Category: Attack Feeds

Critical SQL Injection Vulnerability in Apache Traffic Control Rated 9.9 CVSS — Patch Now – [email protected] (The Hacker News)

– [[{“value”:”The Apache Software Foundation (ASF) has shipped security updates to address a critical security flaw in Traffic Control that, if successfully exploited, could allow an attacker to execute arbitrary Structured Query Language (SQL) commands in the database. The SQL injection vulnerability, tracked as CVE-2024-45387, is rated 9.9 out of 10.0 on the CVSS scoring system. “An SQL injection”}]]  –...

Ruijie Networks’ Cloud Platform Flaws Could Expose 50,000 Devices to Remote Attacks – [email protected] (The Hacker News)

– [[{“value”:”Cybersecurity researchers have discovered several security flaws in the cloud management platform developed by Ruijie Networks that could permit an attacker to take control of the network appliances. “These vulnerabilities affect both the Reyee platform, as well as Reyee OS network devices,” Claroty researchers Noam Moshe and Tomer Goldschmidt said in a recent analysis. “The vulnerabilities, if”}]]  – Read...

Iran’s Charming Kitten Deploys BellaCPP: A New C++ Variant of BellaCiao Malware – [email protected] (The Hacker News)

– [[{“value”:”The Iranian nation-state hacking group known as Charming Kitten has been observed deploying a C++ variant of a known malware called BellaCiao. Russian cybersecurity company Kaspersky, which dubbed the new version BellaCPP, said it discovered the artifact as part of a “recent” investigation into a compromised machine in Asia that was also infected with the BellaCiao malware. BellaCiao was...

The AI Fix #30: ChatGPT reveals the devastating truth about Santa (Merry Christmas!) – Graham Cluley

– [[{“value”:”In episode 30 of The AI Fix, AIs are caught lying to avoid being turned off, Apple’s AI flubs a headline, ChatGPT is available to people who haven’t left the 1970s, our hosts regret to inform you that an AI artist now has a personality, and ant-like robots join forces to lob each other over things. Graham discovers that...

Researchers Uncover PyPI Packages Stealing Keystrokes and Hijacking Social Accounts – [email protected] (The Hacker News)

– [[{“value”:”Cybersecurity researchers have flagged two malicious packages that were uploaded to the Python Package Index (PyPI) repository and came fitted with capabilities to exfiltrate sensitive information from compromised hosts, according to new findings from Fortinet FortiGuard Labs. The packages, named zebo and cometlogger, attracted 118 and 164 downloads each, prior to them being taken down.”}]]  – Read More  –...

CISA Adds Acclaim USAHERDS Vulnerability to KEV Catalog Amid Active Exploitation – [email protected] (The Hacker News)

– [[{“value”:”The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added a now-patched high-severity security flaw impacting Acclaim Systems USAHERDS to the Known Exploited Vulnerabilities (KEV) catalog, based on evidence of active exploitation in the wild. The vulnerability in question is CVE-2021-44207 (CVSS score: 8.1), a case of hard-coded, static credentials in Acclaim USAHERDS that”}]]  – Read More  –...

North Korean Hackers Pull Off $308M Bitcoin Heist from Crypto Firm DMM Bitcoin – [email protected] (The Hacker News)

– [[{“value”:”Japanese and U.S. authorities have formerly attributed the theft of cryptocurrency worth $308 million from cryptocurrency company DMM Bitcoin in May 2024 to North Korean cyber actors. “The theft is affiliated with TraderTraitor threat activity, which is also tracked as Jade Sleet, UNC4899, and Slow Pisces,” the agencies said. “TraderTraitor activity is often characterized by targeted social”}]]  – Read...

Apache Tomcat Vulnerability CVE-2024-56337 Exposes Servers to RCE Attacks – [email protected] (The Hacker News)

– [[{“value”:”The Apache Software Foundation (ASF) has released a security update to address an important vulnerability in its Tomcat server software that could result in remote code execution (RCE) under certain conditions. The vulnerability, tracked as CVE-2024-56337, has been described as an incomplete mitigation for CVE-2024-50379 (CVSS score: 9.8), another critical security flaw in the same product that”}]]  – Read...

State Department’s disinformation office to close after funding nixed in NDAA – djohnson

– [[{“value”:” The State Department’s center for fighting global disinformation received a lump of coal in its Christmas stocking this week as congressional lawmakers excluded new funding and authorization for the office beyond this year. The Global Engagement Center, which tracks foreign disinformation, will lose  its authority on Dec. 24. Despite a concerted push by State officials to lobby Congress...

Judge grants ruling in favor of WhatsApp against spyware firm NSO Group – Tim Starks

– [[{“value”:” A federal judge has dealt the first major legal blow against spyware maker NSO Group, ruling in favor of WhatsApp in a five-year-old lawsuit against the Israeli firm over allegations that it hacked the chat service. Northern California District Court Judge Phyllis Hamilton made her ruling on Friday as a summary judgment, thus not requiring a full trial....

Feds lay blame while Chinese telecom attack continues – Greg Otto

– [[{“value”:” The United States’ telecommunications infrastructure has been infiltrated by actors affiliated with China. Some of our nation’s most powerful leaders have been targeted — including President-elect Donald Trump and Vice President-elect JD Vance. This is one of the most severe cybersecurity incidents against telecom the United States has ever been subject to, and — worse yet — it...

⚡ THN Weekly Recap: Top Cybersecurity Threats, Tools and Tips – [email protected] (The Hacker News)

– [[{“value”:”The online world never takes a break, and this week shows why. From ransomware creators being caught to hackers backed by governments trying new tricks, the message is clear: cybercriminals are always changing how they attack, and we need to keep up. Hackers are using everyday tools in harmful ways, hiding spyware in trusted apps, and finding new ways...

AI Could Generate 10,000 Malware Variants, Evading Detection in 88% of Case – [email protected] (The Hacker News)

– [[{“value”:”Cybersecurity researchers have found that it’s possible to use large language models (LLMs) to generate new variants of malicious JavaScript code at scale in a manner that can better evade detection. “Although LLMs struggle to create malware from scratch, criminals can easily use them to rewrite or obfuscate existing malware, making it harder to detect,” Palo Alto Networks Unit...

Rockstar2FA Collapse Fuels Expansion of FlowerStorm Phishing-as-a-Service – [email protected] (The Hacker News)

– [[{“value”:”An interruption to the phishing-as-a-service (PhaaS) toolkit called Rockstar 2FA has led to a rapid uptick in activity from another nascent offering named FlowerStorm. “It appears that the [Rockstar2FA] group running the service experienced at least a partial collapse of its infrastructure, with pages associated with the service no longer reachable,” Sophos said in a new report published last”}]] ...

Top 10 Cybersecurity Trends to Expect in 2025 – [email protected] (The Hacker News)

– The 2025 cybersecurity landscape is increasingly complex, driven by sophisticated cyber threats, increased regulation, and rapidly evolving technology. In 2025, organizations will be challenged with protecting sensitive information for their customers while continuing to provide seamless and easy user experiences. Here’s a closer look at ten emerging challenges and threats set to shape the  – Read More  – The...

U.S. Judge Rules Against NSO Group in WhatsApp Pegasus Spyware Case – [email protected] (The Hacker News)

– [[{“value”:”Meta Platforms-owned WhatsApp scored a major legal victory in its fight against Israeli commercial spyware vendor NSO Group after a federal judge in the U.S. state of California ruled in favor of the messaging giant for exploiting a security vulnerability to deliver Pegasus. “The limited evidentiary record before the court does show that defendants’ Pegasus code was sent through...

Italy Fines OpenAI €15 Million for ChatGPT GDPR Data Privacy Violations – [email protected] (The Hacker News)

– [[{“value”:”Italy’s data protection authority has fined ChatGPT maker OpenAI a fine of €15 million ($15.66 million) over how the generative artificial intelligence application handles personal data. The fine comes nearly a year after the Garante found that ChatGPT processed users’ information to train its service in violation of the European Union’s General Data Protection Regulation (GDPR). The authority”}]]  –...

LockBit Developer Rostislav Panev Charged for Billions in Global Ransomware Damages – [email protected] (The Hacker News)

– [[{“value”:”A dual Russian and Israeli national has been charged in the United States for allegedly being the developer of the now-defunct LockBit ransomware-as-a-service (RaaS) operation since its inception in or around 2019 through at least February 2024. Rostislav Panev, 51, was arrested in Israel earlier this August and is currently awaiting extradition, the U.S. Department of Justice (DoJ) said...

Justice Department unveils charges against alleged LockBit developer – Greg Otto

– [[{“value”:” The U.S. Department of Justice revealed charges Friday against Rostislav Panev, a dual Russian and Israeli national, for his alleged role as a developer in the notorious LockBit ransomware group. Panev was arrested in Israel following a U.S. provisional arrest request and is currently awaiting extradition. Authorities allege that Panev has been an instrumental figure in LockBit’s operations...

Builder.ai Database Misconfiguration Exposes 1.29 TB of Unsecured Records – Waqas

– Cybersecurity researcher Jeremiah Fowler discovered a 1.2TB database containing over 3 million records of Builder.ai, a London-based AI software and app development company. Discover the risks, lessons learned, and best practices for data security.  – Read More  – Hackread – Latest Cybersecurity, Tech, Crypto & Hacking News 

Lazarus Group Spotted Targeting Nuclear Engineers with CookiePlus Malware – [email protected] (The Hacker News)

– [[{“value”:”The Lazarus Group, an infamous threat actor linked to the Democratic People’s Republic of Korea (DPRK), has been observed leveraging a “complex infection chain” targeting at least two employees belonging to an unnamed nuclear-related organization within the span of one month in January 2024. The attacks, which culminated in the deployment of a new modular backdoor referred to as...

Sophos Issues Hotfixes for Critical Firewall Flaws: Update to Prevent Exploitation – [email protected] (The Hacker News)

– [[{“value”:”Sophos has released hotfixes to address three security flaws in Sophos Firewall products that could be exploited to achieve remote code execution and allow privileged system access under certain conditions. Of the three, two are rated Critical in severity. There is currently no evidence that the shortcomings have been exploited in the wild. The list of vulnerabilities is as...

Rspack npm Packages Compromised with Crypto Mining Malware in Supply Chain Attack – [email protected] (The Hacker News)

– [[{“value”:”The developers of Rspack have revealed that two of their npm packages, @rspack/core and @rspack/cli, were compromised in a software supply chain attack that allowed a malicious actor to publish malicious versions to the official package registry with cryptocurrency mining malware. Following the discovery, versions 1.1.7 of both libraries have been unpublished from the npm registry. The latest”}]]  –...

Hackers Exploiting Critical Fortinet EMS Vulnerability to Deploy Remote Access Tools – [email protected] (The Hacker News)

– [[{“value”:”A now-patched critical security flaw impacting Fortinet FortiClient EMS is being exploited by malicious actors as part of a cyber campaign that installed remote desktop software such as AnyDesk and ScreenConnect.  The vulnerability in question is CVE-2023-48788 (CVSS score: 9.3), an SQL injection bug that allows attackers to execute unauthorized code or commands by sending specially crafted”}]]  – Read...

CISA Adds Critical Flaw in BeyondTrust Software to Exploited Vulnerabilities List – [email protected] (The Hacker News)

– [[{“value”:”The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Thursday added a critical security flaw impacting BeyondTrust Privileged Remote Access (PRA) and Remote Support (RS) products to the Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation in the wild. The vulnerability, tracked as CVE-2024-12356 (CVSS score: 9.8), is a command injection flaw that”}]]  – Read More  –...

Study finds ‘significant uptick’ in cybersecurity disclosures to SEC – Greg Otto

– [[{“value”:” The introduction of new cybersecurity disclosure rules by the U.S. Securities and Exchange Commission has led to a significant uptick in the number of reported cybersecurity incidents from public companies, according to a leading U.S. law firm that specializes in finance and M&A activity. Analysis by Paul Hastings LLP found that since the disclosure law went into effect...

Israeli court to hear U.S. extradition request for alleged LockBit developer – Greg Otto

– [[{“value”:” An Israeli Court is set to deliberate a significant extradition case involving Rostislav Panev, an Israeli citizen alleged to be involved with the notorious LockBit ransomware gang. According to Israeli news outlet Ynet, a U.S. extradition request was made public Thursday claiming that between 2019 and 2024, Panev served as a software developer for LockBit. During this period,...

Web Hacking Service ‘Araneida’ Tied to Turkish IT Firm – BrianKrebs

– [[{“value”:” Cybercriminals are selling hundreds of thousands of credential sets stolen with the help of a cracked version of Acunetix, a powerful commercial web app vulnerability scanner, new research finds. The cracked software is being resold as a cloud-based attack tool by at least two different services, one of which KrebsOnSecurity traced to an information technology firm based in...

Chinese cyber center points finger at U.S. over alleged cyberattacks to steal trade secrets – Tim Starks

– [[{“value”:” China’s national cyber incident response center accused the U.S. government of launching cyberattacks against two Chinese tech companies in a bid to steal trade secrets. In a notice Wednesday, the National Computer Network Emergency Response Technical Team/Coordination Center of China (CNCERT) said a suspected U.S. intelligence agency was behind the attacks, and that CNCERT had “handled” them, according...

Smashing Security podcast #398: Fake CAPTCHAs, Harmageddon, and Krispy Kreme – Graham Cluley

– [[{“value”:”This week, we delve into the dark world of fake CAPTCHAs designed to hijack your computer. Plus, the AI safety clock is ticking down – is doomsday closer than we think? And to top it off, we uncover the sticky situation of Krispy Kreme facing a ransomware attack. All this and more is discussed in the latest jam-packed edition...

Ukrainian sentenced to five years in jail for work on Raccoon Stealer – Greg Otto

– [[{“value”:” Ukrainian national Mark Sokolovsky was sentenced Wednesday to five years in federal prison for his role in operating Raccoon Infostealer malware, which infiltrated millions of computers worldwide to steal personal data. According to court documents, Sokolovsky, 28, was integral to operations that allowed the leasing of Raccoon Infostealer for $200 per month, payable via cryptocurrency. Users predominantly deployed...

Thousands Download Malicious npm Libraries Impersonating Legitimate Tools – [email protected] (The Hacker News)

– [[{“value”:”Threat actors have been observed uploading malicious typosquats of legitimate npm packages such as typescript-eslint and @types/node that have racked up thousands of downloads on the package registry. The counterfeit versions, named @typescript_eslinter/eslint and types-node, are engineered to download a trojan and retrieve second-stage payloads, respectively. “While typosquatting attacks are”}]]  – Read More  – The Hacker News 

Juniper Warns of Mirai Botnet Targeting SSR Devices with Default Passwords – [email protected] (The Hacker News)

– [[{“value”:”Juniper Networks is warning that Session Smart Router (SSR) products with default passwords are being targeted as part of a malicious campaign that deploys the Mirai botnet malware. The company said it’s issuing the advisory after “several customers” reported anomalous behavior on their Session Smart Network (SSN) platforms on December 11, 2024. “These systems have been infected with the...

Fortinet Warns of Critical FortiWLM Flaw That Could Lead to Admin Access Exploits – [email protected] (The Hacker News)

– [[{“value”:”Fortinet has issued an advisory for a now-patched critical security flaw impacting Wireless LAN Manager (FortiWLM) that could lead to disclosure of sensitive information. The vulnerability, tracked as CVE-2023-34990, carries a CVSS score of 9.6 out of a maximum of 10.0. “A relative path traversal [CWE-23] in FortiWLM may allow a remote unauthenticated attacker to read sensitive files,” the”}]] ...

UAC-0125 Abuses Cloudflare Workers to Distribute Malware Disguised as Army+ App – [email protected] (The Hacker News)

– [[{“value”:”The Computer Emergency Response Team of Ukraine (CERT-UA) has disclosed that a threat actor it tracks as UAC-0125 is leveraging Cloudflare Workers service to trick military personnel in the country into downloading malware disguised as Army+, a mobile app that was introduced by the Ministry of Defence back in August 2024 in an effort to make the armed forces...

Dutch DPA Fines Netflix €4.75 Million for GDPR Violations Over Data Transparency – [email protected] (The Hacker News)

– [[{“value”:”The Dutch Data Protection Authority (DPA) on Wednesday fined video on-demand streaming service Netflix €4.75 million ($4.93 million) for not giving consumers enough information about how it used their data between 2018 and 2020. An investigation launched by the DPA in 2019 found that the tech giant did not inform customers clearly enough in its privacy statement about what...