The Hacker News

Syndikovat obsah
The Hacker News has been internationally recognized as a leading news source dedicated to promoting awareness for security experts and [email protected]
Aktualizace: 57 min 13 sek zpět

Severe Flaws Disclosed in Brocade SANnav SAN Management Software

26 Duben, 2024 - 16:03
Several security vulnerabilities disclosed in Brocade SANnav storage area network (SAN) management application could be exploited to compromise susceptible appliances. The 18 flaws impact all versions up to and including 2.3.0, according to independent security researcher Pierre Barre, who discovered and reported them. The issues range from incorrect firewall rules,Newsroomhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

10 Critical Endpoint Security Tips You Should Know

26 Duben, 2024 - 12:46
In today's digital world, where connectivity is rules all, endpoints serve as the gateway to a business’s digital kingdom. And because of this, endpoints are one of hackers' favorite targets.  According to the IDC, 70% of successful breaches start at the endpoint. Unprotected endpoints provide vulnerable entry points to launch devastating cyberattacks. With IT The Hacker Newshttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

New 'Brokewell' Android Malware Spread Through Fake Browser Updates

26 Duben, 2024 - 12:42
Fake browser updates are being used to push a previously undocumented Android malware called Brokewell. "Brokewell is a typical modern banking malware equipped with both data-stealing and remote-control capabilities built into the malware," Dutch security firm ThreatFabric said in an analysis published Thursday. The malware is said to be in active development, Newsroomhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Palo Alto Networks Outlines Remediation for Critical PAN-OS Flaw Under Attack

26 Duben, 2024 - 12:18
Palo Alto Networks has shared remediation guidance for a recently disclosed critical security flaw impacting PAN-OS that has come under active exploitation. The vulnerability, tracked as CVE-2024-3400 (CVSS score: 10.0), could be weaponized to obtain unauthenticated remote shell command execution on susceptible devices. It has been addressed in Newsroomhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Hackers Exploiting WP-Automatic Plugin Bug to Create Admin Accounts on WordPress Sites

26 Duben, 2024 - 07:49
Threat actors are attempting to actively exploit a critical security flaw in the WP‑Automatic plugin for WordPress that could allow site takeovers. The shortcoming, tracked as CVE-2024-27956, carries a CVSS score of 9.9 out of a maximum of 10. It impacts all versions of the plugin prior to 3.9.2.0. "This vulnerability, a SQL injection (SQLi) flaw, poses a severe threat as Newsroomhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

North Korea's Lazarus Group Deploys New Kaolin RAT via Fake Job Lures

25 Duben, 2024 - 18:47
The North Korea-linked threat actor known as Lazarus Group employed its time-tested fabricated job lures to deliver a new remote access trojan called Kaolin RAT as part of attacks targeting specific individuals in the Asia region in summer 2023. The malware could, "aside from standard RAT functionality, change the last write timestamp of a selected file and load any received DLL Newsroomhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Network Threats: A Step-by-Step Attack Demonstration

25 Duben, 2024 - 13:13
Follow this real-life network attack simulation, covering 6 steps from Initial Access to Data Exfiltration. See how attackers remain undetected with the simplest tools and why you need multiple choke points in your defense strategy. Surprisingly, most network attacks are not exceptionally sophisticated, technologically advanced, or reliant on zero-day tools that exploit The Hacker Newshttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

DOJ Arrests Founders of Crypto Mixer Samourai for $2 Billion in Illegal Transactions

25 Duben, 2024 - 12:21
The U.S. Department of Justice (DoJ) on Wednesday announced the arrest of two co-founders of a cryptocurrency mixer called Samourai and seized the service for allegedly facilitating over $2 billion in illegal transactions and for laundering more than $100 million in criminal proceeds. To that end, Keonne Rodriguez, 35, and William Lonergan Hill, 65, have been charged Newsroomhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Google Postpones Third-Party Cookie Deprecation Amid U.K. Regulatory Scrutiny

25 Duben, 2024 - 08:37
Google has once again pushed its plans to deprecate third-party tracking cookies in its Chrome web browser as it works to address outstanding competition concerns from U.K. regulators over its Privacy Sandbox initiative. The tech giant said it's working closely with the U.K. Competition and Markets Authority (CMA) and hopes to achieve an agreement by the end of the year. As part of theNewsroomhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

State-Sponsored Hackers Exploit Two Cisco Zero-Day Vulnerabilities for Espionage

25 Duben, 2024 - 07:50
A new malware campaign leveraged two zero-day flaws in Cisco networking gear to deliver custom malware and facilitate covert data collection on target environments. Cisco Talos, which dubbed the activity ArcaneDoor, attributed it as the handiwork of a previously undocumented sophisticated state-sponsored actor it tracks under the name UAT4356 (aka Storm-1849 by Microsoft). "UAT4356 Newsroomhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

U.S. Treasury Sanctions Iranian Firms and Individuals Tied to Cyber Attacks

24 Duben, 2024 - 15:43
The U.S. Treasury Department's Office of Foreign Assets Control (OFAC) on Monday sanctioned two firms and four individuals for their involvement in malicious cyber activities on behalf of the Iranian Islamic Revolutionary Guard Corps Cyber Electronic Command (IRGC-CEC) from at least 2016 to April 2021. This includes the front companies Mehrsam Andisheh Saz Nik (MASN) and Dadeh Newsroomhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Researchers Detail Multistage Attack Hijacking Systems with SSLoad, Cobalt Strike

24 Duben, 2024 - 15:36
Cybersecurity researchers have discovered an ongoing attack campaign that's leveraging phishing emails to deliver a malware called SSLoad. The campaign, codenamed FROZEN#SHADOW by Securonix, also involves the deployment of Cobalt Strike and the ConnectWise ScreenConnect remote desktop software. "SSLoad is designed to stealthily infiltrate systems, gather sensitive Newsroomhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Major Security Flaws Expose Keystrokes of Over 1 Billion Chinese Keyboard App Users

24 Duben, 2024 - 11:36
Security vulnerabilities uncovered in cloud-based pinyin keyboard apps could be exploited to reveal users' keystrokes to nefarious actors. The findings come from the Citizen Lab, which discovered weaknesses in eight of nine apps from vendors like Baidu, Honor, iFlytek, OPPO, Samsung, Tencent, Vivo, and Xiaomi. The only vendor whose keyboard app did not have any security Newsroomhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

CISO Perspectives on Complying with Cybersecurity Regulations

24 Duben, 2024 - 11:24
Compliance requirements are meant to increase cybersecurity transparency and accountability. As cyber threats increase, so do the number of compliance frameworks and the specificity of the security controls, policies, and activities they include. For CISOs and their teams, that means compliance is a time-consuming, high-stakes process that demands strong organizational and The Hacker Newshttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

eScan Antivirus Update Mechanism Exploited to Spread Backdoors and Miners

24 Duben, 2024 - 09:02
A new malware campaign has been exploiting the updating mechanism of the eScan antivirus software to distribute backdoors and cryptocurrency miners like XMRig through a long-standing threat codenamed GuptiMiner targeting large corporate networks. Cybersecurity firm Avast said the activity is the work of a threat actor with possible connections to a North Korean hacking group dubbed Newsroomhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

CoralRaider Malware Campaign Exploits CDN Cache to Spread Info-Stealers

24 Duben, 2024 - 06:50
A new ongoing malware campaign has been observed distributing three different stealers, such as CryptBot, LummaC2, and Rhadamanthys hosted on Content Delivery Network (CDN) cache domains since at least February 2024. Cisco Talos has attributed the activity with moderate confidence to a threat actor tracked as CoralRaider, a suspected Vietnamese-origin Newsroomhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Apache Cordova App Harness Targeted in Dependency Confusion Attack

23 Duben, 2024 - 16:00
Researchers have identified a dependency confusion vulnerability impacting an archived Apache project called Cordova App Harness. Dependency confusion attacks take place owing to the fact that package managers check the public repositories before private registries, thus allowing a threat actor to publish a malicious package with the same name to a public package repository. This&
Kategorie: Hacking & Security

Apache Cordova App Harness Targeted in Dependency Confusion Attack

23 Duben, 2024 - 16:00
Researchers have identified a dependency confusion vulnerability impacting an archived Apache project called Cordova App Harness. Dependency confusion attacks take place owing to the fact that package managers check the public repositories before private registries, thus allowing a threat actor to publish a malicious package with the same name to a public package repository. This&Newsroomhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Webinar: Learn Proactive Supply Chain Threat Hunting Techniques

23 Duben, 2024 - 13:28
In the high-stakes world of cybersecurity, the battleground has shifted. Supply chain attacks have emerged as a potent threat, exploiting the intricate web of interconnected systems and third-party dependencies to breach even the most formidable defenses. But what if you could turn the tables and proactively hunt these threats before they wreak havoc? We invite you to join us for an
Kategorie: Hacking & Security

Webinar: Learn Proactive Supply Chain Threat Hunting Techniques

23 Duben, 2024 - 13:28
In the high-stakes world of cybersecurity, the battleground has shifted. Supply chain attacks have emerged as a potent threat, exploiting the intricate web of interconnected systems and third-party dependencies to breach even the most formidable defenses. But what if you could turn the tables and proactively hunt these threats before they wreak havoc? We invite you to join us for an The Hacker Newshttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security