RomCom RAT strikes again! Cyber threat actors are targeting the NATO Summit in Vilnius with phishing attacks.
Read: https://thehackernews.com/2023/07/romcom-rat-targeting-nato-and-ukraine.html
Read: https://thehackernews.com/2023/07/romcom-rat-targeting-nato-and-ukraine.html
π17π₯8π5π€2
π Mozilla Firefox has introduced a new feature called Quarantined Domains, which blocks certain add-ons on specific sites due to security risks.
Read details: https://thehackernews.com/2023/07/new-mozilla-feature-blocks-risky-add.html
Read details: https://thehackernews.com/2023/07/new-mozilla-feature-blocks-risky-add.html
π72π₯17π7β‘5π€―3π€2
β‘ Apple just released critical updates to patch an actively exploited zero-day (CVE-2023-37450) flaw.
π‘οΈ Update to iOS 16.5.1 (a), iPadOS 16.5.1 (a), macOS Ventura 13.4.1 (a), and Safari 16.5.2.
Read: https://thehackernews.com/2023/07/apple-issues-urgent-patch-for-zero-day.html
π‘οΈ Update to iOS 16.5.1 (a), iPadOS 16.5.1 (a), macOS Ventura 13.4.1 (a), and Safari 16.5.2.
Read: https://thehackernews.com/2023/07/apple-issues-urgent-patch-for-zero-day.html
π30π₯9π6β‘5π±5
Protect your systems against Big Head ransomware's diverse attack vectors! It's not just about encryptionβit also incorporates a file infector called Neshta to deceive security solutions.
Read: https://thehackernews.com/2023/07/beware-of-big-head-ransomware-spreading.html
Read: https://thehackernews.com/2023/07/beware-of-big-head-ransomware-spreading.html
π14π₯9
New report reveals ongoing SCARLETEEL attack campaign targeting AWS Fargate. Cybercriminals escalate privileges, exploit vulnerabilities, and profit through crypto mining.
Learn more about this attack: https://thehackernews.com/2023/07/scarleteel-cryptojacking-campaign.html
Learn more about this attack: https://thehackernews.com/2023/07/scarleteel-cryptojacking-campaign.html
π5π€5π₯1
Discover the power of MITRE ATT&CK! This widely adopted framework categorizes tactics, techniques, and procedures used in cyberattacks, helping security professionals build strong defense strategies.
Learn more: https://thehackernews.com/2023/07/how-to-apply-mitre-att-to-your.html
Learn more: https://thehackernews.com/2023/07/how-to-apply-mitre-att-to-your.html
π20π₯4
π¨ Security Alert: Hackers are exploiting a Microsoft Windows policy loophole to forge signatures on kernel-mode drivers, gaining complete system access.
Learn more about this major threat: https://thehackernews.com/2023/07/hackers-exploit-windows-policy-loophole.html
Learn more about this major threat: https://thehackernews.com/2023/07/hackers-exploit-windows-policy-loophole.html
π€―33π12π11π±8π3π₯1
Heads up, everyone! Microsoft has released updates to fix 130 security flaws, including 6 zero-day vulnerabilities being actively exploited. Update your software now to keep your systems secure.
Learn more: https://thehackernews.com/2023/07/microsoft-releases-patches-for-130.html
Learn more: https://thehackernews.com/2023/07/microsoft-releases-patches-for-130.html
π29π₯16π8π€1
A sophisticated threat actor has been employing a new Python-based fileless attack called PyLoose to mine cryptocurrency on cloud workloads, bypassing traditional detection methods.
Read details: https://thehackernews.com/2023/07/python-based-pyloose-fileless-attack.html
Read details: https://thehackernews.com/2023/07/python-based-pyloose-fileless-attack.html
π€17π8π₯2β‘1π1
π¨πΉοΈ Attention gamers! A new rootkit signed by Microsoft has been discovered, targeting the #gaming sector in China.
Read details here: https://thehackernews.com/2023/07/chinese-hackers-deploy-microsoft-signed.html
Read details here: https://thehackernews.com/2023/07/chinese-hackers-deploy-microsoft-signed.html
π€―17π8π4π€4π3
Microsoft thwarts cyber attack by a Chinese nation-state actor targeting government agencies and organizations, focused on espionage and data theft.
Read more: https://thehackernews.com/2023/07/microsoft-thwarts-chinese-cyber-attack.html
Read more: https://thehackernews.com/2023/07/microsoft-thwarts-chinese-cyber-attack.html
π₯15π7π5π€5
Ransomware attacks continue to rise in 2023, with cybercriminals extorting a staggering $449.1 million in the first half of the year alone. These extortionists are showing no signs of slowing down, with their sights set on a potential $898.6 million haul in 2023.
Read: https://thehackernews.com/2023/07/ransomware-extortion-skyrockets-in-2023.html
Read: https://thehackernews.com/2023/07/ransomware-extortion-skyrockets-in-2023.html
π₯16π€12π10π±9π€―5π4
Phishing attacks are becoming more sophisticated with AI. Discover how cybercriminals leverage AI to enhance their phishing techniques and what organizations can do to defend against them.
Read: https://thehackernews.com/2023/07/the-risks-and-preventions-of-ai-in.html
Read: https://thehackernews.com/2023/07/the-risks-and-preventions-of-ai-in.html
π38π±11π9π₯3
β‘οΈ SonicWall and Fortinet both address critical vulnerabilities in their network security software. Update SonicWall's GMS and Analytics, and Fortinet's FortiOS and FortiProxy immediately to protect against unauthorized access.
Read: https://thehackernews.com/2023/07/new-vulnerabilities-disclosed-in.html
Read: https://thehackernews.com/2023/07/new-vulnerabilities-disclosed-in.html
π₯19π9π€―3π€2
A sophisticated China-based hacking campaign has targeted U.S. government agencies and organizations, compromising email accounts via Microsoft Outlook Web Access in Exchange Online (OWA) & Outlook.
Read: https://thehackernews.com/2023/07/us-government-agencies-emails.html
Read: https://thehackernews.com/2023/07/us-government-agencies-emails.html
π22π6π4π±1
U.S. CISA warns of critical vulnerabilities in Rockwell Automation ControlLogix ENIP modules, allowing remote code execution and DoS attacks.
Read details: https://thehackernews.com/2023/07/rockwell-automation-controllogix-bugs.html
Read details: https://thehackernews.com/2023/07/rockwell-automation-controllogix-bugs.html
π10π10
Watch out, researchers! A recently discovered proof-of-concept (PoC) exploit on GitHub for CVE-2023-35829 turns out to be a malicious downloader. It silently executes a bash script disguised as a kernel-level process.
Read more: https://thehackernews.com/2023/07/blog-post.html
Read more: https://thehackernews.com/2023/07/blog-post.html
π€―29π11π11π±5π€4
π¨ A highly aggressive cloud campaign by the TeamTNT group called Silentbob has infected 196 hosts! They're targeting Docker, Kubernetes, Redis, Postgres, and more. The focus appears to be testing the botnet rather than cryptomining.
Read: https://thehackernews.com/2023/07/teamtnts-silentbob-botnet-infecting-196.html
Read: https://thehackernews.com/2023/07/teamtnts-silentbob-botnet-infecting-196.html
π±14π₯6π4
A new report reveals a series of cyberattacks targeting government entities, military organizations, & civilian users in #Ukraine & Poland. The attacks aim to steal sensitive data and gain remote access to infected systems.
Learn more: https://thehackernews.com/2023/07/picassoloader-malware-used-in-ongoing.html
Learn more: https://thehackernews.com/2023/07/picassoloader-malware-used-in-ongoing.html
π17π7π6π€5π±5π€―2
Zimbra users, be cautious! Email collaboration software company has warned of an actively exploited zero-day vulnerability in its software.
Read details here: https://thehackernews.com/2023/07/zimbra-warns-of-critical-zero-day-flaw.html
Apply the patch ASAP to eliminate the attack vector.
Read details here: https://thehackernews.com/2023/07/zimbra-warns-of-critical-zero-day-flaw.html
Apply the patch ASAP to eliminate the attack vector.
π20π€4π€―3π2