Microsoft has issued a warning about the Zerobot Go-based botnet malware, which is constantly evolving and has recently gained some new exploits and capabilities to attack IoT devices and web applications.
Read: https://thehackernews.com/2022/12/zerobot-botnet-emerges-as-growing.html
Read: https://thehackernews.com/2022/12/zerobot-botnet-emerges-as-growing.html
👍17😱9🔥4🤔4
Researchers have identified two security vulnerabilities in the Ghost blogging platform, one of which allows hackers to gain higher privileges by sending malicious HTTP requests.
Read: https://thehackernews.com/2022/12/two-new-security-flaws-reported-in.html
Read: https://thehackernews.com/2022/12/two-new-security-flaws-reported-in.html
🤯20👍9🤔5🔥4⚡1
⚡ A new detailed analysis of FIN7 cybercrime syndicate has revealed its organizational hierarchy and role as a partner in various ransomware attacks, including DarkSide, REvil, and LockBit.
Read details: https://thehackernews.com/2022/12/fin7-cybercrime-syndicate-emerges-as.html
Read details: https://thehackernews.com/2022/12/fin7-cybercrime-syndicate-emerges-as.html
🔥20👍11⚡6👏3😁3
The August 2022 security breach at popular password management service LastPass was worse than originally reported, with hackers obtained a trove of personal data, including encrypted password vaults.
Read: https://thehackernews.com/2022/12/lastpass-admits-to-severe-data-breach.html
Read: https://thehackernews.com/2022/12/lastpass-admits-to-severe-data-breach.html
😁29🤯13👍7🔥7😱7👏4🤔4⚡2
French privacy watchdog fines Microsoft Ireland €60 million for placing advertising cookies on users' computers without explicit consent.
Read: https://thehackernews.com/2022/12/france-fines-microsoft-60-million-for.html
Read: https://thehackernews.com/2022/12/france-fines-microsoft-60-million-for.html
😁32👍16👏16⚡3🔥1😱1
Vice Society ransomware group has switched to a new custom payload called 'PolyVice" that uses robust encryption with NTRUEncrypt and ChaCha20-Poly1305.
Read: https://thehackernews.com/2022/12/vice-society-ransomware-attackers-adopt.html
Read: https://thehackernews.com/2022/12/vice-society-ransomware-attackers-adopt.html
😱18👍13🔥7😁1
Researchers have uncovered a new phishing campaign targeting the Kavach two-factor authentication solution used by Indian government officials.
Read details: https://thehackernews.com/2022/12/researchers-warn-of-kavach-2fa-phishing.html
Read details: https://thehackernews.com/2022/12/researchers-warn-of-kavach-2fa-phishing.html
😁9👍8🤔8👏6🤯3🔥2
FrodoPIR — A new privacy-focused system that allows clients to securely query a database without revealing query information to an untrusted server, making it useful for a range of apps, including safe browsing, breached password checks, and more.
https://thehackernews.com/2022/12/frodopir-new-privacy-focused-database.html
https://thehackernews.com/2022/12/frodopir-new-privacy-focused-database.html
👍38🔥10👏8
Cybercriminals are distributing info-stealing malware to developers through Python Package Index (PyPI). These malware variants, such as ANGEL and Celestial Stealer, are based on W4SP Stealer.
Read: https://thehackernews.com/2022/12/w4sp-stealer-discovered-in-multiple.html
Read: https://thehackernews.com/2022/12/w4sp-stealer-discovered-in-multiple.html
🤯34👍25🔥13😱12🤔10😁7⚡4👏2
Alert! PrivateLoader, a pay-per-install malware downloader service, is being used to distribute the information-stealing malware known as RisePro.
Read: https://thehackernews.com/2022/12/privateloader-ppi-service-found.html
Read: https://thehackernews.com/2022/12/privateloader-ppi-service-found.html
👍21🤯10🔥7😱5
GuLoader malware has upped its game, using advanced tactics to bypass security software.
Researchers have uncovered a 3-stage process where VBScript delivers shellcode within itself while performing anti-analysis checks.
Read: https://thehackernews.com/2022/12/guloader-malware-utilizing-new.html
Researchers have uncovered a 3-stage process where VBScript delivers shellcode within itself while performing anti-analysis checks.
Read: https://thehackernews.com/2022/12/guloader-malware-utilizing-new.html
👍25😱11🔥10
Facebook has reached a settlement of $725 million in a lawsuit over the Cambridge Analytica data leak.
Read: https://thehackernews.com/2022/12/facebook-to-pay-725-million-to-settle.html
Read: https://thehackernews.com/2022/12/facebook-to-pay-725-million-to-settle.html
👍49🤯40👏13🤔13😁10⚡8😱7🔥3
Alert! BlueNoroff APT hackers are using new techniques to bypass Windows' Mark of the Web protections, including the use of .ISO and .VHD file formats.
Read: https://thehackernews.com/2022/12/bluenoroff-apt-hackers-using-new-ways.html
Read: https://thehackernews.com/2022/12/bluenoroff-apt-hackers-using-new-ways.html
😱46👍23⚡10🔥9👏5😁4
Hackers are turning to malicious Excel add-in (.XLL) files as their initial attack vector, in response to Microsoft's decision to block VBA macros by default for Office files downloaded from the Internet .
https://thehackernews.com/2022/12/apt-hackers-turn-to-malicious-excel-add.html
https://thehackernews.com/2022/12/apt-hackers-turn-to-malicious-excel-add.html
👍39🤔21🔥12👏7🤯2
BitKeep, a decentralized multi-chain cryptocurrency wallet, has confirmed a cyberattack that led to the distribution of fraudulent versions of its Android app, resulting in the theft of an estimated $9.9 million worth of digital assets.
https://thehackernews.com/2022/12/bitkeep-confirms-cyber-attack-loses.html
https://thehackernews.com/2022/12/bitkeep-confirms-cyber-attack-loses.html
😁30🤯30👍20🔥5
A new malvertising campaign has been discovered that targets people searching for popular #software. This campaign uses Google Ads to spread Trojanized variants that deploy malware, including Raccoon Stealer and Vidar.
Read: https://thehackernews.com/2022/12/new-malvertising-campaign-via-google.html
Read: https://thehackernews.com/2022/12/new-malvertising-campaign-via-google.html
👍33😁8⚡3
Thousands of Citrix ADC and Gateway endpoints have not yet been patched for two critical vulnerabilities (CVE-2022-27510 and CVE-2022-27518), leaving several organisations vulnerable to potential cyberattacks.
https://thehackernews.com/2022/12/thousands-of-citrix-servers-still.html
https://thehackernews.com/2022/12/thousands-of-citrix-servers-still.html
🤔24👍16🔥13⚡6👏6😱1
CISA has added two-year-old vulnerabilities in TIBCO Software's JasperReports product to its KEV catalog after discovering evidence of active exploitation by cybercriminals.
Read: https://thehackernews.com/2022/12/cisa-warns-of-active-exploitation-of.html
Read: https://thehackernews.com/2022/12/cisa-warns-of-active-exploitation-of.html
👍37🤔11👏7⚡4🔥4
Google has agreed to pay $29.5 million to settle lawsuits brought by Indiana and Washington, D.C. over its "deceptive" location tracking practices.
Read: https://thehackernews.com/2023/01/google-to-pay-295-million-to-settle.html
Read: https://thehackernews.com/2023/01/google-to-pay-295-million-to-settle.html
🔥26👍20👏11😱10😁5🤯5⚡4
A new strain of Linux malware is targeting WordPress sites, taking advantage of vulnerabilities in various plugins and themes to infiltrate and compromise vulnerable systems.
Read: https://thehackernews.com/2023/01/wordpress-security-alert-new-linux.html
Read: https://thehackernews.com/2023/01/wordpress-security-alert-new-linux.html
🤯32🔥18👍9😁9👏7⚡4😱1