Nowhere to hide!
Researchers uncover a potential new method of profiling users in the crowd by de-anonymizing their smart device IDs (e.g., MAC addresses) to their biometrics (e.g., face, voice, gait).
Details β€ https://thehackernews.com/2020/04/deanonymize-device-biometrics.html
Researchers uncover a potential new method of profiling users in the crowd by de-anonymizing their smart device IDs (e.g., MAC addresses) to their biometrics (e.g., face, voice, gait).
Details β€ https://thehackernews.com/2020/04/deanonymize-device-biometrics.html
</> Patch 'em all </>
Adobe today released security patches for over a dozen newly-discovered critical vulnerabilities affecting 3 of its popular software:
β Magento CMS
β Adobe Illustrator
β Adobe Bridge
Read details β https://thehackernews.com/2020/04/adobe-software-updates.html
Adobe today released security patches for over a dozen newly-discovered critical vulnerabilities affecting 3 of its popular software:
β Magento CMS
β Adobe Illustrator
β Adobe Bridge
Read details β https://thehackernews.com/2020/04/adobe-software-updates.html
During COVID19 pandemic, where many organizations & universities are embracing online learning, researchers discover multiple critical vulnerabilities in 3 widely-used Learning Management System (LMS) plugins for #WordPress sites.
Read more β https://thehackernews.com/2020/04/wordpress-lms-plugins.html
Read more β https://thehackernews.com/2020/04/wordpress-lms-plugins.html
EventBot β A new Android malware spotted in-the-wild steals infected users' BANKING passwords, exfiltrate private DATA, and capture KEYSTROKES to spy on accounts and the content of other apps installed on the targeted devices.
Read: https://thehackernews.com/2020/04/android-banking-keylogger.html
Read: https://thehackernews.com/2020/04/android-banking-keylogger.html
π₯ WARNING β Hereβs a new CVSS 10 Bug.
A newly disclosed critical SaltStack RCE (as root) vulnerability (CVE-2020-11651) affects thousands of servers (~6000) deployed in data centers and cloud environments.
Read details β https://thehackernews.com/2020/05/saltstack-rce-vulnerability.html
A newly disclosed critical SaltStack RCE (as root) vulnerability (CVE-2020-11651) affects thousands of servers (~6000) deployed in data centers and cloud environments.
Read details β https://thehackernews.com/2020/05/saltstack-rce-vulnerability.html
WARNING β Just within a day after public disclosure of SaltStack RCE vulnerability (CVE-2020-11651), hackers have started exploiting unpatched servers.
β LineageOS [hacked]
β Ghost CMS [hacked]
β DigiCert [hacked]
Read more: https://thehackernews.com/2020/05/saltstack-rce-exploit.html
β LineageOS [hacked]
β Ghost CMS [hacked]
β DigiCert [hacked]
Read more: https://thehackernews.com/2020/05/saltstack-rce-exploit.html
Now this π is Interesting!
A researcher demonstrated a malware that jumps air-gapped β also audio gapped β devices (PC, servers, IoT, embedded devices) by turning their power-supplies into out-of-band speakers.
Read details + watch demo β€
https://thehackernews.com/2020/05/air-gap-malware-power-speaker.html
A researcher demonstrated a malware that jumps air-gapped β also audio gapped β devices (PC, servers, IoT, embedded devices) by turning their power-supplies into out-of-band speakers.
Read details + watch demo β€
https://thehackernews.com/2020/05/air-gap-malware-power-speaker.html
Attention Xiaomi Users!
You Should immediately change the newly introduced PRIVACY setting in your Mi/Mi Pro and Mint browsers to prevent the company from spying on your web history and online activities when browsing in INCOGNITO mode.
Read details:
https://thehackernews.com/2020/05/xiaomi-browser-history.html
You Should immediately change the newly introduced PRIVACY setting in your Mi/Mi Pro and Mint browsers to prevent the company from spying on your web history and online activities when browsing in INCOGNITO mode.
Read details:
https://thehackernews.com/2020/05/xiaomi-browser-history.html
{new} π₯ Watch Out Enterprises!
Citrix ShareFile platform contains critical vulnerabilities that could let unauthenticated attackers steal proprietary, sensitive business data from on-premise storage zone controllers.
Details β https://thehackernews.com/2020/05/citrix-sharefile-vulnerability.html
Citrix ShareFile platform contains critical vulnerabilities that could let unauthenticated attackers steal proprietary, sensitive business data from on-premise storage zone controllers.
Details β https://thehackernews.com/2020/05/citrix-sharefile-vulnerability.html
Facebook launches 'Discover,' a new, yet another, free Internet service in partnership with mobile carriers across the world.
Unlike previous projects, Discover:
β Treats all websites equally,
β Accesses sites through a secure web proxy,
β Lets users browse text-based sites.
Read details:
https://thehackernews.com/2020/05/facebook-discover-free-internet.html
Unlike previous projects, Discover:
β Treats all websites equally,
β Accesses sites through a secure web proxy,
β Lets users browse text-based sites.
Read details:
https://thehackernews.com/2020/05/facebook-discover-free-internet.html
A Chinese APT group has recently been spotted targeting government entities in the Asia-Pacific region as part of a stealthy cyber-espionage campaign that went undetected for the last 5 years.
Read details β€ https://thehackernews.com/2020/05/asia-pacific-cyber-espionage.html
Read details β€ https://thehackernews.com/2020/05/asia-pacific-cyber-espionage.html
Digital Ocean β one of the largest modern web hosting companies β recently suffered a data leak incident that exposed some of its customers' data to unauthorized third parties, at least 15 times.
Read more: https://thehackernews.com/2020/05/digitalocean-data-breach.html
Read more: https://thehackernews.com/2020/05/digitalocean-data-breach.html
β‘ ThunderSpy π΅οΈββοΈ
7 new unpatchable hardware vulnerabilities affect all Thunderbolt-equipped computers sold in the last 9 years, letting attackers steal data from encrypted systemsβwhen locked or in sleep modeβthrough 'evil maid' scenarios.
Read: https://thehackernews.com/2020/05/thunderbolt-vulnerabilities.html
7 new unpatchable hardware vulnerabilities affect all Thunderbolt-equipped computers sold in the last 9 years, letting attackers steal data from encrypted systemsβwhen locked or in sleep modeβthrough 'evil maid' scenarios.
Read: https://thehackernews.com/2020/05/thunderbolt-vulnerabilities.html
Watch Out !!!
If you are running a vBulletin forum website, make sure to install a newly issued security patch update that fixes an undisclosed critical vulnerability (CVE-2020-12720) in the popular forum software.
Read here: https://thehackernews.com/2020/05/vBulletin-access-vulnerability.html
If you are running a vBulletin forum website, make sure to install a newly issued security patch update that fixes an undisclosed critical vulnerability (CVE-2020-12720) in the popular forum software.
Read here: https://thehackernews.com/2020/05/vBulletin-access-vulnerability.html
Over 4000 Android apps are 'unknowingly' leaking sensitive information on their millions of users through misconfigured (publicly accessible) Google cloud-hosted Firebase databases, a recent assessment of just 15,000 apps revealed.
Read details: https://thehackernews.com/2020/05/android-firebase-database-security.html
Read details: https://thehackernews.com/2020/05/android-firebase-database-security.html
Kali Linux version 2020.2 has been released with:
β KDE Plasma Makeover & Login
β PowerShell by Default
β Kali on ARM Improvements
β Lessons From The Installer Changes
β New Key Packages & Icons
β Behind the Scenes, Infrastructure Improvements
https://twitter.com/TheHackersNews/status/1260254183644487680
β KDE Plasma Makeover & Login
β PowerShell by Default
β Kali on ARM Improvements
β Lessons From The Installer Changes
β New Key Packages & Icons
β Behind the Scenes, Infrastructure Improvements
https://twitter.com/TheHackersNews/status/1260254183644487680
X (formerly Twitter)
The Hacker News (@TheHackersNews) on X
Kali Linux version 2020.2 has been released with:
β KDE Plasma Makeover & Login
β PowerShell by Default
β Kali on ARM Improvements
β Lessons From The Installer Changes
β New Key Packages & Icons
β Behind the Scenes, Infrastructure Improvements
https://t.co/3mwdEeIh7s
β KDE Plasma Makeover & Login
β PowerShell by Default
β Kali on ARM Improvements
β Lessons From The Installer Changes
β New Key Packages & Icons
β Behind the Scenes, Infrastructure Improvements
https://t.co/3mwdEeIh7s
On the 3rd anniversary of global WannaCry ransomware outbreak, U.S. Defense, FBI & CISA released a joint report exposing 3 new sophisticated malware North Korean state-sponsored hackers are using against its targets.
Read more: https://thehackernews.com/2020/05/fbi-north-korean-malware.html
Read more: https://thehackernews.com/2020/05/fbi-north-korean-malware.html
Researcher at ESET spotted a new piece of malware that he claimed to be tailored for attacking computers protected insider "AirβGapped networks."
Read more about 'Ramsay malware' β
https://thehackernews.com/2020/05/airgap-network-malware.html
Read more about 'Ramsay malware' β
https://thehackernews.com/2020/05/airgap-network-malware.html
Remember the Reverse RDP Attacks?
A path traversal vulnerability in Windows RDP client that could let a server reversibly compromise a client system that connects to it.
Microsoft issued a patch for it in July 2019, which was bypassed and re-patched in February 2020, which apparently is still incomplete and leaves dozens of 3rd party RDP clients vulnerable that uses Microsoft API function.
https://thehackernews.com/2020/05/reverse-rdp-attack-patch.html
A path traversal vulnerability in Windows RDP client that could let a server reversibly compromise a client system that connects to it.
Microsoft issued a patch for it in July 2019, which was bypassed and re-patched in February 2020, which apparently is still incomplete and leaves dozens of 3rd party RDP clients vulnerable that uses Microsoft API function.
https://thehackernews.com/2020/05/reverse-rdp-attack-patch.html
A new variant of COMpfun cyber-espionage malware interprets HTTP status codes to learn what to do with the hacked computersβbelonging to diplomatic entities in Europe.
Read more: https://thehackernews.com/2020/05/malware-http-codes.html
Read more: https://thehackernews.com/2020/05/malware-http-codes.html