Category: Attack Feeds

0

Researchers Uncover Backdoor in Solana’s Popular Web3.js npm Library – [email protected] (The Hacker News)

– [[{“value”:”Cybersecurity researchers are alerting to a software supply chain attack targeting the popular @solana/web3.js npm library that involved pushing two malicious versions capable of harvesting users’ private keys with an aim to drain their cryptocurrency wallets. The attack has been detected in versions 1.95.6 and 1.95.7. Both these versions are no longer available for download from the npm”}]]  –...

0

Joint Advisory Warns of PRC-Backed Cyber Espionage Targeting Telecom Networks – [email protected] (The Hacker News)

– [[{“value”:”A joint advisory issued by Australia, Canada, New Zealand, and the U.S. has warned of a broad cyber espionage campaign undertaken by People’s Republic of China (PRC)-affiliated threat actors targeting telecommunications providers. “Identified exploitations or compromises associated with these threat actors’ activity align with existing weaknesses associated with victim infrastructure; no novel”}]]  – Read More  – The Hacker News 

0

Hackers Use Corrupted ZIPs and Office Docs to Evade Antivirus and Email Defenses – [email protected] (The Hacker News)

– [[{“value”:”Cybersecurity researchers have called attention to a novel phishing campaign that leverages corrupted Microsoft Office documents and ZIP archives as a way to bypass email defenses. “The ongoing attack evades #antivirus software, prevents uploads to sandboxes, and bypasses Outlook’s spam filters, allowing the malicious emails to reach your inbox,” ANY.RUN said in a series of posts on X. The”}]] ...

0

Critical SailPoint IdentityIQ Vulnerability Exposes Files to Unauthorized Access – [email protected] (The Hacker News)

– [[{“value”:”A critical security vulnerability has been disclosed in SailPoint’s IdentityIQ identity and access management (IAM) software that allows unauthorized access to content stored within the application directory. The flaw, tracked as CVE-2024-10905, has a CVSS score of 10.0, indicating maximum severity. It affects IdentityIQ versions 8.2. 8.3, 8.4, and other previous versions. IdentityIQ “allows”}]]  – Read More  – The...

0

Veeam Issues Patch for Critical RCE Vulnerability in Service Provider Console – [email protected] (The Hacker News)

– [[{“value”:”Veeam has released security updates to address a critical flaw impacting Service Provider Console (VSPC) that could pave the way for remote code execution on susceptible instances. The vulnerability, tracked as CVE-2024-42448, carries a CVSS score of 9.9 out of a maximum of 10.0. The company noted that the bug was identified during internal testing. “From the VSPC management...

0

Dark Web Hydra Market Mastermind Sentenced to Life by Russia – Deeba Ahmed

– Stanislav Moiseyev, the organizer of the notorious Hydra Market, has been sentenced to life imprisonment by a Moscow court. Learn about the massive scale of this dark web marketplace and the international efforts to dismantle it.  – Read More  – Hackread – Latest Cybersecurity, Tech, Crypto & Hacking News 

0

U.S. government says Salt Typhoon is still in telecom networks – Tim Starks

– [[{“value”:” Telecommunications providers are still trying to evict the Chinese government-linked hackers behind a monumental and sweeping breach that the government began investigating this spring, U.S. administration officials said Tuesday, while also providing guidance they believe can attempt to kick the attackers off the network for good.  Government agencies are also still grappling with the attack’s full scope, the officials told...

0

FTC goes after three data brokers with enforcement actions – Greg Otto

– [[{“value”:” The Federal Trade Commission took action against three data brokers Tuesday, alleging the companies unlawfully tracked and sold sensitive consumer location data, including information that related to people’s visits to health care facilities and places of worship. The FTC’s complaint accuses Virginia-based Gravy Analytics and its subsidiary Venntel of violating the FTC Act by allegedly obtaining consumer location...

0

Why Phishers Love New TLDs Like .shop, .top and .xyz – BrianKrebs

– [[{“value”:” Phishing attacks increased nearly 40 percent in the year ending August 2024, with much of that growth concentrated at a small number of new generic top-level domains (gTLDs) — such as .shop, .top, .xyz — that attract scammers with rock-bottom prices and no meaningful registration requirements, new research finds. Meanwhile, the nonprofit entity that oversees the domain name...

0

Detailing the Attack Surfaces of the WolfBox E40 EV Charger – Dmitry Janushkevich

– [[{“value”:” The WolfBox E40 is a Level 2 electric vehicle charge station designed for residential home use. Its hardware has a minimal user interface, providing a Bluetooth Low Energy (BLE) interface for configuration and an NFC reader for user authentication. Typical for this class of devices, the appliance employs a mobile application for the owner’s installation and regular operation...

0

Inside a new initiative to lend cybersecurity volunteers to organizations that need it most – Tim Starks

– [[{“value”:” A cybersecurity volunteering initiative is launching Tuesday in a bid to aid vulnerable organizations that have few resources — like schools and nonprofits — by leveraging potentially thousands of cyber pros who can provide free expertise. The University of California, Berkeley’s Center for Long-Term Cybersecurity and the CyberPeace Institute are leading the project dubbed the Cyber Resilience Corps,...

0

The AI Fix #27: Why is AI full of real-life Bond villains? – Graham Cluley

– [[{“value”:”In episode 27 of The AI Fix, robots catch a ball, lead a revolt, and enjoy a juicy steak. Or do they? Graham struggles with a Micro USB cable, a student struggles with a school’s anti-AI rules, and OpenAI’s Sora video generation AI is leaked by hacktivists. Graham circles back into an outside-the-box deep-dive where he synergises the low-hanging...

0

Cisco Warns of Exploitation of Decade-Old ASA WebVPN Vulnerability – [email protected] (The Hacker News)

– [[{“value”:”Cisco on Monday updated an advisory to warn customers of active exploitation of a decade-old security flaw impacting its Adaptive Security Appliance (ASA). The vulnerability, tracked as CVE-2014-2120 (CVSS score: 4.3), concerns a case of insufficient input validation in ASA’s WebVPN login page that could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack”}]]  – Read...

0

NachoVPN Tool Exploits Flaws in Popular VPN Clients for System Compromise – [email protected] (The Hacker News)

– [[{“value”:”Cybersecurity researchers have disclosed a set of flaws impacting Palo Alto Networks and SonicWall virtual private network (VPN) clients that could be potentially exploited to gain remote code execution on Windows and macOS systems. “By targeting the implicit trust VPN clients place in servers, attackers can manipulate client behaviours, execute arbitrary commands, and gain high levels of access”}]]  –...

0

No guarantees of payday for ransomware gang that claims to have hacked children’s hospital – Graham Cluley

– [[{“value”:”What is the point of INC Ransom’s attack on Alder Hey? They are not likely to be paid, and the attack on a children’s hospital only increases the chances that they will one day find their collars felt by law enforcement. Read more in my article on the Hot for Security blog.”}]]  – Read More  – Graham Cluley 

0

CFPB proposes new rule to regulate expansive data broker industry – Greg Otto

– [[{“value”:” In an era where personal data is increasingly commodified, the Consumer Financial Protection Bureau (CFPB) is attempting to regulate the sprawling industry of data brokers. A newly proposed rule released Tuesday aims to put data brokers in line with the Fair Credit Reporting Act (FCRA), ensuring accountability and consumer privacy amid widespread security issues. Initially established in 1970,...

0

North Korean Kimsuky Hackers Use Russian Email Addresses for Credential Theft Attacks – [email protected] (The Hacker News)

– [[{“value”:”The North Korea-aligned threat actor known as Kimsuky has been linked to a series of phishing attacks that involve sending email messages that originate from Russian sender addresses to ultimately conduct credential theft. “Phishing emails were sent mainly through email services in Japan and Korea until early September,” South Korean cybersecurity company Genians said. “Then, from mid-September,”}]]  – Read...

0

Best Ways to Reduce Your Digital Footprint Now – [email protected]

– [[{“value”:” Every activity you perform online, whether it is commenting on a news article, sharing something on social media or your shopping preferences leaves a digital footprint. This digital trail helps organizations find more about you. And while it does offer a certain degree of convenience, it can be a real hazard to your online privacy. Fortunately, there are...

0

Horns&Hooves Campaign Delivers RATs via Fake Emails and JavaScript Payloads – [email protected] (The Hacker News)

– [[{“value”:”A newly discovered malware campaign has been found to target private users, retailers, and service businesses mainly located in Russia to deliver NetSupport RAT and BurnsRAT. The campaign, dubbed Horns&Hooves by Kaspersky, has hit more than 1,000 victims since it began around March 2023. The end goal of these attacks is to leverage the access afforded by these trojans...

0

Small number of vulnerabilities patched in last Android security update of 2024 – Greg Otto

– [[{“value”:” Google on Monday released its December 2024 Android Security Bulletin, detailing a range of security vulnerabilities affecting various components across Android devices, with some potentially allowing remote code execution and local escalation of privileges. The bulletin’s most critical concern centers on vulnerabilities within the system components, which allow developers to build applications with specific functionalities within the Android...

0

Notorious ransomware developer charged with computer crimes in Russia – Greg Otto

– [[{“value”:” Russian authorities have charged Mikhail Matveev, a notorious hacker known as Wazawaka, for creating malware used to extort commercial organizations, the Russian Interior Ministry announced last week. Matveev, linked to ransomware groups such as Babuk, Conti, DarkSide, Hive, and LockBit, faces charges under Russia’s Criminal Code for the creation or distribution of software intended to damage or manipulate...

0

SmokeLoader Malware Resurfaces, Targeting Manufacturing and IT in Taiwan – [email protected] (The Hacker News)

– [[{“value”:”Taiwanese entities in manufacturing, healthcare, and information technology sectors have become the target of a new campaign distributing the SmokeLoader malware. “SmokeLoader is well-known for its versatility and advanced evasion techniques, and its modular design allows it to perform a wide range of attacks,” Fortinet FortiGuard Labs said in a report shared with The Hacker News. “While”}]]  – Read...

0

THN Recap: Top Cybersecurity Threats, Tools and Tips (Nov 25 – Dec 1) – [email protected] (The Hacker News)

– [[{“value”:”Ever wonder what happens in the digital world every time you blink? Here’s something wild – hackers launch about 2,200 attacks every single day, which means someone’s trying to break into a system somewhere every 39 seconds. And get this – while we’re all worried about regular hackers, there are now AI systems out there that can craft phishing...

0

A Guide to Securing AI App Development: Join This Cybersecurity Webinar – [email protected] (The Hacker News)

– [[{“value”:”Artificial Intelligence (AI) is no longer a far-off dream—it’s here, changing the way we live. From ordering coffee to diagnosing diseases, it’s everywhere. But while you’re creating the next big AI-powered app, hackers are already figuring out ways to break it. Every AI app is an opportunity—and a potential risk. The stakes are huge: data leaks, downtime, and even...

0

8 Million Android Users Hit by SpyLoan Malware in Loan Apps on Google Play – [email protected] (The Hacker News)

– [[{“value”:”Over a dozen malicious Android apps identified on the Google Play Store that have been collectively downloaded over 8 million times contain malware known as SpyLoan, according to new findings from McAfee Labs. “These PUP (potentially unwanted programs) applications use social engineering tactics to trick users into providing sensitive information and granting extra mobile app permissions, which”}]]  – Read...

0

INTERPOL Arrests 5,500 in Global Cybercrime Crackdown, Seizes Over $400 Million – [email protected] (The Hacker News)

– [[{“value”:”A global law enforcement operation has led to the arrest of more than 5,500 suspects involved in financial crimes and the seizure of more than $400 million in virtual assets and government-backed currencies. The coordinated exercise saw the participation of authorities from 40 countries, territories, and regions as part of the latest wave of Operation HAECHI-V, which took place...

0

Wanted Russian Cybercriminal Linked to Hive and LockBit Ransomware Has Been Arrested – [email protected] (The Hacker News)

– [[{“value”:”A Russian cybercriminal wanted in the U.S. in connection with LockBit and Hive ransomware operations has been arrested by law enforcement authorities in the country. According to a news report from Russian media outlet RIA Novosti, Mikhail Pavlovich Matveev has been accused of developing a malicious program designed to encrypt files and seek ransom in return for a decryption...

0

Fake Betting Apps Using AI-Generated Voices to Sensitive Data – Deeba Ahmed

– Group-IB has discovered that cybercriminals are using fake betting apps and ads with AI-generated voices to steal personal information and money. Discover the tactics used by scammers and how to avoid falling victim to these fraudulent schemes.  – Read More  – Hackread – Latest Cybersecurity, Tech, Crypto & Hacking News 

0

AI-Powered Fake News Campaign Targets Western Support for Ukraine and U.S. Elections – [email protected] (The Hacker News)

– [[{“value”:”A Moscow-based company sanctioned by the U.S. earlier this year has been linked to yet another influence operation designed to turn public opinion against Ukraine and erode Western support since at least December 2023. The covert campaign undertaken by Social Design Agency (SDA), leverages videos enhanced using artificial intelligence (AI) and bogus websites impersonating reputable news sources”}]]  – Read...

0

Protecting Tomorrow’s World: Shaping the Cyber-Physical Future – [email protected] (The Hacker News)

– The lines between digital and physical realms increasingly blur. While this opens countless opportunities for businesses, it also brings numerous challenges. In our recent webinar, Shaping the Cyber-Physical Future: Trends, Challenges, and Opportunities for 2025, we explored the different factors shaping the cyber-physical future. In an insightful conversation with industry experts, we discussed  – Read More  – The Hacker...

0

Microsoft Fixes AI, Cloud, and ERP Security Flaws; One Exploited in Active Attacks – [email protected] (The Hacker News)

– [[{“value”:”Microsoft has addressed four security flaws impacting its artificial intelligence (AI), cloud, enterprise resource planning, and Partner Center offerings, including one that it said has been exploited in the wild. The vulnerability that has been tagged with an “Exploitation Detected” assessment is CVE-2024-49035 (CVSS score: 8.7), a privilege escalation flaw in partner.microsoft[.]com. “An”}]]  – Read More  – The Hacker...