Zyxel has released a patch to address a critical security vulnerability affecting firewall devices that can allow unauthenticated and remote attackers to gain arbitrary code execution.
Read: https://thehackernews.com/2022/05/zyxel-releases-patch-for-critical.html
Read: https://thehackernews.com/2022/05/zyxel-releases-patch-for-critical.html
Jordan's foreign ministry has been targeted by a spear-phishing campaign dropping a stealthy backdoor dubbed Saitama.
Read: https://thehackernews.com/2022/05/new-saitama-backdoor-targeted-official.html
Read: https://thehackernews.com/2022/05/new-saitama-backdoor-targeted-official.html
Google has announced the creation of a new "Open Source Maintenance Crew" to focus on improving the cybersecurity of critical open source projects.
Read: https://thehackernews.com/2022/05/google-created-open-source-maintenance.html
Read: https://thehackernews.com/2022/05/google-created-open-source-maintenance.html
SonicWall has published an advisory warning of three new vulnerabilities in its Secure Mobile Access (SMA) 1000 appliances, including a high-threat authentication bypass vulnerability.
Read: https://thehackernews.com/2022/05/sonicwall-releases-patches-for-new.html
Read: https://thehackernews.com/2022/05/sonicwall-releases-patches-for-new.html
European Parliament announced a "provisional agreement" on NIS2, a new directive that aims to improve cybersecurity by setting stricter ground rules for critical industries such as energy, financial markets, health, and digital infrastructure.
https://thehackernews.com/2022/05/europe-agrees-to-adopt-new-nis2.html
https://thehackernews.com/2022/05/europe-agrees-to-adopt-new-nis2.html
A 28-year-old Ukrainian national has been sentenced to four years in prison for siphoning thousands of server credentials and selling them on the darkweb to make money.
Read: https://thehackernews.com/2022/05/ukrainian-hacker-jailed-for-4-years-in.html
Read: https://thehackernews.com/2022/05/ukrainian-hacker-jailed-for-4-years-in.html
👍1
Researchers are warning about a new malware toolkit called "Eternity Project" that allows professional and amateur cybercriminals to buy stealers, clippers, worms, miners, #ransomware, and a distributed denial of service (DDoS) bot.
Read: https://thehackernews.com/2022/05/researchers-warn-of-eternity-project.html
Read: https://thehackernews.com/2022/05/researchers-warn-of-eternity-project.html
In a first-of-its-kind study, researchers have demonstrated a novel attack surface that could allows malware to be executed on the iPhone while the phone is "OFF".
Read: https://thehackernews.com/2022/05/researchers-find-way-to-run-malware-on.html
Read: https://thehackernews.com/2022/05/researchers-find-way-to-run-malware-on.html
👍1
More than 200 apps masquerading as fitness, photo editing, and puzzle apps on Google Play Store have been caught infecting users' Android devices with the Facestealer spyware, which steals credentials and valuable cryptocurrency information.
https://thehackernews.com/2022/05/over-200-apps-on-play-store-caught.html
https://thehackernews.com/2022/05/over-200-apps-on-play-store-caught.html
👍1
Russian Conti ransomware gang has threatened to overthrow the newly elected government of Costa Rica with a cyberattack and has increased its ransom demand to $20 million in order to obtain a decryption key to unlock the hacked systems.
Read: https://thehackernews.com/2022/05/russian-conti-ransomware-gang-threatens.html
Read: https://thehackernews.com/2022/05/russian-conti-ransomware-gang-threatens.html
Microsoft warns against "cryware" malware that steals information and exfiltrates data directly from untrusted cryptocurrency wallets.
Read: https://thehackernews.com/2022/05/microsoft-warns-of-cryware-info.html
Read: https://thehackernews.com/2022/05/microsoft-warns-of-cryware-info.html
U.S. State Department, Treasury Department, and FBI warn that highly skilled North Korean software and app developers are posing as "non-DPRK nationals" to work as freelancers or IT consultants enabling the regime's malicious cyberattacks.
Read: https://thehackernews.com/2022/05/us-warns-against-north-korean-hackers.html
Read: https://thehackernews.com/2022/05/us-warns-against-north-korean-hackers.html
Microsoft warns of a new malicious campaign targeting SQL Servers that involves use of a built-in PowerShell utility (sqlps.exe) to achieve fileless persistence on compromised systems.
Read: https://thehackernews.com/2022/05/hackers-gain-fileless-persistence-on.html
Read: https://thehackernews.com/2022/05/hackers-gain-fileless-persistence-on.html
Researchers reveal the inner working of a cybercriminal group known as "Wizard Spider," providing unprecedented visibility into its structure, background, and motivations.
Read details — https://thehackernews.com/2022/05/researchers-expose-inner-working-of.html
Read details — https://thehackernews.com/2022/05/researchers-expose-inner-working-of.html
👍1
VMware has issued patches to address two new vulnerabilities — CVE-2022-22972 and CVE-2022-22973 — affecting Workspace ONE Access, Identity Manager and vRealize Automation, which can be exploited to backdoor enterprise networks.
Read: https://thehackernews.com/2022/05/vmware-releases-patches-for-new.html
Read: https://thehackernews.com/2022/05/vmware-releases-patches-for-new.html
🤯1
Web trackers running in the background of several of the world's most popular websites are intercepting emails and passwords of visitors even before they submit an online form.
Read: https://thehackernews.com/2022/05/web-trackers-caught-intercepting-online.html
Read: https://thehackernews.com/2022/05/web-trackers-caught-intercepting-online.html
Google has patched a high-severity vulnerability in its OAuth library for Java that could be exploited by a malicious actor with a compromised token to trigger arbitrary payloads.
Read: https://thehackernews.com/2022/05/high-severity-bug-reported-in-googles.html
Read: https://thehackernews.com/2022/05/high-severity-bug-reported-in-googles.html
👍1
A novel Bluetooth relay attack could allow attackers to remotely unlock and operate cars, open smart locks in residential buildings, and breach secured areas more easily than ever before.
Read: https://thehackernews.com/2022/05/new-bluetooth-hack-could-let-attackers.html
Read: https://thehackernews.com/2022/05/new-bluetooth-hack-could-let-attackers.html
QNAP urges its users to update their network-attached storage (NAS) devices immediately to prevent a new wave of Deadbolt ransomware attacks.
Read details: https://thehackernews.com/2022/05/qnap-urges-users-to-update-nas-devices.html
Read details: https://thehackernews.com/2022/05/qnap-urges-users-to-update-nas-devices.html
The North Korean-backed Lazarus hacker group has been observed exploiting the Log4Shell vulnerability in VMware Horizon servers to deploy the NukeSped implant ( aka Manuscrypt) against targets in its southern counterpart.
Read: https://thehackernews.com/2022/05/hackers-exploiting-vmware-horizon-to.html
Read: https://thehackernews.com/2022/05/hackers-exploiting-vmware-horizon-to.html