Personal data of over 100 million users is exposed by 23 #Android apps on the Google Play Store, potentially making them a lucrative target for malicious actors.
The list of affected apps can be found here: https://thehackernews.com/2021/05/these-23-android-apps-expose-over.html
The list of affected apps can be found here: https://thehackernews.com/2021/05/these-23-android-apps-expose-over.html
The Hacker News
23 Android Apps Expose Over 100,000,000 Users' Personal Data
Android apps leaked sensitive data of more than 100 million users, potentially making them a lucrative target for malicious actors.
Microsoft warns users to be watchful of the threat of STRRAT data-stealing malware, which is being spread through a "massive email campaign" posing as a ransomware infection.
Read details: https://thehackernews.com/2021/05/microsoft-warns-of-data-stealing.html
Read details: https://thehackernews.com/2021/05/microsoft-warns-of-data-stealing.html
The Hacker News
Microsoft Warns of Data Stealing Malware That Pretends to Be Ransomware
Microsoft urges Windows users to be aware of a new threat of data theft malware that pretends to be ransomware.
CNA Financial, one of the largest insurance companies in the US, has reportedly paid hackers $40 MILLION in ransom to regain access to its systems—making it the most expensive ransom payment to date.
Read: https://thehackernews.com/2021/05/insurance-firm-cna-financial-reportedly.html
Read: https://thehackernews.com/2021/05/insurance-firm-cna-financial-reportedly.html
The Hacker News
Insurance Firm CNA Financial Reportedly Paid Hackers $40 Million in Ransom
CNA Financial, one of the largest insurance companies in the US, reportedly paid hackers $40 million in ransom to regain access to its systems.
A massive data breach at India's flag carrier airline — AirIndia — has exposed credit card and passport data of 4.5 million passengers registered between August 2011 and February 2021, a period of nearly 10 years.
Read: https://thehackernews.com/2021/05/indias-flag-carrier-airline-air-india.html
Read: https://thehackernews.com/2021/05/indias-flag-carrier-airline-air-india.html
The Hacker News
Air India Hack Exposes Credit Card and Passport Info of 4.5 Million Passengers
India's flag carrier airline, Air India, suffers data breach affecting 4.5 million of its customers over a period stretching nearly 10 years after.
The FBI has issued a ⚡FLASH ALERT warning of the Conti ransomware that has affected 16 healthcare and emergency services organizations in the United States.
Read details: https://thehackernews.com/2021/05/fbi-warns-conti-ransomware-hit-16-us.html
Read details: https://thehackernews.com/2021/05/fbi-warns-conti-ransomware-hit-16-us.html
The Hacker News
FBI Warns Conti Ransomware Hit 16 U.S. Health and Emergency Services
16 U.S. health and emergency services were hit by Conti ransomware, FBI warns.
👍1
Researchers disclose details on several critical vulnerabilities affecting Nagios IT monitoring software that could let attackers hijack corporate networks.
Read: https://thehackernews.com/2021/05/details-disclosed-on-critical-flaws.html
Read: https://thehackernews.com/2021/05/details-disclosed-on-critical-flaws.html
The Hacker News
Details Disclosed On Critical Flaws Affecting Nagios IT Monitoring Software
Details have been revealed about security vulnerabilities affecting Nagios IT monitoring software
A new study has revealed that state-sponsored hackers linked to North Korea were behind a series of "CryptoCore" cyberattacks on cryptocurrency exchanges over the past 3 years.
Read: https://thehackernews.com/2021/05/researchers-link-cryptocore-attacks-on.html
Read: https://thehackernews.com/2021/05/researchers-link-cryptocore-attacks-on.html
The Hacker News
Researchers Link CryptoCore Attacks On Cryptocurrency Exchanges to North Korea
State-sponsored hackers affiliated with North Korea are believed to be behind CryptoCore attacks on cryptocurrency exchanges.
Apple has released software updates for iOS, macOS, tvOS, watchOS, and Safari web browser, containing security patches to address multiple vulnerabilities—including EMERGENCY security patches for the ongoing 0-DAY attacks
https://thehackernews.com/2021/05/apple-issues-patches-to-combat-ongoing.html
https://thehackernews.com/2021/05/apple-issues-patches-to-combat-ongoing.html
The Hacker News
Apple Issues Patches to Combat Ongoing 0-Day Attacks on macOS, tvOS
Apple has released security updates for iOS, macOS, tvOS, watchOS, and Safari web browser to fix multiple vulnerabilities.
A newly discovered set of vulnerabilities in Bluetooth Core and Mesh Profile specifications could pose a threat to legitimate devices, allowing attackers to impersonate them and initiate MITM attacks.
Read: https://thehackernews.com/2021/05/new-bluetooth-flaws-let-attackers.html
Read: https://thehackernews.com/2021/05/new-bluetooth-flaws-let-attackers.html
The Hacker News
New Bluetooth Flaws Let Attackers Impersonate Legitimate Devices
Hackers can impersonate legitimate Bluetooth devices with new Bluetooth flaws
A new high-severity buffer overflow vulnerability (CVE-2021-22908) has been reported in Pulse Connect Secure (PCS) that allows a remote, authenticated user with privileges to browse SMB shares to execute arbitrary code as the root user.
Read: https://thehackernews.com/2021/05/new-high-severity-vulnerability.html
Read: https://thehackernews.com/2021/05/new-high-severity-vulnerability.html
The Hacker News
New High-Severity Vulnerability Reported in Pulse Connect Secure VPN
Pulse Connect Secure VPN has been reported to have a new high-severity vulnerability.
Russian-language darkweb marketplace Hydra has emerged as a hotspot for illicit activities, pulling in a whopping $1.37 BILLION worth of cryptocurrencies in 2020.
Read details: https://thehackernews.com/2021/05/russian-hydra-darknet-market-made-over.html
Read details: https://thehackernews.com/2021/05/russian-hydra-darknet-market-made-over.html
The Hacker News
Russian Hydra DarkNet Market Made Over $1.3 Billion in 2020
Over $1.3 Billion was made by Russia's dark-net market Hydra in 2020
A critical flaw — CVE-2021-21985 — has been found in VMware vCenter Server that could let attackers execute arbitrary code on the targeted servers.
https://thehackernews.com/2021/05/critical-rce-vulnerability-found-in.html
Additionally, VMware has released patches for a separate authentication issue affecting vSphere Client.
https://thehackernews.com/2021/05/critical-rce-vulnerability-found-in.html
Additionally, VMware has released patches for a separate authentication issue affecting vSphere Client.
Researchers at #Google have discovered yet another variant of the DRAM Rowhammer attack, called 'Half-Double,' that bypasses all existing defenses to tamper with data stored in memory.
Read details: https://thehackernews.com/2021/05/google-researchers-discover-new-variant.html
Read details: https://thehackernews.com/2021/05/google-researchers-discover-new-variant.html
🔥 WhatsApp has sued the Indian government over new Internet regulations that could force it to break encryption for "traceability,' eventually putting the privacy of billions of users at risk.
Read: https://thehackernews.com/2021/05/whatsapp-sues-indian-government-over.html
Read: https://thehackernews.com/2021/05/whatsapp-sues-indian-government-over.html
Iranian hackers deployed a series of destructive wiper #malware attacks against Israeli targets, disguising the activities as ransomware attacks.
Read: https://thehackernews.com/2021/05/data-wiper-malware-disguised-as.html
Read: https://thehackernews.com/2021/05/data-wiper-malware-disguised-as.html
Researchers have discovered severe security vulnerabilities in Visual Studio Code extensions, demonstrating yet another supply chain attack vector that could enable attackers to compromise local machines as well as build and deployment systems through an integrated development environment (IDE).
https://thehackernews.com/2021/05/newly-discovered-bugs-in-vscode.html
https://thehackernews.com/2021/05/newly-discovered-bugs-in-vscode.html
Hackers are now using fake foundations to trick Uyghurs based in Pakistan and China into downloading #malware as part of espionage activities.
Read details: https://thehackernews.com/2021/05/hackers-using-fake-foundations-to.html
Read details: https://thehackernews.com/2021/05/hackers-using-fake-foundations-to.html
Watch Out!!!
Cybercriminals used malvertising campaigns on #Google search pages to spread trojanized installers of the widely used remote desktop software AnyDesk.
Read details: https://thehackernews.com/2021/05/malvertising-campaign-on-google.html
Cybercriminals used malvertising campaigns on #Google search pages to spread trojanized installers of the widely used remote desktop software AnyDesk.
Read details: https://thehackernews.com/2021/05/malvertising-campaign-on-google.html
The Hacker News
Malvertising Campaign On Google Distributed Trojanized AnyDesk Installer
Trojanized AnyDesk installers were distributed through Google advertisements
Chinese hackers continue to target Pulse Secure VPN devices as part of their #cyberespionage activities, dropping malicious web shells to exfiltrate sensitive information from corporate networks.
https://thehackernews.com/2021/05/chinese-cyber-espionage-hackers.html
https://thehackernews.com/2021/05/chinese-cyber-espionage-hackers.html
Hackers behind SolarWinds supply-chain attack target government agencies, think tanks, consultants, and other organizations in 24 countries with new backdoor malware.
Read details: https://thehackernews.com/2021/05/solarwinds-hackers-target-think-tanks.html
Read details: https://thehackernews.com/2021/05/solarwinds-hackers-target-think-tanks.html
The Hacker News
SolarWinds Hackers Target Think Tanks With New 'NativeZone' Backdoor
Hackers Behind SolarWinds Hack Target Think Tanks With New Backdoor