New malware alert!
REF2924, a threat group targeting entities in South and Southeast Asia, has been spotted deploying NAPLISTENER - an HTTP listener designed to evade network-based detection.
Learn more: https://thehackernews.com/2023/03/new-naplistener-malware-used-by-ref2924.html
REF2924, a threat group targeting entities in South and Southeast Asia, has been spotted deploying NAPLISTENER - an HTTP listener designed to evade network-based detection.
Learn more: https://thehackernews.com/2023/03/new-naplistener-malware-used-by-ref2924.html
🤯22👍14😁4🔥2⚡1
🚨 NuGet Repository under attack! New malicious campaign aims to infect DotNET developer systems with cryptocurrency stealer malware.
Learn more: https://thehackernews.com/2023/03/rogue-nuget-packages-infect-net.html
Beware of 13 rogue packages downloaded 160k+ times in the past month.
Learn more: https://thehackernews.com/2023/03/rogue-nuget-packages-infect-net.html
Beware of 13 rogue packages downloaded 160k+ times in the past month.
👍24😁8🤯7👏4🔥2⚡1
⚠️ CISA warns of critical flaws in Industrial Control Systems from Keysight, Delta Electronics, Siemens, VISAM, Rockwell Automation, and Hitachi Energy.
Learn more: https://thehackernews.com/2023/03/cisa-alerts-on-critical-security.html
Update your software ASAP to avoid potential security breaches!
Learn more: https://thehackernews.com/2023/03/cisa-alerts-on-critical-security.html
Update your software ASAP to avoid potential security breaches!
👍34🤯12🔥7👏5😁2
💻 Chinese state-sponsored 🕵️♂️ threat actors infiltrate Microsoft Exchange servers in new wave of cyber attacks on Middle East telecoms.
Learn more: https://thehackernews.com/2023/03/operation-soft-cell-chinese-hackers.html
Researchers find a custom variant of Mimikatz, called mim221, with new anti-detection features.
Learn more: https://thehackernews.com/2023/03/operation-soft-cell-chinese-hackers.html
Researchers find a custom variant of Mimikatz, called mim221, with new anti-detection features.
👍15⚡4😁3🤯3👏1
🚨 German and South Korean intel agencies warn of Kimsuky cyberattacks targeting Gmail inboxes via malicious browser extensions.
The group has also extended its attacks to Android malware strains such as FastFire, FastSpy, and RambleOn.
Read: https://thehackernews.com/2023/03/german-and-south-korean-agencies-warn.html
The group has also extended its attacks to Android malware strains such as FastFire, FastSpy, and RambleOn.
Read: https://thehackernews.com/2023/03/german-and-south-korean-agencies-warn.html
🔥19👍14😱5⚡2😁1
🔥 Heads up! New Nexus Android banking trojan is here, targeting 450 financial apps & crypto services.
It can even read 2FA codes from SMS & Google Authenticator by exploiting Android's accessibility services.
Learn more: https://thehackernews.com/2023/03/nexus-new-rising-android-banking-trojan.html
It can even read 2FA codes from SMS & Google Authenticator by exploiting Android's accessibility services.
Learn more: https://thehackernews.com/2023/03/nexus-new-rising-android-banking-trojan.html
👍29🤯22⚡9🔥6🤔4👏1
⚠️Chinese nation-state groups are getting better at bypassing security!
Learn more: https://thehackernews.com/2023/03/researchers-uncover-chinese-nation.html
They are now using TONEINS, TONESHELL, and PUBLOAD malware for more effective infiltration, as well as HIUPAN and ACNSHELL for reverse shell.
Learn more: https://thehackernews.com/2023/03/researchers-uncover-chinese-nation.html
They are now using TONEINS, TONESHELL, and PUBLOAD malware for more effective infiltration, as well as HIUPAN and ACNSHELL for reverse shell.
🤔17👍8🔥6🤯4😱3
Don't let third-party app access put your company's data at risk!
Join our upcoming webinar to learn about the potential dangers and get expert insights on how to keep your SaaS apps secure.
Learn from the experts - register today: https://thn.news/risk-of-3rd-party-saas-apps
Join our upcoming webinar to learn about the potential dangers and get expert insights on how to keep your SaaS apps secure.
Learn from the experts - register today: https://thn.news/risk-of-3rd-party-saas-apps
thehacker.news
Webinar: Inside the High Risk of 3rd-Party SaaS Apps
Don't be a victim of 3rd-Party SaaS App breaches - Learn how to protect your business!
👍29
🐍 Python developers, beware! Malicious package on PyPI uses Unicode to evade detection and deploy info-stealing malware!
📢 Learn more: https://thehackernews.com/2023/03/malicious-python-package-uses-unicode.html
📢 Learn more: https://thehackernews.com/2023/03/malicious-python-package-uses-unicode.html
👍20👏11🔥9⚡7
GitHub replaces RSA SSH host key after brief exposure in public repository to prevent any bad actor from impersonating the service or eavesdropping on users' operations over SSH.
Learn more: https://thehackernews.com/2023/03/github-swiftly-replaces-exposed-rsa-ssh.html
Learn more: https://thehackernews.com/2023/03/github-swiftly-replaces-exposed-rsa-ssh.html
🤯33👍21🤔16⚡6
OpenAI discloses a Redis bug causing certain ChatGPT users' personal info and chat titles to be exposed.
Learn more: https://thehackernews.com/2023/03/openai-reveals-redis-bug-behind-chatgpt.html
Learn more: https://thehackernews.com/2023/03/openai-reveals-redis-bug-behind-chatgpt.html
😱58😁30👍16🔥15👏15🤯1
Conor Brian Fitzpatrick, the 20-year-old founder and admin of the now-defunct BreachForums, has been charged in the U.S. with conspiracy to commit access device fraud. If found guilty, he faces up to five years in prison.
Read: https://thehackernews.com/2023/03/20-year-old-breachforums-founder-faces.html
Read: https://thehackernews.com/2023/03/20-year-old-breachforums-founder-faces.html
🤯21👍12⚡4👏3
🚨 Microsoft releases out-of-band update for privacy-defeating flaw in Windows 10 & 11 screenshot editing tools!
Learn more: https://thehackernews.com/2023/03/microsoft-issues-patch-for-acropalypse.html
🔒 Dubbed "aCropalypse," the #vulnerability allows malicious actors to recover edited parts of screenshots.
Learn more: https://thehackernews.com/2023/03/microsoft-issues-patch-for-acropalypse.html
🔒 Dubbed "aCropalypse," the #vulnerability allows malicious actors to recover edited parts of screenshots.
🔥18👍12⚡3😱3
⚠️ MacOS Alert! MacStealer targeting Apple devices running macOS Catalina & later, M1/M2 CPUs.
The malware Telegram for C&C, stealing documents, browser cookies, iCloud keychain, passwords & credit card info.
Learn more: https://thehackernews.com/2023/03/new-macstealer-macos-malware-steals.html
The malware Telegram for C&C, stealing documents, browser cookies, iCloud keychain, passwords & credit card info.
Learn more: https://thehackernews.com/2023/03/new-macstealer-macos-malware-steals.html
😁24👍15🤔9🤯7😱7🔥4
Heads up, iPhone and iPad users! Apple has backported fixes for an actively exploited vulnerability (CVE-2023-23529) to older models.
Details: https://thehackernews.com/2023/03/apple-issues-urgent-security-update-for.html
Make sure to update to iOS 15.7.4 and iPadOS 15.7.4 ASAP to stay protected.
Details: https://thehackernews.com/2023/03/apple-issues-urgent-security-update-for.html
Make sure to update to iOS 15.7.4 and iPadOS 15.7.4 ASAP to stay protected.
👍36🤔8😱8⚡7🔥5😁4
U.S. President Joe Biden signs an executive order restricting the use of commercial spyware by federal government agencies, citing security and counterintelligence risks.
Learn more: https://thehackernews.com/2023/03/president-biden-signs-executive-order.html
Learn more: https://thehackernews.com/2023/03/president-biden-signs-executive-order.html
🤔31👍19😁15👏7⚡3
🚨 New phishing campaign targets European entities using Remcos RAT & Formbook via DBatLoader malware!
Read: https://thehackernews.com/2023/03/stealthy-dbatloader-malware-loader.html
DBatLoader exploits multi-layered obfuscated HTML & OneNote attachments, and leverages image steganography to evade detection engines.
Read: https://thehackernews.com/2023/03/stealthy-dbatloader-malware-loader.html
DBatLoader exploits multi-layered obfuscated HTML & OneNote attachments, and leverages image steganography to evade detection engines.
😁17👏8⚡3👍3🔥2😱2
New IcedID Lite and Forked malware variants discovered!
Threat actors pivot away from banking fraud functionality to focus on payload delivery, including #ransomware.
Learn more: https://thehackernews.com/2023/03/icedid-malware-shifts-focus-from.html
Threat actors pivot away from banking fraud functionality to focus on payload delivery, including #ransomware.
Learn more: https://thehackernews.com/2023/03/icedid-malware-shifts-focus-from.html
⚡10👍6🤯3🔥1😁1
APT group SideCopy, known for targeting India & Afghanistan government agencies, has launched a new phishing campaign delivering Action RAT and AuTo Stealer.
Learn more: https://thehackernews.com/2023/03/pakistan-origin-sidecopy-linked-to-new.html
Learn more: https://thehackernews.com/2023/03/pakistan-origin-sidecopy-linked-to-new.html
😱16👍8⚡7🔥5🤯4😁3👏1🤔1
🚀 Microsoft unveils Security Copilot in preview! Powered by OpenAI's GPT-4, it offers end-to-end defense 🔒 at machine speed and scale.
Details here: https://thehackernews.com/2023/03/microsoft-introduces-gpt-4-ai-powered.html
Details here: https://thehackernews.com/2023/03/microsoft-introduces-gpt-4-ai-powered.html
🤯48👍8🔥8🤔8😱8⚡2😁2