Mastodon, the decentralized social network, releases critical security update. Update your instance ASAP to prevent potential DoS and remote code execution attacks.
Read details: https://thehackernews.com/2023/07/mastodon-social-network-patches.html
Read details: https://thehackernews.com/2023/07/mastodon-social-network-patches.html
π22π€5β‘3π3
π Yet another critical SQL injection vulnerability (CVE-2023-36934) uncovered in popular MOVEit Transferβthe same software that was exploited in a series of recent cyberattacks to deploy Clop #ransomware.
Read details: https://thehackernews.com/2023/07/another-critical-unauthenticated-sqli.html
Read details: https://thehackernews.com/2023/07/another-critical-unauthenticated-sqli.html
π19π€4π3
π‘οΈ Struggling with limited visibility into cyber threats? Discover how "Continuous Threat Exposure Management" empowers CISOs and SOC teams to proactively protect their assets, data, and systems.
Read details: https://thehackernews.com/2023/07/close-security-gaps-with-continuous.html
Read details: https://thehackernews.com/2023/07/close-security-gaps-with-continuous.html
π14π€3
Beware! Voice phishing has taken an advanced twist with "Letscall."
This multi-step vishing attack combines hi-tech malware, voice traffic routing, and social engineering to deceive victims into micro-loans and disclose personal info.
Read: https://thehackernews.com/2023/07/vishing-goes-high-tech-new-letscall.html
This multi-step vishing attack combines hi-tech malware, voice traffic routing, and social engineering to deceive victims into micro-loans and disclose personal info.
Read: https://thehackernews.com/2023/07/vishing-goes-high-tech-new-letscall.html
π19π₯14π€―7β‘6π±4π2
π¨ Beware, Android users! Two popular file management apps on #Google Play Store revealed as spyware, sending users' data to servers in China.
Over 1.5M users' security and privacy are at risk.
Read details: https://thehackernews.com/2023/07/two-spyware-apps-on-google-play-with-15.html
Over 1.5M users' security and privacy are at risk.
Read details: https://thehackernews.com/2023/07/two-spyware-apps-on-google-play-with-15.html
π48π±27π17π€―12β‘8π₯6π€6
π¨ ALERT: $20 million stolen from Revolut in a massive cyber attack. The organized criminal groups took advantage of a loophole, leading to significant financial losses:
Read: http://thehackernews.com/2023/07/hackers-steal-20-million-by-exploiting.html
Read: http://thehackernews.com/2023/07/hackers-steal-20-million-by-exploiting.html
π€―44π±22π₯15π9π€9β‘6π5
Beware, LATAM businesses! A sophisticated banking trojan called TOITOIN is targeting Latin American organizations. Evading detection with custom-designed modules and a multi-stage attack strategy, it demands immediate attention.
Read: https://thehackernews.com/2023/07/new-toitoin-banking-trojan-targeting.html
Read: https://thehackernews.com/2023/07/new-toitoin-banking-trojan-targeting.html
π₯13π6π€―3π1
RomCom RAT strikes again! Cyber threat actors are targeting the NATO Summit in Vilnius with phishing attacks.
Read: https://thehackernews.com/2023/07/romcom-rat-targeting-nato-and-ukraine.html
Read: https://thehackernews.com/2023/07/romcom-rat-targeting-nato-and-ukraine.html
π17π₯8π5π€2
π Mozilla Firefox has introduced a new feature called Quarantined Domains, which blocks certain add-ons on specific sites due to security risks.
Read details: https://thehackernews.com/2023/07/new-mozilla-feature-blocks-risky-add.html
Read details: https://thehackernews.com/2023/07/new-mozilla-feature-blocks-risky-add.html
π72π₯17π7β‘5π€―3π€2
β‘ Apple just released critical updates to patch an actively exploited zero-day (CVE-2023-37450) flaw.
π‘οΈ Update to iOS 16.5.1 (a), iPadOS 16.5.1 (a), macOS Ventura 13.4.1 (a), and Safari 16.5.2.
Read: https://thehackernews.com/2023/07/apple-issues-urgent-patch-for-zero-day.html
π‘οΈ Update to iOS 16.5.1 (a), iPadOS 16.5.1 (a), macOS Ventura 13.4.1 (a), and Safari 16.5.2.
Read: https://thehackernews.com/2023/07/apple-issues-urgent-patch-for-zero-day.html
π30π₯9π6β‘5π±5
Protect your systems against Big Head ransomware's diverse attack vectors! It's not just about encryptionβit also incorporates a file infector called Neshta to deceive security solutions.
Read: https://thehackernews.com/2023/07/beware-of-big-head-ransomware-spreading.html
Read: https://thehackernews.com/2023/07/beware-of-big-head-ransomware-spreading.html
π14π₯9
New report reveals ongoing SCARLETEEL attack campaign targeting AWS Fargate. Cybercriminals escalate privileges, exploit vulnerabilities, and profit through crypto mining.
Learn more about this attack: https://thehackernews.com/2023/07/scarleteel-cryptojacking-campaign.html
Learn more about this attack: https://thehackernews.com/2023/07/scarleteel-cryptojacking-campaign.html
π5π€5π₯1
Discover the power of MITRE ATT&CK! This widely adopted framework categorizes tactics, techniques, and procedures used in cyberattacks, helping security professionals build strong defense strategies.
Learn more: https://thehackernews.com/2023/07/how-to-apply-mitre-att-to-your.html
Learn more: https://thehackernews.com/2023/07/how-to-apply-mitre-att-to-your.html
π20π₯4
π¨ Security Alert: Hackers are exploiting a Microsoft Windows policy loophole to forge signatures on kernel-mode drivers, gaining complete system access.
Learn more about this major threat: https://thehackernews.com/2023/07/hackers-exploit-windows-policy-loophole.html
Learn more about this major threat: https://thehackernews.com/2023/07/hackers-exploit-windows-policy-loophole.html
π€―33π12π11π±8π3π₯1
Heads up, everyone! Microsoft has released updates to fix 130 security flaws, including 6 zero-day vulnerabilities being actively exploited. Update your software now to keep your systems secure.
Learn more: https://thehackernews.com/2023/07/microsoft-releases-patches-for-130.html
Learn more: https://thehackernews.com/2023/07/microsoft-releases-patches-for-130.html
π29π₯16π8π€1
A sophisticated threat actor has been employing a new Python-based fileless attack called PyLoose to mine cryptocurrency on cloud workloads, bypassing traditional detection methods.
Read details: https://thehackernews.com/2023/07/python-based-pyloose-fileless-attack.html
Read details: https://thehackernews.com/2023/07/python-based-pyloose-fileless-attack.html
π€17π8π₯2β‘1π1
π¨πΉοΈ Attention gamers! A new rootkit signed by Microsoft has been discovered, targeting the #gaming sector in China.
Read details here: https://thehackernews.com/2023/07/chinese-hackers-deploy-microsoft-signed.html
Read details here: https://thehackernews.com/2023/07/chinese-hackers-deploy-microsoft-signed.html
π€―17π8π4π€4π3
Microsoft thwarts cyber attack by a Chinese nation-state actor targeting government agencies and organizations, focused on espionage and data theft.
Read more: https://thehackernews.com/2023/07/microsoft-thwarts-chinese-cyber-attack.html
Read more: https://thehackernews.com/2023/07/microsoft-thwarts-chinese-cyber-attack.html
π₯15π7π5π€5
Ransomware attacks continue to rise in 2023, with cybercriminals extorting a staggering $449.1 million in the first half of the year alone. These extortionists are showing no signs of slowing down, with their sights set on a potential $898.6 million haul in 2023.
Read: https://thehackernews.com/2023/07/ransomware-extortion-skyrockets-in-2023.html
Read: https://thehackernews.com/2023/07/ransomware-extortion-skyrockets-in-2023.html
π₯16π€12π10π±9π€―5π4
Phishing attacks are becoming more sophisticated with AI. Discover how cybercriminals leverage AI to enhance their phishing techniques and what organizations can do to defend against them.
Read: https://thehackernews.com/2023/07/the-risks-and-preventions-of-ai-in.html
Read: https://thehackernews.com/2023/07/the-risks-and-preventions-of-ai-in.html
π38π±11π9π₯3