Researchers have traced the LAPSUS$ cyberattacks to a 16-year-old hacker in England.
Read details: https://thehackernews.com/2022/03/researchers-trace-lapsus-cyber-attacks.html
Read details: https://thehackernews.com/2022/03/researchers-trace-lapsus-cyber-attacks.html
A 23-year-old Russian national has been indicted in the U.S. and added to the FBI's Cyber Most Wanted list for allegedly administering a cybercrime forum that sold stolen login credentials, personal and credit card data.
Read: https://thehackernews.com/2022/03/23-year-old-russian-hacker-wanted-by.html
Read: https://thehackernews.com/2022/03/23-year-old-russian-hacker-wanted-by.html
At least 2 distinct groups of North Korean state- sponsored hackers exploited a ZERO-DAY (CVE-2022-0609) vulnerability in Google Chrome to launch cyberattacks on the fintech, IT, and media industries.
Read details: https://thehackernews.com/2022/03/north-korean-hackers-exploited-chrome.html
Read details: https://thehackernews.com/2022/03/north-korean-hackers-exploited-chrome.html
British police have arrested seven suspected members, aged 16 to 21, of the cyber extortion and hacking gang LAPSUS$, which attacked Okta, Microsoft, and Nvidia.
Read details: https://thehackernews.com/2022/03/7-suspected-members-of-lapsus-hacker.html
Read details: https://thehackernews.com/2022/03/7-suspected-members-of-lapsus-hacker.html
How to Build a Custom Malware Analysis Sandbox
https://thehackernews.com/2022/03/how-to-build-custom-malware-analysis.html
https://thehackernews.com/2022/03/how-to-build-custom-malware-analysis.html
π₯1
Google has rolled out an urgent out-of-band update for the Chrome browser for millions of Windows, macOS, and Linux users to patch a new actively exploited zero-day vulnerability.
Read details: https://thehackernews.com/2022/03/google-issues-urgent-chrome-update-to.html
Read details: https://thehackernews.com/2022/03/google-issues-urgent-chrome-update-to.html
Another Chinese hacker group has entered the fray of the Ukraine conflict and is attacking victims with the HeaderTip backdoor.
Read details: https://thehackernews.com/2022/03/another-chinese-hacking-group-spotted.html
Read details: https://thehackernews.com/2022/03/another-chinese-hacking-group-spotted.html
U.S. Federal Communications Commission (FCC) has added Russian cybersecurity firm Kaspersky Lab and two Chinese telecom firms on its list of national security threats, saying they pose an "unacceptable risk" to the country's national security.
https://thehackernews.com/2022/03/fcc-adds-kaspersky-and-chinese-telecom.html
https://thehackernews.com/2022/03/fcc-adds-kaspersky-and-chinese-telecom.html
Muhstik botnet is targeting Redis servers using a recently disclosed highly critical vulnerability (CVE-2022-0543 / CVSS 10.0) in the database system.
Read details: https://thehackernews.com/2022/03/muhstik-botnet-targeting-redis-servers.html
Read details: https://thehackernews.com/2022/03/muhstik-botnet-targeting-redis-servers.html
"Purple Fox" hackers have been using a new FatalRAT variant in their recent malware distribution campaigns and have also improved evasion mechanisms to bypass security software.
Read details: https://thehackernews.com/2022/03/purple-fox-hackers-spotted-using-new.html
Read details: https://thehackernews.com/2022/03/purple-fox-hackers-spotted-using-new.html
Cybercriminals are exploiting unpatched Microsoft Exchange servers to hijack email reply chains, tricking victims into installing IceID info-stealing malware.
Read details: https://thehackernews.com/2022/03/hackers-hijack-email-reply-chains-on.html
Read details: https://thehackernews.com/2022/03/hackers-hijack-email-reply-chains-on.html
This Mandiant incident report for Okta's Lapsus$ breach details the entire timeline of events.
Read details: https://thehackernews.com/2022/03/new-report-on-okta-hack-reveals-entire.html
Read details: https://thehackernews.com/2022/03/new-report-on-okta-hack-reveals-entire.html
Researchers have uncovered a large-scale supply chain attack which exploited dependency confusion attacks on NPM repository by uploading more than 800 malicious packages.
Read details: https://thehackernews.com/2022/03/a-threat-actor-dubbed-red-lili-has-been.html
Read details: https://thehackernews.com/2022/03/a-threat-actor-dubbed-red-lili-has-been.html
Hackers using a "complex and powerful" malware loader with the goal of installing cryptocurrency miners on compromised systems and potentially enabling the theft of #Discord tokens.
Details: https://thehackernews.com/2022/03/new-malware-loader-verblecon-infects.html
Details: https://thehackernews.com/2022/03/new-malware-loader-verblecon-infects.html
π1
A group of academics has designed a new system called "Privid" that provides privacy-preserving surveillance video analytics to combat concerns about invasive tracking.
Read details: https://thehackernews.com/2022/03/privid-privacy-preserving-surveillance.html
Read details: https://thehackernews.com/2022/03/privid-privacy-preserving-surveillance.html
π1
Researchers have observed a new βTransparent Tribeβ hacking campaign targeting #Indian government and military entities.
Read details: https://thehackernews.com/2022/03/new-hacking-campaign-by-transparent.html
Read details: https://thehackernews.com/2022/03/new-hacking-campaign-by-transparent.html
π1
A potentially critical SonicOS vulnerability affects SonicWall firewall appliances, allowing unauthenticated, remote attackers to execute arbitrary code and cause a denial-of-service (DoS) condition.
Read details: https://thehackernews.com/2022/03/critical-sonicos-vulnerability-affects.html
Read details: https://thehackernews.com/2022/03/critical-sonicos-vulnerability-affects.html
π1
U.S. Cybersecurity Agency (CISA) and the Department of Energy (DoE) have issued a joint warning against attacks on Internet-connected uninterruptible power supply (UPS) devices.
Read details: https://thehackernews.com/2022/03/cisa-warns-of-ongoing-cyber-attacks.html
Read details: https://thehackernews.com/2022/03/cisa-warns-of-ongoing-cyber-attacks.html
β‘ LAPSUS$ gang announced their return on after a week-long "vacation," leaking a large amount of data (70 GB) allegedly from the software company Globant, including the source code for some of its customers.
https://thehackernews.com/2022/03/lapsus-claims-to-have-breached-it-firm.html
https://thehackernews.com/2022/03/lapsus-claims-to-have-breached-it-firm.html
Researchers demonstrate a new vulnerability in remote keyless entry system that could allow thieves to remotely unlock and even start Honda and Acura vehicles.
Read details: https://thehackernews.com/2022/03/hondas-keyless-access-bug-could-let.html
Read details: https://thehackernews.com/2022/03/hondas-keyless-access-bug-could-let.html