkit-infiltrated.html
Read details: https://thehackernews.com/2021/05/new-stealthy-rootkit-infiltrated.html
The Hacker News
New Stealthy Rootkit Infiltrated Networks of High-Profile Organizations
Hackers target high-profile organizations in Asia and Africa with an evasive Windows rootkit.
TsuNAME — A new critical vulnerability affecting DNS resolvers could let attackers carry out reflection-based DDoS attacks to take down authoritative servers.
Find details here: https://thehackernews.com/2021/05/new-tsuname-flaw-could-let-attackers.html
Find details here: https://thehackernews.com/2021/05/new-tsuname-flaw-could-let-attackers.html
A researcher has disclosed 6 unpatched 0-day vulnerabilities affecting the "RemoteMouse" app for Android (over 1 million installs) & iOS devices that could let remote hackers gain full RCE on connected computers without user interaction.
Read: https://thehackernews.com/2021/05/6-unpatched-flaws-disclosed-in-remote.html
Read: https://thehackernews.com/2021/05/6-unpatched-flaws-disclosed-in-remote.html
The Hacker News
6 Unpatched Flaws Disclosed in Remote Mouse App for Android and iOS
6 Unpatched Flaws Disclosed in Remote Mouse App for Android and iOS | Read latest news headlines on latest news and technical coverage on cybersecurity, infosec and hacking.
Google this week announced 4 major privacy and security that everyone needs to know about:
— Two-factor authentication for all, by default.
— Privacy labels for Google Play apps
— Hardware-Enforced Exploit Protection for Chrome
— Cosign for signing and verifying container images
Read details here: https://thehackernews.com/2021/05/4-major-privacy-and-security-updates.html
— Two-factor authentication for all, by default.
— Privacy labels for Google Play apps
— Hardware-Enforced Exploit Protection for Chrome
— Cosign for signing and verifying container images
Read details here: https://thehackernews.com/2021/05/4-major-privacy-and-security-updates.html
Facebook has decided it won't deactivate WhatsApp accounts that don't agree with its latest controversial privacy policy by May 15, but will instead restrict some key features as a reminder.https://thehackernews.com/2021/05/facebook-will-limit-your-whatsapp.html
The Hacker News
Facebook Will Limit Your WhatsApp Features For Not Accepting Privacy Policy
Facebook Will Limit Your WhatsApp Features For Not Accepting Privacy Policy
⚡ WATCH OUT — U.S. and British authorities have warned of top 12 software security vulnerabilities that Russian intelligence hackers are exploiting in various operations.
Find details here: https://thehackernews.com/2021/05/top-11-security-flaws-russian-spy.html
Find details here: https://thehackernews.com/2021/05/top-11-security-flaws-russian-spy.html
The Hacker News
Top 12 Security Flaws Russian Spy Hackers Are Exploiting in the Wild
In a joint effort, US and UK agencies have listed top 11 security vulnerabilities that Russian intelligence hackers exploit in various operations.
A major ransomware cyberattack forced Colonial Pipeline—the largest fuel pipeline operator in the United States—to shut down its entire network.
Details: https://thehackernews.com/2021/05/ransomware-cyber-attack-forced-largest.html
Details: https://thehackernews.com/2021/05/ransomware-cyber-attack-forced-largest.html
The Hacker News
Ransomware Cyber Attack Forced the Largest U.S. Fuel Pipeline to Shut Down
A major #ransomware #cyberattack forced Colonial Pipeline—the largest fuel pipeline operator in the United States—to shut down its entire network.
Four people have pleaded guilty to helping cyber criminals with bulletproof hosting used to spread malware such as Zeus, SpyEye, Citadel and Blackhole Exploit Kit.
Read: https://thehackernews.com/2021/05/four-plead-guilty-to-aiding-cyber.html
Read: https://thehackernews.com/2021/05/four-plead-guilty-to-aiding-cyber.html
The Hacker News
Four Plead Guilty to Aiding Cyber Criminals with Bulletproof Hosting
Four people plead guilty to helping organized crime criminals with Bulletproof Hosting.
👍1
WARNING — Over 25% of Tor exit relays have been spying on users' dark web activity since an unknown threat actor managed to increase the number of servers and now control over 27% of the total Tor network exit capacity.
Details: https://thehackernews.com/2021/05/over-25-of-tor-exit-relays-are-spying.html
Details: https://thehackernews.com/2021/05/over-25-of-tor-exit-relays-are-spying.html
The Hacker News
Over 25% Of Tor Exit Relays Spied On Users' Dark Web Activities
Researcher Finds That Over 25% of Tor Exit Relays Are Snooping On Users
The United States government has declared emergency in 17 states and D.C. over a cyberattack on a major fuel pipeline company.
Read: https://thehackernews.com/2021/05/us-declares-emergency-in-17-states-over.html
Read: https://thehackernews.com/2021/05/us-declares-emergency-in-17-states-over.html
The Hacker News
U.S. Declares Emergency in 17 States Over Fuel Pipeline Cyber Attack
17 U.S. states have issued an emergency declaration because of a cyber attack on fuel pipelines.
Experts warn of TeaBot, a new Android banking Trojan that hijacks users' credentials and SMS messages to enable fraudulent activity against users of more than 60 banks in Spain, Germany, Italy, Belgium and the Netherlands.
Read: https://thehackernews.com/2021/05/experts-warn-of-new-android-banking.html
Read: https://thehackernews.com/2021/05/experts-warn-of-new-android-banking.html
The Hacker News
Experts warn of a new Android banking trojan stealing users' credentials
Cybersecurity researchers on Monday disclosed a new Android trojan that hijacks users' credentials, SMS messages to facilitate fraudulent activities.
US intelligence agencies are warning of weaknesses in the 5G network—such as inadequate deployments and supply chain threats—that cybercriminals and nation-state adversaries can exploit to gain valuable intelligence.
Read: https://thehackernews.com/2021/05/us-intelligence-agencies-warn-about-5g.html
Read: https://thehackernews.com/2021/05/us-intelligence-agencies-warn-about-5g.html
The Hacker News
U.S. Intelligence Agencies Warn About 5G Network Weaknesses
U.S Intelligence Agencies Warn About 5G Network Weaknesses
Alert: Hackers Exploit Adobe Reader 0-Day Vulnerability in the Wild
Read: https://thehackernews.com/2021/05/alert-hackers-exploit-adobe-reader-0.html
Also receiving critical patches today are Adobe Experience Manager, InDesign, Illustrator, Magento, Creative Cloud, Media Encoder, After Effects, and Animate.
Read: https://thehackernews.com/2021/05/alert-hackers-exploit-adobe-reader-0.html
Also receiving critical patches today are Adobe Experience Manager, InDesign, Illustrator, Magento, Creative Cloud, Media Encoder, After Effects, and Animate.
The Hacker News
Alert: Hackers Exploit Adobe Reader 0-Day Vulnerability in the Wild
Hackers are exploiting Adobe Reader's zero-day vulnerability in the wild.
BABUK ransomware hacker gang leaked data from the Metropolitan Police Department after talks failed over $4 million ransom demand.
Read details: https://thehackernews.com/2021/05/ransomware-gang-leaks-metropolitan.html
Read details: https://thehackernews.com/2021/05/ransomware-gang-leaks-metropolitan.html
Patch Tuesday (May 2021)
Microsoft has released the latest Windows updates to patch a dozen newly discovered vulnerabilities, one of the most critical of which is a wormable RCE (CVE-2021-31166) in the HTTP protocol stack.
Read details - https://thehackernews.com/2021/05/latest-microsoft-windows-updates-patch.html
Microsoft has released the latest Windows updates to patch a dozen newly discovered vulnerabilities, one of the most critical of which is a wormable RCE (CVE-2021-31166) in the HTTP protocol stack.
Read details - https://thehackernews.com/2021/05/latest-microsoft-windows-updates-patch.html
🔥 Attention! A set of new vulnerabilities—dubbed FragAttacks—affects nearly all Wi-Fi devices shipped in the past 24 years.
https://thehackernews.com/2021/05/nearly-all-wifi-devices-are-vulnerable.html
These flaws could let hackers forge encrypted frames in various ways, enabling code execution and exfiltration of sensitive data.
https://thehackernews.com/2021/05/nearly-all-wifi-devices-are-vulnerable.html
These flaws could let hackers forge encrypted frames in various ways, enabling code execution and exfiltration of sensitive data.
The dark web is getting loaded with bogus COVID19 test results, fraudulent vaccination cards and questionable vaccines.
Read: https://thehackernews.com/2021/05/dark-web-getting-loaded-with-bogus.html
Read: https://thehackernews.com/2021/05/dark-web-getting-loaded-with-bogus.html
Source code of cybersecurity company Rapid7 was accessed by hackers during a recent supply-chain attack that compromised Codecov, a popular code coverage tool.
Details: https://thehackernews.com/2021/05/rapid7-source-code-breached-in-codecov.html
Details: https://thehackernews.com/2021/05/rapid7-source-code-breached-in-codecov.html
The Hacker News
Rapid7 Source Code Breached in Codecov Supply-Chain Attack
Cybersecurity company Rapid7 Source Code Breached in Codecov Supply-Chain Attack
Colonial Pipeline paid hackers $5 million to regain control of its data and network after a devastating cyberattack forced the company to shut down fuel pipeline operations for six days.
Read: https://thehackernews.com/2021/05/colonial-pipeline-paid-nearly-5-million.html
Read: https://thehackernews.com/2021/05/colonial-pipeline-paid-nearly-5-million.html