Two Eastern European nationals have been sentenced in the U.S. for offering "bulletproof #hosting" services to cybercriminals, which hackers used to distribute #malware and attack financial institutions across the country.
Read: https://thehackernews.com/2021/10/two-eastern-europeans-sentenced-for.html
Read: https://thehackernews.com/2021/10/two-eastern-europeans-sentenced-for.html
π1
Watch Out!
Google warns that hackers have been hijacking accounts of high-profile YouTube creators with malware that steals browser cookies for session hijacking, a technique that can effectively circumvent 2-factor authentication.
Details: https://thehackernews.com/2021/10/hackers-stealing-browser-cookies-to.html
Google warns that hackers have been hijacking accounts of high-profile YouTube creators with malware that steals browser cookies for session hijacking, a technique that can effectively circumvent 2-factor authentication.
Details: https://thehackernews.com/2021/10/hackers-stealing-browser-cookies-to.html
U.S. government has announced new regulations banning the sale of hacking software and #surveillance equipment to Russia, China and other authoritarian regimes.
Read details: https://thehackernews.com/2021/10/us-government-bans-sale-of-hacking.html
Read details: https://thehackernews.com/2021/10/us-government-bans-sale-of-hacking.html
A newly discovered vulnerability in that never-ending trial version of the popular WinRAR software could allow attackers to execute arbitrary code on target systems.
Read: https://thehackernews.com/2021/10/bug-in-free-winrar-software-could-let.html
Read: https://thehackernews.com/2021/10/bug-in-free-winrar-software-could-let.html
Researchers have discovered a new rootkit malware that has a valid digital signature issued by Microsoft and is targeting online gamers in China.
Read details: https://thehackernews.com/2021/10/researchers-discover-microsoft-signed.html
Read details: https://thehackernews.com/2021/10/researchers-discover-microsoft-signed.html
Cybercrime gang FIN7 created a fake cybersecurity company called "Bastion Secure" to recruit IT experts and get them to launch ransomware attacks.
Read details: https://thehackernews.com/2021/10/hackers-set-up-fake-company-to-get-it.html
Read details: https://thehackernews.com/2021/10/hackers-set-up-fake-company-to-get-it.html
The hacker group "Lone Wolf" uses political and government-themed malicious domains to target entities in India and Afghanistan with commodity RATs.
Read details: https://thehackernews.com/2021/10/lone-wolf-hacker-group-targeting.html
Read details: https://thehackernews.com/2021/10/lone-wolf-hacker-group-targeting.html
π€―1
A popular JavaScript NPM library with over 6 million weekly downloads has been hijacked to publish crypto-mining malware.
Read details: https://thehackernews.com/2021/10/popular-npm-package-hijacked-to-publish.html
Read details: https://thehackernews.com/2021/10/popular-npm-package-hijacked-to-publish.html
π1
In a multiple-country effort, law enforcement agencies 'reportedly' hacked the infrastructure of REvil ransomware group and forced it offline.
Read details: https://thehackernews.com/2021/10/feds-reportedly-hacked-revil-ransomware.html
Read details: https://thehackernews.com/2021/10/feds-reportedly-hacked-revil-ransomware.html
Microsoft's threat intelligence team has uncovered "a series of large-scale credential phishing campaigns" using a custom phishing kit called "TodayZoo."
Read details: https://thehackernews.com/2021/10/microsoft-warns-of-todayzoo-phishing.html
Read details: https://thehackernews.com/2021/10/microsoft-warns-of-todayzoo-phishing.html
New York Times journalist Ben Hubbard was repeatedly targeted with Israel-based NSO Groups Pegasus spyware over a three-year period after reporting on Saudi Arabia.
Read details: https://thehackernews.com/2021/10/nyt-journalist-repeatedly-hacked-with.html
Read details: https://thehackernews.com/2021/10/nyt-journalist-repeatedly-hacked-with.html
Watch Out! Hackers are actively exploiting a critical vulnerability in multiple versions of a time and billing system called BillQuick to deploy ransomware on vulnerable systems.
Read details: https://thehackernews.com/2021/10/hackers-exploited-popular-billquick.html
Read details: https://thehackernews.com/2021/10/hackers-exploited-popular-billquick.html
Microsoft warns of continued supply-chain attacks by hacker group Nobelium, which has compromised 14 downstream customers of several cloud service providers, managed service providers and other IT service companies.
Read: https://thehackernews.com/2021/10/microsoft-warns-of-continued-supply.html
Read: https://thehackernews.com/2021/10/microsoft-warns-of-continued-supply.html
< Gummy Browsers >
Researchers find a new way that could let attackers collect browserβs fingerprinting information and spoof it without the victimβs awareness.
Read details: https://thehackernews.com/2021/10/new-attack-let-attacker-collect-and.html
Researchers find a new way that could let attackers collect browserβs fingerprinting information and spoof it without the victimβs awareness.
Read details: https://thehackernews.com/2021/10/new-attack-let-attacker-collect-and.html
Mozilla warns that two malicious Firefox add-ons installed by over 455,000 users prevent users from downloading security updates, accessing updated blocklists, and updating remotely configured content.
Read details: https://thehackernews.com/2021/10/malicious-firefox-add-ons-block-browser.html
Read details: https://thehackernews.com/2021/10/malicious-firefox-add-ons-block-browser.html
π1
Over 10 MILLION users have been targeted with 151 malicious Android apps from the Google Play Store that tricked users into paying for premium subscription services without their knowledge or consent.
Details: https://thehackernews.com/2021/10/over-10-million-android-users-targeted.html
Details: https://thehackernews.com/2021/10/over-10-million-android-users-targeted.html
North Korean hacking group Lazarus has been observed waging two separate supply-chain attacks to gain a foothold in corporate networks and attack downstream organizations.
Read details: https://thehackernews.com/2021/10/latest-report-uncovers-supply-chain.html
Read details: https://thehackernews.com/2021/10/latest-report-uncovers-supply-chain.html
A widespread malicious email campaign deploys a new malware loader that gives attackers initial access to corporate networks to spread malicious payloads like Qakbot and Cobalt Strike.
Read: https://thehackernews.com/2021/10/hackers-using-squirrelwaffle-loader-to.html
Read: https://thehackernews.com/2021/10/hackers-using-squirrelwaffle-loader-to.html
Two more malicious libraries distributed via the official NPM repository have been caught stealing credentials, installing remote access trojans, and infecting compromised systems with ransomware.
Read: https://thehackernews.com/2021/10/malicious-npm-libraries-caught.html
Read: https://thehackernews.com/2021/10/malicious-npm-libraries-caught.html
Cybersecurity researchers at ESET have discovered a new unique #malware loader, dubbed Wslink, that runs as a server and executes received modules in memory.
Read details: https://thehackernews.com/2021/10/new-wslink-malware-loader-runs-as.html
Read details: https://thehackernews.com/2021/10/new-wslink-malware-loader-runs-as.html