CISA warns of multiple vulnerabilities in Airspan Networks' Mimosa equipment that could be abused to execute remote code, trigger a DoS attack, and obtain sensitive information.
Read details: https://thehackernews.com/2022/02/cisa-warns-of-critical-vulnerabilities.html
Read details: https://thehackernews.com/2022/02/cisa-warns-of-critical-vulnerabilities.html
The United States has indicted 6 India-based call centers and their directors for allegedly being involved in placing tens of millions of fraudulent calls that defrauded thousands of American consumers.
Read: https://thehackernews.com/2022/02/us-authorities-charge-6-indian-call.html
Read: https://thehackernews.com/2022/02/us-authorities-charge-6-indian-call.html
⚡After NSO, another Israeli company, 'QuaDream,' has been caught weaponizing iPhone bugs to deploy a spyware called 'Reign,' similar to Pegasus, on targeted devices.
Read details: https://thehackernews.com/2022/02/another-israeli-firm-quadream-caught.html
Read details: https://thehackernews.com/2022/02/another-israeli-firm-quadream-caught.html
Microsoft shared more details about the tactics and techniques used by the Russian hacking group Gamaredon in cyberespionage attacks on various facilities in Ukraine over the past six months.
Details: https://thehackernews.com/2022/02/microsoft-uncovers-new-details-of.html
Details: https://thehackernews.com/2022/02/microsoft-uncovers-new-details-of.html
A new vulnerability (CVE-2022-24348) has been discovered in Argo CD, which is used by thousands of organizations globally, could let hackers steal sensitive information such as secrets, passwords, and API keys from Kubernetes apps.
Details: https://thehackernews.com/2022/02/new-argo-cd-bug-could-let-hackers-steal.html
Details: https://thehackernews.com/2022/02/new-argo-cd-bug-could-let-hackers-steal.html
CISA, the U.S. cybersecurity agency, has ordered all federal agencies to immediately and mandatorily secure their systems against an actively exploited vulnerability (CVE-2022-21882) in Microsoft Windows operating systems.
Details: https://thehackernews.com/2022/02/cisa-orders-federal-agencies-to-patch.html
Details: https://thehackernews.com/2022/02/cisa-orders-federal-agencies-to-patch.html
Chinese state-backed Antlion APT hacker group is targeting financial institutions in Taiwan with a new stealth malware backdoor that allowed it to stay under the radar for at least 18 months.
Read details: https://thehackernews.com/2022/02/chinese-hackers-target-taiwanese.html
Read details: https://thehackernews.com/2022/02/chinese-hackers-target-taiwanese.html
Systems hosting content pertaining to the National Games of China were hacked just a few days before the competition began.
Read details: https://thehackernews.com/2022/02/hackers-backdoored-systems-at-chinas.html
Read details: https://thehackernews.com/2022/02/hackers-backdoored-systems-at-chinas.html
Earth Karkaddan hacker group has been targeting the Indian government and military with a new Android malware called "CapraRAT'' to steal information.
Details: https://thehackernews.com/2022/02/new-caprarat-android-malware-targets.html
Details: https://thehackernews.com/2022/02/new-caprarat-android-malware-targets.html
Microsoft has temporarily disabled the MSIX ms-appinstaller protocol handler in Windows following evidence that a vulnerability in the component was exploited to deliver malware such as Emotet, TrickBot, and Bazaloader.
Details: https://thehackernews.com/2022/02/microsoft-temporarily-disables-msix-app.html
Details: https://thehackernews.com/2022/02/microsoft-temporarily-disables-msix-app.html
Microsoft finally disables Internet-based VBA macros by default in Office applications to prevent phishing and malware attacks.
Read details: https://thehackernews.com/2022/02/microsoft-disables-internet-macros-in.html
Read details: https://thehackernews.com/2022/02/microsoft-disables-internet-macros-in.html
FluBot and Medusa, two separate Android banking trojans, join forces to use the same distribution network to launch simultaneous attacks.
Read details: https://thehackernews.com/2022/02/medusa-android-banking-trojan-spreading.html
Read details: https://thehackernews.com/2022/02/medusa-android-banking-trojan-spreading.html
Hackers behind the 'Roaming Mantis' malware for Android are now using smishing techniques to target European users.
Read: https://thehackernews.com/2022/02/roaming-mantis-android-malware.html
Read: https://thehackernews.com/2022/02/roaming-mantis-android-malware.html
Researchers warn that PrivateLoader pay-per-install service is used by a number of malware families, such as SmokeLoader, RedLine Stealer, Vidar, Raccoon, and GCleaner, to expand their victim list.
Read details: https://thehackernews.com/2022/02/several-malware-families-using-pay-per.html
Read details: https://thehackernews.com/2022/02/several-malware-families-using-pay-per.html
Hackers allied with Palestine are now using a new implant called "NimbleMamba" to attack Middle East governments, foreign policy think tanks, and a state-affiliated airline.
Read details: https://thehackernews.com/2022/02/palestinian-hackers-using-new.html
Read details: https://thehackernews.com/2022/02/palestinian-hackers-using-new.html
⚡February 2022 Patch Tuesday
Microsoft, Adobe, Android, Mozilla, Intel, SAP, Citrix and other major software companies release security updates to patch dozens of security vulnerabilities in their products.
Details — https://thehackernews.com/2022/02/microsoft-and-other-major-software.html
Microsoft, Adobe, Android, Mozilla, Intel, SAP, Citrix and other major software companies release security updates to patch dozens of security vulnerabilities in their products.
Details — https://thehackernews.com/2022/02/microsoft-and-other-major-software.html
ESET's latest threat report shows Russian cyber espionage hacking groups are using COVID -19 lures to attack European diplomats.
Read: https://thehackernews.com/2022/02/russian-apt-hackers-used-covid-19-lures.html
Read: https://thehackernews.com/2022/02/russian-apt-hackers-used-covid-19-lures.html
A new Marlin backdoor was used by Iranian hackers in the "Out to Sea" cyberespionage campaigns.
https://thehackernews.com/2022/02/iranian-hackers-using-new-marlin.html
https://thehackernews.com/2022/02/iranian-hackers-using-new-marlin.html
United States seizes $3.6 BILLION in cryptocurrency stolen during the 2016 Bitfinex hack and arrests a couple for conspiring to launder $4.5 billion worth of cryptocurrency.
Read: https://thehackernews.com/2022/02/us-arrests-two-and-seizes-36-million-in.html
Read: https://thehackernews.com/2022/02/us-arrests-two-and-seizes-36-million-in.html
WordPress plugin "PHP Everywhere" contains multiple critical RCE vulnerabilities, affecting more than 30,000 websites worldwide.
Read details: https://thehackernews.com/2022/02/critical-rce-flaws-in-php-everywhere.html
Read details: https://thehackernews.com/2022/02/critical-rce-flaws-in-php-everywhere.html