Researchers found a vulnerability in AI-as-a-service provider "Replicate" that could allow unauthorized access to proprietary AI models and sensitive data.
Read: https://thehackernews.com/2024/05/experts-find-flaw-in-replicate-ai.html
The issue stemmed from the arbitrary code execution potential in AI model packaging.
Read: https://thehackernews.com/2024/05/experts-find-flaw-in-replicate-ai.html
The issue stemmed from the arbitrary code execution potential in AI model packaging.
๐22๐ฅ10๐7โก5
Indian government, defense, and aerospace sectors targeted by Pakistan-nexus actor Transparent Tribe using cross-platform malware written in Python, Golang, and Rust.
Learn about the new set of attacks: https://thehackernews.com/2024/05/pakistan-linked-hackers-deploy-python.html
Learn about the new set of attacks: https://thehackernews.com/2024/05/pakistan-linked-hackers-deploy-python.html
๐ฅ17โก8๐3๐3๐คฏ3๐1
๐จ Experts have uncovered phishing campaigns using HTML smuggling, DNS tunneling, generative AI, PhaaS toolkits, malvertising, and Cloudflare Workers to serve malicious sites targeting Microsoft and Gmail credentials.
Find out more: https://thehackernews.com/2024/05/new-tricks-in-phishing-playbook.html
Find out more: https://thehackernews.com/2024/05/new-tricks-in-phishing-playbook.html
๐ฅ17๐5
๐จ Cyber Alert: #Microsoft highlights Morocco-based Storm-0539, stealing up to $100,000/day in gift card fraud.
๐ Discover the full story: https://thehackernews.com/2024/05/moroccan-cybercrime-group-steals-up-to.html
๐ Discover the full story: https://thehackernews.com/2024/05/moroccan-cybercrime-group-steals-up-to.html
๐11๐ฅ8๐6๐2โก1
๐จ 83% of organizations have fallen victim to phishing. Itโs time to rethink our security strategies. Discover innovative solutions that inspect web sessions and neutralize threats in real-time.
Read the full report: https://thehackernews.com/2024/05/report-dark-side-of-phishing-protection.html
Read the full report: https://thehackernews.com/2024/05/report-dark-side-of-phishing-protection.html
๐ค12๐ฅ9๐6๐3โก1๐1
๐จ Critical Alert: TP-Link Archer C5400X ๐ฎ Gaming Router Vulnerability.
๐ฆ Severity: Maximum (CVSS 10.0)
๐ก๏ธ Impact: Remote code execution Patch available: Firmware version 1_1.1.7 Protect your network, update now!
Read more: https://thehackernews.com/2024/05/tp-link-gaming-router-vulnerability.html
๐ฆ Severity: Maximum (CVSS 10.0)
๐ก๏ธ Impact: Remote code execution Patch available: Firmware version 1_1.1.7 Protect your network, update now!
Read more: https://thehackernews.com/2024/05/tp-link-gaming-router-vulnerability.html
๐ฅ18๐ฑ10๐6๐5โก2๐2
Unknown threat actors are targeting WordPress sites with a new attack vector, using the Dessky Snippets plugin to insert malicious PHP code and harvest credit card data.
Read More ๐ https://thehackernews.com/2024/05/wordpress-plugin-exploited-to-steal.html
Read More ๐ https://thehackernews.com/2024/05/wordpress-plugin-exploited-to-steal.html
๐ฑ15โก4๐3
Dual Threat: CatDDoS & DNSBomb!
๐ฑ CatDDoS botnet exploits 80+ vulnerabilities, targeting 300+ devices daily for DDoS attacks.
๐ฃ DNSBomb, a new attack technique, achieves a 20,000x amplification in PDoS attacks.
Read the full story: https://thehackernews.com/2024/05/researchers-warn-of-catddos-botnet-and.html
๐ฑ CatDDoS botnet exploits 80+ vulnerabilities, targeting 300+ devices daily for DDoS attacks.
๐ฃ DNSBomb, a new attack technique, achieves a 20,000x amplification in PDoS attacks.
Read the full story: https://thehackernews.com/2024/05/researchers-warn-of-catddos-botnet-and.html
๐ค14๐คฏ10๐6โก3
Special deals from the ANYRUN interactive malware sandbox ๐
New and existing clients can receive:
โ 6 months of free service
โ Additional licenses for team members
Get it until May 31 โก๏ธ https://thn.news/anyrun-sandbox
New and existing clients can receive:
โ 6 months of free service
โ Additional licenses for team members
Get it until May 31 โก๏ธ https://thn.news/anyrun-sandbox
app.any.run
Subscription Plans - ANY.RUN
Interactive malware hunting service. Live testing of most type of threats in any environments. No installation and no waiting necessary.
๐12๐คฏ5๐2๐1
๐ With endless cyber threats, the 'spray 'n pray' approach is costing you big time. Discover the secret to prioritizing your resources and efforts on what truly matters.
Donโt miss out โ read the full article now: https://thehackernews.com/2024/05/4-step-approach-to-mapping-and-securing.html
Donโt miss out โ read the full article now: https://thehackernews.com/2024/05/4-step-approach-to-mapping-and-securing.html
๐ฅ14๐4๐ค1
๐ธ Indian national pleads guilty to stealing over $37M through fake Coinbase website.
In separate cases, a Ukrainian arrested for aiding North Korean IT workers; Vietnamese charged for helping Chinese remote IT workers commit wire fraud.
Read: https://thehackernews.com/2024/05/indian-national-pleads-guilty-to-37.html
In separate cases, a Ukrainian arrested for aiding North Korean IT workers; Vietnamese charged for helping Chinese remote IT workers commit wire fraud.
Read: https://thehackernews.com/2024/05/indian-national-pleads-guilty-to-37.html
๐คฏ23๐7๐5๐ฑ5๐ฅ1
๐จ BreachForums domain is back online just 2 weeks after a law enforcement takedown!
Trap or blunder?
Learn more: https://thehackernews.com/2024/05/breachforums-returns-just-weeks-after.html
It's now selling: 1.3 TB database with 560M Ticketmaster customers' data for $500K!
Trap or blunder?
Learn more: https://thehackernews.com/2024/05/breachforums-returns-just-weeks-after.html
It's now selling: 1.3 TB database with 560M Ticketmaster customers' data for $500K!
๐27๐7๐ฅ6โก4๐ค2
Microsoft uncovers Moonstone Sleet, a new North Korean hacker group targeting various sectors with ransomware and custom malware, using fake companies and tools to infiltrate targets.
Details here: https://thehackernews.com/2024/05/microsoft-uncovers-moonstone-sleet-new.html
Details here: https://thehackernews.com/2024/05/microsoft-uncovers-moonstone-sleet-new.html
๐11๐ฅ7๐4
๐ป Malachi Mullings, a 31-year-old from Georgia, has been sentenced to 10 years for laundering $4.5 million through BEC and ๐ romance scams.
Learn how they pulled off the scam: https://thehackernews.com/2024/05/us-sentences-31-year-old-to-10-years.html
Learn how they pulled off the scam: https://thehackernews.com/2024/05/us-sentences-31-year-old-to-10-years.html
๐15๐9๐ฅ6๐6
๐ Introducing GRC Mastery โ Cyber Security GRC Training for beginners.
๐ฝ๏ธ Video modules, assessments, quizzes.
๐ Master risk management, audit, compliance, asset management.
๐ญ Capstone Project: NIST assessment.
๐ Earn a certificate.
Check it out: https://grcmastery.com
๐ฝ๏ธ Video modules, assessments, quizzes.
๐ Master risk management, audit, compliance, asset management.
๐ญ Capstone Project: NIST assessment.
๐ Earn a certificate.
Check it out: https://grcmastery.com
Grcmastery
GRC Mastery - Start a Non-Technical Cyber Security Career!
Start a Non-Technical Cyber Security Career! No degree, certifications, coding, or ANY technical knowledge required.
๐ฅ14๐11๐ค2๐1
๐ง๐ท๐ฐ New campaign targets Brazilian banks with AllaSenha, a custom AllaKore RAT variant. The malware steals banking credentials and uses Azure cloud for C2.
Learn more: https://thehackernews.com/2024/05/brazilian-banks-targeted-by-new.html
Learn more: https://thehackernews.com/2024/05/brazilian-banks-targeted-by-new.html
๐ฅ15๐2๐ค1
๐จ Attention: Check Point discovers zero-day vulnerability CVE-2024-24919 in Network Security VPN gateway products, exploited in the wild.
Read more here: https://thehackernews.com/2024/05/check-point-warns-of-zero-day-attacks.html
๐ง Ensure your systems are patched with the latest hotfixes.
Read more here: https://thehackernews.com/2024/05/check-point-warns-of-zero-day-attacks.html
๐ง Ensure your systems are patched with the latest hotfixes.
๐คฏ15๐11๐ฑ4๐ค2๐1
Employee offboarding is crucial for security. 63% of businesses may have ex-employees with data access. Automate SaaS security to reduce risks.
Learn more at: https://thehackernews.com/2024/05/new-research-warns-about-weak.html
Learn more at: https://thehackernews.com/2024/05/new-research-warns-about-weak.html
๐ค9๐7๐ฅ2
A malicious Python package, pytoileur, has been found in PyPI, aiming at cryptocurrency theft. Downloaded 316 times and re-uploaded after removal, this highlights significant risks in open-source ecosystems.
Learn more: https://thehackernews.com/2024/05/cybercriminals-abuse-stackoverflow-to.html
Learn more: https://thehackernews.com/2024/05/cybercriminals-abuse-stackoverflow-to.html
๐คฏ13๐12โก4๐ฑ4๐1
๐จ Warning: Okta warns of a vulnerability in the cross-origin authentication feature of their Customer Identity Cloud (CIC) that attackers are increasingly exploiting for credential stuffing attacks.
Learn more: https://thehackernews.com/2024/05/okta-warns-of-credential-stuffing.html
Learn more: https://thehackernews.com/2024/05/okta-warns-of-credential-stuffing.html
๐ค10๐9๐คฏ2