Category: Attack Feeds

0

Iranian and Russian Entities Sanctioned for Election Interference Using AI and Cyber Tactics – [email protected] (The Hacker News)

– [[{“value”:”The U.S. Treasury Department’s Office of Foreign Assets Control (OFAC) on Tuesday leveled sanctions against two entities in Iran and Russia for their attempts to interfere with the November 2024 presidential election. The federal agency said the entities – a subordinate organization of Iran’s Islamic Revolutionary Guard Corps and a Moscow-based affiliate of Russia’s Main Intelligence”}]]  – Read More ...

0

US sanctions Russian, Iranian groups for election interference – djohnson

– [[{“value”:” The U.S. State Department has sanctioned two foreign organizations and one individual who it alleges worked on behalf of Russian and Iranian intelligence agencies to interfere in the 2024 U.S. general election. “These actors sought to stoke sociopolitical tensions and undermine our election institutions during the 2024 U.S. general election,” said State Department Press Secretary Matthew Miller in...

0

After UN adoption, controversial cybercrime treaty’s next steps could prove vital – Tim Starks

– [[{“value”:” A divisive United Nations cybercrime treaty — one that critics say is a huge danger to human rights and that the United States cautiously agreed to advance — is now in the hands of member nations. The U.N. General Assembly adopted the treaty without a vote last week, leaving ratification to individual states. If the past is any...

0

New U.S. DoJ Rule Halts Bulk Data Transfers to Adversarial Nations to Protect Privacy – [email protected] (The Hacker News)

– [[{“value”:”The U.S. Department of Justice (DoJ) has issued a final rule carrying out Executive Order (EO) 14117, which prevents mass transfer of citizens’ personal data to countries of concern such as China (including Hong Kong and Macau), Cuba, Iran, North Korea, Russia, and Venezuela. “This final rule is a crucial step forward in addressing the extraordinary national security threat...

0

Chinese APT Exploits BeyondTrust API Key to Access U.S. Treasury Systems and Documents – [email protected] (The Hacker News)

– [[{“value”:”The United States Treasury Department said it suffered a “major cybersecurity incident” that allowed suspected Chinese threat actors to remotely access some computers and unclassified documents.  “On December 8, 2024, Treasury was notified by a third-party software service provider, BeyondTrust, that a threat actor had gained access to a key used by the vendor to secure a cloud-based”}]]  –...

0

Misconfigured Kubernetes RBAC in Azure Airflow Could Expose Entire Cluster to Exploitation – [email protected] (The Hacker News)

– [[{“value”:”Cybersecurity researchers have uncovered three security weaknesses in Microsoft’s Azure Data Factory Apache Airflow integration that, if successfully exploited, could have allowed an attacker to gain the ability to conduct various covert actions, including data exfiltration and malware deployment. “Exploiting these flaws could allow attackers to gain persistent access as shadow administrators”}]]  – Read More  – The Hacker News 

0

U.S. Army Soldier Arrested in AT&T, Verizon Extortions – BrianKrebs

– [[{“value”:” Federal authorities have arrested and indicted a 20-year-old U.S. Army soldier on suspicion of being Kiberphant0m, a cybercriminal who has been selling and leaking sensitive customer call records stolen earlier this year from AT&T and Verizon. As first reported by KrebsOnSecurity last month, the accused is a communications specialist who was recently stationed in South Korea. One of...

0

Treasury workstations hacked by China-linked threat actors – djohnson

– [[{“value”:” The Department of Treasury was notified earlier this month that several of its workstations were hacked by a group believed to be linked to China, the department confirmed to CyberScoop. According to a letter sent Monday to leaders on the Senate Committee on Banking, Housing and Urban Affairs and obtained by CyberScoop, the compromises occurred through third-party software...

0

Thousands of industrial routers vulnerable to command injection flaw  – djohnson

– [[{“value”:” Thousands of industrial routers from a Chinese telecommunications equipment manufacturer are vulnerable to a post-authentication vulnerability, with indications it is already being exploited in the wild to infect devices with Mirai malware. On Dec. 27, VulnCheck detailed the vulnerability, tracked as CVE-2024-12856, wherein an attacker can leverage default credentials in Four-Faith F3x24 and F3x36 routers to remotely inject...

0

⚡ THN Weekly Recap: Top Cybersecurity Threats, Tools and Tips – [email protected] (The Hacker News)

– [[{“value”:”Every week, the digital world faces new challenges and changes. Hackers are always finding new ways to breach systems, while defenders work hard to keep our data safe. Whether it’s a hidden flaw in popular software or a clever new attack method, staying informed is key to protecting yourself and your organization. In this week’s update, we’ll cover the...

0

New HIPAA Rules Mandate 72-Hour Data Restoration and Annual Compliance Audits – [email protected] (The Hacker News)

– [[{“value”:”The United States Department of Health and Human Services’ (HHS) Office for Civil Rights (OCR) has proposed new cybersecurity requirements for healthcare organizations with an aim to safeguard patients’ data against potential cyber attacks. The proposal, which seeks to modify the Health Insurance Portability and Accountability Act (HIPAA) of 1996, is part of a broader initiative to bolster the”}]] ...

0

When Good Extensions Go Bad: Takeaways from the Campaign Targeting Browser Extensions – [email protected] (The Hacker News)

– News has been making headlines over the weekend of the extensive attack campaign targeting browser extensions and injecting them with malicious code to steal user credentials. Currently, over 25 extensions, with an install base of over two million users, have been found to be compromised, and customers are now working to figure out their exposure (LayerX, one of the...

0

Happy 15th Anniversary, KrebsOnSecurity! – BrianKrebs

– [[{“value”:” Image: Shutterstock, Dreamansions. KrebsOnSecurity.com turns 15 years old today! Maybe it’s indelicate to celebrate the birthday of a cybercrime blog that mostly publishes bad news, but happily many of 2024’s most engrossing security stories were about bad things happening to bad guys. It’s also an occasion to note that despite my publishing fewer stories than ever this past...

0

16 Chrome Extensions Hacked, Exposing Over 600,000 Users to Data Theft – [email protected] (The Hacker News)

– [[{“value”:”A new attack campaign has targeted known Chrome browser extensions, leading to at least 16 extensions being compromised and exposing over 600,000 users to data exposure and credential theft. The attack targeted publishers of browser extensions on the Chrome Web Store via a phishing campaign and used their access permissions to insert malicious code into legitimate extensions in order...

0

Secure Gaming During the Holidays – Owais Sultan

– Secure Gaming during holidays is essential as cyberattacks rise by 50%. Protect accounts with 2FA, avoid fake promotions,…  – Read More  – Hackread – Latest Cybersecurity, Tech, Crypto & Hacking News 

0

Stalking via social media aka Cyberstalking – cyberpro

– [[{“value”:” Stalking via Social Media aka Cyberstalking The mere term “stalking” usually sends a chill down the spine. While in-person stalking might be scary, cyberstalking via social media takes on a whole new problematic level. The internet has given people a far too relaxed attitude regarding sharing personal information and this opens the doors for those […] The post...

0

15,000+ Four-Faith Routers Exposed to New Exploit Due to Default Credentials – [email protected] (The Hacker News)

– [[{“value”:”A high-severity flaw impacting select Four-Faith routers has come under active exploitation in the wild, according to new findings from VulnCheck. The vulnerability, tracked as CVE-2024-12856 (CVSS score: 7.2), has been described as an operating system (OS) command injection bug affecting router models F3x24 and F3x36. The severity of the shortcoming is lower due to the fact that it...

0

White House: Salt Typhoon hacks possible because telecoms lacked basic security measures – Greg Otto

– [[{“value”:” The White House said Friday that as the U.S. government continues to assess the damage caused by the Salt Typhoon hacks, the breach occurred in large part due to telecommunications companies failing to implement rudimentary cybersecurity measures across their IT infrastructure.  Anne Neuberger, the White House’s deputy national security adviser for cyber and emerging technology, told reporters Friday...

0

North Korean Hackers Deploy OtterCookie Malware in Contagious Interview Campaign – [email protected] (The Hacker News)

– [[{“value”:”North Korean threat actors behind the ongoing Contagious Interview campaign have been observed dropping a new JavaScript malware called OtterCookie. Contagious Interview (aka DeceptiveDevelopment) refers to a persistent attack campaign that employs social engineering lures, with the hacking crew often posing as recruiters to trick individuals looking for potential job opportunities into”}]]  – Read More  – The Hacker News 

0

Cloud Atlas Deploys VBCloud Malware: Over 80% of Targets Found in Russia – [email protected] (The Hacker News)

– [[{“value”:”The threat actor known as Cloud Atlas has been observed using a previously undocumented malware called VBCloud as part of its cyber attack campaigns targeting “several dozen users” in 2024. “Victims get infected via phishing emails containing a malicious document that exploits a vulnerability in the formula editor (CVE-2018-0802) to download and execute malware code,” Kaspersky researcher Oleg”}]]  –...

0

FICORA and Kaiten Botnets Exploit Old D-Link Vulnerabilities for Global Attacks – [email protected] (The Hacker News)

– [[{“value”:”Cybersecurity researchers are warning about a spike in malicious activity that involves roping vulnerable D-Link routers into two different botnets, a Mirai variant dubbed FICORA and a Kaiten (aka Tsunami) variant called CAPSAICIN. “These botnets are frequently spread through documented D-Link vulnerabilities that allow remote attackers to execute malicious commands via a GetDeviceSettings”}]]  – Read More  – The Hacker...

0

Palo Alto Releases Patch for PAN-OS DoS Flaw — Update Immediately – [email protected] (The Hacker News)

– [[{“value”:”Palo Alto Networks has disclosed a high-severity vulnerability impacting PAN-OS software that could cause a denial-of-service (DoS) condition on susceptible devices. The flaw, tracked as CVE-2024-3393 (CVSS score: 8.7), impacts PAN-OS versions 10.X and 11.X, as well as Prisma Access running PAN-OS versions. It has been addressed in PAN-OS 10.1.14-h8, PAN-OS 10.2.10-h12, PAN-OS 11.1.5, PAN-OS”}]]  – Read More  –...

0

Apache MINA CVE-2024-52046: CVSS 10.0 Flaw Enables RCE via Unsafe Serialization – [email protected] (The Hacker News)

– [[{“value”:”The Apache Software Foundation (ASF) has released patches to address a maximum severity vulnerability in the MINA Java network application framework that could result in remote code execution under specific conditions. Tracked as CVE-2024-52046, the vulnerability carries a CVSS score of 10.0. It affects versions 2.0.X, 2.1.X, and 2.2.X. “The ObjectSerializationDecoder in Apache MINA uses Java’s”}]]  – Read More ...

0

South Korea sanctions 15 North Koreans for IT worker scams, financial hacking schemes – djohnson

– [[{“value”:” The South Korean government has sanctioned more than a dozen individuals and one organization for a wide-ranging global scheme to fund North Korea’s nuclear and missile programs through impersonating IT workers abroad, stealing cryptocurrency and facilitating cyberattacks. South Korean officials on Thursday identified 15 North Korean nationals and the Chosun Geumjeong Economic Information Technology Exchange Corporation for economic...

0

Brazilian Hacker Charged for Extorting $3.2M in Bitcoin After Breaching 300,000 Accounts – [email protected] (The Hacker News)

– [[{“value”:”A Brazilian citizen has been charged in the United States for allegedly threatening to release data stolen by hacking into a company’s network in March 2020. Junior Barros De Oliveira, 29, of Curitiba, Brazil has been charged with four counts of extortionate threats involving information obtained from protected computers and four counts of threatening communications, the U.S. Department of”}]] ...

0

Critical SQL Injection Vulnerability in Apache Traffic Control Rated 9.9 CVSS — Patch Now – [email protected] (The Hacker News)

– [[{“value”:”The Apache Software Foundation (ASF) has shipped security updates to address a critical security flaw in Traffic Control that, if successfully exploited, could allow an attacker to execute arbitrary Structured Query Language (SQL) commands in the database. The SQL injection vulnerability, tracked as CVE-2024-45387, is rated 9.9 out of 10.0 on the CVSS scoring system. “An SQL injection”}]]  –...

0

Ruijie Networks’ Cloud Platform Flaws Could Expose 50,000 Devices to Remote Attacks – [email protected] (The Hacker News)

– [[{“value”:”Cybersecurity researchers have discovered several security flaws in the cloud management platform developed by Ruijie Networks that could permit an attacker to take control of the network appliances. “These vulnerabilities affect both the Reyee platform, as well as Reyee OS network devices,” Claroty researchers Noam Moshe and Tomer Goldschmidt said in a recent analysis. “The vulnerabilities, if”}]]  – Read...

0

Iran’s Charming Kitten Deploys BellaCPP: A New C++ Variant of BellaCiao Malware – [email protected] (The Hacker News)

– [[{“value”:”The Iranian nation-state hacking group known as Charming Kitten has been observed deploying a C++ variant of a known malware called BellaCiao. Russian cybersecurity company Kaspersky, which dubbed the new version BellaCPP, said it discovered the artifact as part of a “recent” investigation into a compromised machine in Asia that was also infected with the BellaCiao malware. BellaCiao was...

0

The AI Fix #30: ChatGPT reveals the devastating truth about Santa (Merry Christmas!) – Graham Cluley

– [[{“value”:”In episode 30 of The AI Fix, AIs are caught lying to avoid being turned off, Apple’s AI flubs a headline, ChatGPT is available to people who haven’t left the 1970s, our hosts regret to inform you that an AI artist now has a personality, and ant-like robots join forces to lob each other over things. Graham discovers that...

0

Researchers Uncover PyPI Packages Stealing Keystrokes and Hijacking Social Accounts – [email protected] (The Hacker News)

– [[{“value”:”Cybersecurity researchers have flagged two malicious packages that were uploaded to the Python Package Index (PyPI) repository and came fitted with capabilities to exfiltrate sensitive information from compromised hosts, according to new findings from Fortinet FortiGuard Labs. The packages, named zebo and cometlogger, attracted 118 and 164 downloads each, prior to them being taken down.”}]]  – Read More  –...

0

CISA Adds Acclaim USAHERDS Vulnerability to KEV Catalog Amid Active Exploitation – [email protected] (The Hacker News)

– [[{“value”:”The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added a now-patched high-severity security flaw impacting Acclaim Systems USAHERDS to the Known Exploited Vulnerabilities (KEV) catalog, based on evidence of active exploitation in the wild. The vulnerability in question is CVE-2021-44207 (CVSS score: 8.1), a case of hard-coded, static credentials in Acclaim USAHERDS that”}]]  – Read More  –...

0

North Korean Hackers Pull Off $308M Bitcoin Heist from Crypto Firm DMM Bitcoin – [email protected] (The Hacker News)

– [[{“value”:”Japanese and U.S. authorities have formerly attributed the theft of cryptocurrency worth $308 million from cryptocurrency company DMM Bitcoin in May 2024 to North Korean cyber actors. “The theft is affiliated with TraderTraitor threat activity, which is also tracked as Jade Sleet, UNC4899, and Slow Pisces,” the agencies said. “TraderTraitor activity is often characterized by targeted social”}]]  – Read...

0

Apache Tomcat Vulnerability CVE-2024-56337 Exposes Servers to RCE Attacks – [email protected] (The Hacker News)

– [[{“value”:”The Apache Software Foundation (ASF) has released a security update to address an important vulnerability in its Tomcat server software that could result in remote code execution (RCE) under certain conditions. The vulnerability, tracked as CVE-2024-56337, has been described as an incomplete mitigation for CVE-2024-50379 (CVSS score: 9.8), another critical security flaw in the same product that”}]]  – Read...