A sophisticated threat actor has been employing a new Python-based fileless attack called PyLoose to mine cryptocurrency on cloud workloads, bypassing traditional detection methods.
Read details: https://thehackernews.com/2023/07/python-based-pyloose-fileless-attack.html
Read details: https://thehackernews.com/2023/07/python-based-pyloose-fileless-attack.html
đ¤17đ8đĨ2âĄ1đ1
đ¨đšī¸ Attention gamers! A new rootkit signed by Microsoft has been discovered, targeting the #gaming sector in China.
Read details here: https://thehackernews.com/2023/07/chinese-hackers-deploy-microsoft-signed.html
Read details here: https://thehackernews.com/2023/07/chinese-hackers-deploy-microsoft-signed.html
đ¤¯17đ8đ4đ¤4đ3
Microsoft thwarts cyber attack by a Chinese nation-state actor targeting government agencies and organizations, focused on espionage and data theft.
Read more: https://thehackernews.com/2023/07/microsoft-thwarts-chinese-cyber-attack.html
Read more: https://thehackernews.com/2023/07/microsoft-thwarts-chinese-cyber-attack.html
đĨ15đ7đ5đ¤5
Ransomware attacks continue to rise in 2023, with cybercriminals extorting a staggering $449.1 million in the first half of the year alone. These extortionists are showing no signs of slowing down, with their sights set on a potential $898.6 million haul in 2023.
Read: https://thehackernews.com/2023/07/ransomware-extortion-skyrockets-in-2023.html
Read: https://thehackernews.com/2023/07/ransomware-extortion-skyrockets-in-2023.html
đĨ16đ¤12đ10đą9đ¤¯5đ4
Phishing attacks are becoming more sophisticated with AI. Discover how cybercriminals leverage AI to enhance their phishing techniques and what organizations can do to defend against them.
Read: https://thehackernews.com/2023/07/the-risks-and-preventions-of-ai-in.html
Read: https://thehackernews.com/2023/07/the-risks-and-preventions-of-ai-in.html
đ38đą11đ9đĨ3
âĄī¸ SonicWall and Fortinet both address critical vulnerabilities in their network security software. Update SonicWall's GMS and Analytics, and Fortinet's FortiOS and FortiProxy immediately to protect against unauthorized access.
Read: https://thehackernews.com/2023/07/new-vulnerabilities-disclosed-in.html
Read: https://thehackernews.com/2023/07/new-vulnerabilities-disclosed-in.html
đĨ19đ9đ¤¯3đ¤2
A sophisticated China-based hacking campaign has targeted U.S. government agencies and organizations, compromising email accounts via Microsoft Outlook Web Access in Exchange Online (OWA) & Outlook.
Read: https://thehackernews.com/2023/07/us-government-agencies-emails.html
Read: https://thehackernews.com/2023/07/us-government-agencies-emails.html
đ22đ6đ4đą1
U.S. CISA warns of critical vulnerabilities in Rockwell Automation ControlLogix ENIP modules, allowing remote code execution and DoS attacks.
Read details: https://thehackernews.com/2023/07/rockwell-automation-controllogix-bugs.html
Read details: https://thehackernews.com/2023/07/rockwell-automation-controllogix-bugs.html
đ10đ10
Watch out, researchers! A recently discovered proof-of-concept (PoC) exploit on GitHub for CVE-2023-35829 turns out to be a malicious downloader. It silently executes a bash script disguised as a kernel-level process.
Read more: https://thehackernews.com/2023/07/blog-post.html
Read more: https://thehackernews.com/2023/07/blog-post.html
đ¤¯29đ11đ11đą5đ¤4
đ¨ A highly aggressive cloud campaign by the TeamTNT group called Silentbob has infected 196 hosts! They're targeting Docker, Kubernetes, Redis, Postgres, and more. The focus appears to be testing the botnet rather than cryptomining.
Read: https://thehackernews.com/2023/07/teamtnts-silentbob-botnet-infecting-196.html
Read: https://thehackernews.com/2023/07/teamtnts-silentbob-botnet-infecting-196.html
đą14đĨ6đ4
A new report reveals a series of cyberattacks targeting government entities, military organizations, & civilian users in #Ukraine & Poland. The attacks aim to steal sensitive data and gain remote access to infected systems.
Learn more: https://thehackernews.com/2023/07/picassoloader-malware-used-in-ongoing.html
Learn more: https://thehackernews.com/2023/07/picassoloader-malware-used-in-ongoing.html
đ17đ7đ6đ¤5đą5đ¤¯2
Zimbra users, be cautious! Email collaboration software company has warned of an actively exploited zero-day vulnerability in its software.
Read details here: https://thehackernews.com/2023/07/zimbra-warns-of-critical-zero-day-flaw.html
Apply the patch ASAP to eliminate the attack vector.
Read details here: https://thehackernews.com/2023/07/zimbra-warns-of-critical-zero-day-flaw.html
Apply the patch ASAP to eliminate the attack vector.
đ20đ¤4đ¤¯3đ2
đ¨ Alert! A new malware strain called AVrecon has quietly targeted over 70,000 small office/home office (SOHO) routers worldwide, forming a massive botnet of 40,000 nodes across 20 countries.
Read: http://thehackernews.com/2023/07/new-soho-router-botnet-avrecon-spreads.html
Read: http://thehackernews.com/2023/07/new-soho-router-botnet-avrecon-spreads.html
đ19đ¤¯10đĨ4đą4
TeamTNT has expanded its cloud credential stealing campaign beyond AWS, now also targeting Azure and Google Cloud Platform.
Learn more about it: https://thehackernews.com/2023/07/teamtnts-cloud-credential-stealing.html
Learn more about it: https://thehackernews.com/2023/07/teamtnts-cloud-credential-stealing.html
đ¤10đ9đą8đ4
â ī¸ Heads up: Over a million WordPress sites are affected by a critical bug in the All-In-One Security (AIOS) plugin.
It stored user passwords in plaintext, posing a risk if admins reused them on other services.
Read: https://thehackernews.com/2023/07/aios-wordpress-plugin-faces-backlash.html
It stored user passwords in plaintext, posing a risk if admins reused them on other services.
Read: https://thehackernews.com/2023/07/aios-wordpress-plugin-faces-backlash.html
đ32đ¤¯22đ17đĨ10đ¤9
đ¨ đ Microsoft admits a validation issue in its code that enabled China-based hackers to forge authentication tokens, granting unauthorized access to Azure AD and Outlook[.]com accounts of over two dozen organizations.
Read: https://thehackernews.com/2023/07/microsoft-bug-allowed-hackers-to-breach.html
Read: https://thehackernews.com/2023/07/microsoft-bug-allowed-hackers-to-breach.html
đ31đ¤¯23đ12đĨ5âĄ3
A new generative AI cybercrime tool called WormGPT is gaining popularity in underground forums. It enables cybercriminals to automate advanced phishing and BEC attacks, using personalized fake emails to increase success rates.
Read: https://thehackernews.com/2023/07/wormgpt-new-ai-tool-allows.html
Read: https://thehackernews.com/2023/07/wormgpt-new-ai-tool-allows.html
đ¤¯48đ32đ21đĨ11đ¤5âĄ4đą1
â ī¸ New report reveals the alarming activities of Gamaredon, a notorious Russian hacking crew. They exploit email and messaging platforms to compromise systems, exfiltrating files in a matter of minutes.
Read: https://thehackernews.com/2023/07/cert-ua-uncovers-gamaredons-rapid-data.html
Read: https://thehackernews.com/2023/07/cert-ua-uncovers-gamaredons-rapid-data.html
đ23đ¤¯14đ2
Cybercriminals are leveraging exploits for CVE-2021-40444 and CVE-2022-30190 to execute code through malicious Word files. Once opened, LokiBot malware is downloaded, logging keystrokes, capturing screenshots, and stealing data.
Read: https://thehackernews.com/2023/07/cybercriminals-exploit-microsoft-word.html
Read: https://thehackernews.com/2023/07/cybercriminals-exploit-microsoft-word.html
đ23âĄ7đ4đ¤3
đ¨ Cyber attacks via infected USB drives have tripled in the first half of 2023. Learn more about the SOGU and SNOWYDRIVE campaigns targeting public and private sector entities worldwide.
Read: https://thehackernews.com/2023/07/malicious-usb-drives-targetinging.html
Read: https://thehackernews.com/2023/07/malicious-usb-drives-targetinging.html
đ18đ¤¯16âĄ5đĨ3