Microsoft warns of a large-scale AiTM phishing attack campaign targeting over 10,000 organizations around the world that hijacks Office 365's authentication process even for accounts with multi-factor authentication (MFA).
Read: https://thehackernews.com/2022/07/microsoft-warns-of-large-scale-aitm.html
Read: https://thehackernews.com/2022/07/microsoft-warns-of-large-scale-aitm.html
👍1
The U.S. Federal Trade Commission (FTC) warned that it would take action against the illegal use and sharing of highly sensitive data by technology companies and false claims of data anonymization.
Read: https://thehackernews.com/2022/07/us-ftc-vows-to-crack-down-on-illegal.html
Read: https://thehackernews.com/2022/07/us-ftc-vows-to-crack-down-on-illegal.html
👍1
ESET researchers have discovered three new buffer overflow vulnerabilities in the UEFI firmware of several Lenovo Notebook devices, including several ThinkBook models.
Details: https://thehackernews.com/2022/07/new-uefi-firmware-vulnerabilities.html
Details: https://thehackernews.com/2022/07/new-uefi-firmware-vulnerabilities.html
Researchers uncover a new vulnerability in numerous AMD and Intel microprocessors that could bypass current protections and lead to Specter-based attacks with speculative execution.
Details: https://thehackernews.com/2022/07/new-retbleed-speculative-execution.html
Details: https://thehackernews.com/2022/07/new-retbleed-speculative-execution.html
Microsoft has disclosed details of a now-patched vulnerability (CVE-2022-26706) in Apple operating systems — iOS, iPadOS, macOS, tvOS and watchOS — that could allow attackers to escalate privileges and deploy malware.
Read: https://thehackernews.com/2022/07/microsoft-details-app-sandbox-escape.html
Read: https://thehackernews.com/2022/07/microsoft-details-app-sandbox-escape.html
👍1🔥1
Nation-state hacking groups aligned with China, Iran, North Korea, and Turkey have been targeting journalists in a series of campaigns to spy on them.
Read: https://thehackernews.com/2022/07/state-backed-hackers-targeting.html
Read: https://thehackernews.com/2022/07/state-backed-hackers-targeting.html
👍1
Researchers warn of a new malware campaign by Pakistani "Transparent Tribe" hackers targeting students at educational institutions in India.
Read: https://thehackernews.com/2022/07/pakistani-hackers-targeting-indian.html
Read: https://thehackernews.com/2022/07/pakistani-hackers-targeting-indian.html
👍2
A former programmer at CIA has been found guilty of leaking a trove of classified hacking tools and exploits dubbed "Vault 7" to WikiLeaks.
Read: https://thehackernews.com/2022/07/former-cia-engineer-convicted-of.html
Read: https://thehackernews.com/2022/07/former-cia-engineer-convicted-of.html
Mantis botnet was behind the largest HTTPS distributed denial-of-service (DDoS) attack in June 2022, targeting thousands of Cloudflare-powered websites.
Read: https://thehackernews.com/2022/07/mantis-botnet-behind-largest-https-ddos.html
Read: https://thehackernews.com/2022/07/mantis-botnet-behind-largest-https-ddos.html
👍2
North Korea-based hackers have been linked to cyberattacks targeting small and medium-sized businesses with the H0lyGh0st ransomware.
Read: https://thehackernews.com/2022/07/north-korean-hackers-targeting-small.html
Read: https://thehackernews.com/2022/07/north-korean-hackers-targeting-small.html
A team of academic researchers has warned of a novel cache-based side-channel deanonymization attack that could be used to defeat anonymity protections and identify a unique website visitor.
Read: https://thehackernews.com/2022/07/new-cache-side-channel-attack-can-de.html
Read: https://thehackernews.com/2022/07/new-cache-side-channel-attack-can-de.html
👍3
A new vulnerability in "Netwrix Auditor," used by thousands of organizations, could allow attackers to execute arbitrary code on affected devices and compromise Active Directory domains.
Read: https://thehackernews.com/2022/07/new-netwrix-auditor-bug-could-let.html
Read: https://thehackernews.com/2022/07/new-netwrix-auditor-bug-could-let.html
VoIP phones using Digium's software have been targeted to drop a web shell on their servers as part of an attack campaign aimed at exfiltrating data by downloading and executing additional payloads.
Read: https://thehackernews.com/2022/07/hackers-targeting-voip-servers-by.html
Read: https://thehackernews.com/2022/07/hackers-targeting-voip-servers-by.html
👍3
Juniper Networks has released security patches to address several vulnerabilities in Junos OS, Contrail Networking and other products, some of which can be exploited to take control of affected systems.
Read: https://thehackernews.com/2022/07/juniper-releases-patches-for-critical.html
Read: https://thehackernews.com/2022/07/juniper-releases-patches-for-critical.html
👍1
Google has removed the Android app permissions list from the Play Store and instead created a new "Data Safety" section where developers can tell users themselves how their data will be used.
https://thehackernews.com/2022/07/google-removes-app-permissions-list.html
https://thehackernews.com/2022/07/google-removes-app-permissions-list.html
👍4
Hackers distributing malicious "password cracking software" for Programmable Logic Controllers (PLCs) and Human-Machine Interfaces (HMIs) to trick operators and industrial engineers into installing Sality malware on critical systems.
Read: https://thehackernews.com/2022/07/hackers-distributing-password-cracking.html
Read: https://thehackernews.com/2022/07/hackers-distributing-password-cracking.html
👍1
Researchers have raised the alarm about a "sudden" spike in cyberattacks attempting to exploit an unpatched vulnerability in one of the WordPress Page Builder plugin.
Read details: https://thehackernews.com/2022/07/experts-notice-sudden-surge-in.html
Read details: https://thehackernews.com/2022/07/experts-notice-sudden-surge-in.html
👍1
Pegasus spyware was used to hack into the devices of dozens of pro-democracy activists in Thailand as part of an extensive espionage operation.
Read details: https://thehackernews.com/2022/07/pegasus-spyware-used-to-hack-devices-of.html
Read details: https://thehackernews.com/2022/07/pegasus-spyware-used-to-hack-devices-of.html
🤔1
FirmwareBleed — A new study has highlighted an " industry failure" to adopting mitigations for "Speculative Execution" attacks released by AMD and Intel, posing a firmware supply chain threat.
Read details: https://thehackernews.com/2022/07/new-study-finds-most-enterprise-vendors.html
Read details: https://thehackernews.com/2022/07/new-study-finds-most-enterprise-vendors.html
👍1👏1
FBI has warned of cyber criminals spreading rogue cryptocurrency apps to defraud investors in the virtual asset space.
It is estimated that the illicit scheme netted 244 victims and caused $42.7 million in losses.
Read: https://thehackernews.com/2022/07/fbi-warns-of-fake-cryptocurrency-apps.html
It is estimated that the illicit scheme netted 244 victims and caused $42.7 million in losses.
Read: https://thehackernews.com/2022/07/fbi-warns-of-fake-cryptocurrency-apps.html
👍1🔥1