Category: Attack Feeds

0

State Department’s disinformation office to close after funding nixed in NDAA – djohnson

– [[{“value”:” The State Department’s center for fighting global disinformation received a lump of coal in its Christmas stocking this week as congressional lawmakers excluded new funding and authorization for the office beyond this year. The Global Engagement Center, which tracks foreign disinformation, will lose  its authority on Dec. 24. Despite a concerted push by State officials to lobby Congress...

0

Judge grants ruling in favor of WhatsApp against spyware firm NSO Group – Tim Starks

– [[{“value”:” A federal judge has dealt the first major legal blow against spyware maker NSO Group, ruling in favor of WhatsApp in a five-year-old lawsuit against the Israeli firm over allegations that it hacked the chat service. Northern California District Court Judge Phyllis Hamilton made her ruling on Friday as a summary judgment, thus not requiring a full trial....

0

Feds lay blame while Chinese telecom attack continues – Greg Otto

– [[{“value”:” The United States’ telecommunications infrastructure has been infiltrated by actors affiliated with China. Some of our nation’s most powerful leaders have been targeted — including President-elect Donald Trump and Vice President-elect JD Vance. This is one of the most severe cybersecurity incidents against telecom the United States has ever been subject to, and — worse yet — it...

0

⚡ THN Weekly Recap: Top Cybersecurity Threats, Tools and Tips – [email protected] (The Hacker News)

– [[{“value”:”The online world never takes a break, and this week shows why. From ransomware creators being caught to hackers backed by governments trying new tricks, the message is clear: cybercriminals are always changing how they attack, and we need to keep up. Hackers are using everyday tools in harmful ways, hiding spyware in trusted apps, and finding new ways...

0

AI Could Generate 10,000 Malware Variants, Evading Detection in 88% of Case – [email protected] (The Hacker News)

– [[{“value”:”Cybersecurity researchers have found that it’s possible to use large language models (LLMs) to generate new variants of malicious JavaScript code at scale in a manner that can better evade detection. “Although LLMs struggle to create malware from scratch, criminals can easily use them to rewrite or obfuscate existing malware, making it harder to detect,” Palo Alto Networks Unit...

0

Rockstar2FA Collapse Fuels Expansion of FlowerStorm Phishing-as-a-Service – [email protected] (The Hacker News)

– [[{“value”:”An interruption to the phishing-as-a-service (PhaaS) toolkit called Rockstar 2FA has led to a rapid uptick in activity from another nascent offering named FlowerStorm. “It appears that the [Rockstar2FA] group running the service experienced at least a partial collapse of its infrastructure, with pages associated with the service no longer reachable,” Sophos said in a new report published last”}]] ...

0

Top 10 Cybersecurity Trends to Expect in 2025 – [email protected] (The Hacker News)

– The 2025 cybersecurity landscape is increasingly complex, driven by sophisticated cyber threats, increased regulation, and rapidly evolving technology. In 2025, organizations will be challenged with protecting sensitive information for their customers while continuing to provide seamless and easy user experiences. Here’s a closer look at ten emerging challenges and threats set to shape the  – Read More  – The...

0

U.S. Judge Rules Against NSO Group in WhatsApp Pegasus Spyware Case – [email protected] (The Hacker News)

– [[{“value”:”Meta Platforms-owned WhatsApp scored a major legal victory in its fight against Israeli commercial spyware vendor NSO Group after a federal judge in the U.S. state of California ruled in favor of the messaging giant for exploiting a security vulnerability to deliver Pegasus. “The limited evidentiary record before the court does show that defendants’ Pegasus code was sent through...

0

Italy Fines OpenAI €15 Million for ChatGPT GDPR Data Privacy Violations – [email protected] (The Hacker News)

– [[{“value”:”Italy’s data protection authority has fined ChatGPT maker OpenAI a fine of €15 million ($15.66 million) over how the generative artificial intelligence application handles personal data. The fine comes nearly a year after the Garante found that ChatGPT processed users’ information to train its service in violation of the European Union’s General Data Protection Regulation (GDPR). The authority”}]]  –...

0

LockBit Developer Rostislav Panev Charged for Billions in Global Ransomware Damages – [email protected] (The Hacker News)

– [[{“value”:”A dual Russian and Israeli national has been charged in the United States for allegedly being the developer of the now-defunct LockBit ransomware-as-a-service (RaaS) operation since its inception in or around 2019 through at least February 2024. Rostislav Panev, 51, was arrested in Israel earlier this August and is currently awaiting extradition, the U.S. Department of Justice (DoJ) said...

0

Justice Department unveils charges against alleged LockBit developer – Greg Otto

– [[{“value”:” The U.S. Department of Justice revealed charges Friday against Rostislav Panev, a dual Russian and Israeli national, for his alleged role as a developer in the notorious LockBit ransomware group. Panev was arrested in Israel following a U.S. provisional arrest request and is currently awaiting extradition. Authorities allege that Panev has been an instrumental figure in LockBit’s operations...

0

Builder.ai Database Misconfiguration Exposes 1.29 TB of Unsecured Records – Waqas

– Cybersecurity researcher Jeremiah Fowler discovered a 1.2TB database containing over 3 million records of Builder.ai, a London-based AI software and app development company. Discover the risks, lessons learned, and best practices for data security.  – Read More  – Hackread – Latest Cybersecurity, Tech, Crypto & Hacking News 

0

Lazarus Group Spotted Targeting Nuclear Engineers with CookiePlus Malware – [email protected] (The Hacker News)

– [[{“value”:”The Lazarus Group, an infamous threat actor linked to the Democratic People’s Republic of Korea (DPRK), has been observed leveraging a “complex infection chain” targeting at least two employees belonging to an unnamed nuclear-related organization within the span of one month in January 2024. The attacks, which culminated in the deployment of a new modular backdoor referred to as...

0

Sophos Issues Hotfixes for Critical Firewall Flaws: Update to Prevent Exploitation – [email protected] (The Hacker News)

– [[{“value”:”Sophos has released hotfixes to address three security flaws in Sophos Firewall products that could be exploited to achieve remote code execution and allow privileged system access under certain conditions. Of the three, two are rated Critical in severity. There is currently no evidence that the shortcomings have been exploited in the wild. The list of vulnerabilities is as...

0

Rspack npm Packages Compromised with Crypto Mining Malware in Supply Chain Attack – [email protected] (The Hacker News)

– [[{“value”:”The developers of Rspack have revealed that two of their npm packages, @rspack/core and @rspack/cli, were compromised in a software supply chain attack that allowed a malicious actor to publish malicious versions to the official package registry with cryptocurrency mining malware. Following the discovery, versions 1.1.7 of both libraries have been unpublished from the npm registry. The latest”}]]  –...

0

Hackers Exploiting Critical Fortinet EMS Vulnerability to Deploy Remote Access Tools – [email protected] (The Hacker News)

– [[{“value”:”A now-patched critical security flaw impacting Fortinet FortiClient EMS is being exploited by malicious actors as part of a cyber campaign that installed remote desktop software such as AnyDesk and ScreenConnect.  The vulnerability in question is CVE-2023-48788 (CVSS score: 9.3), an SQL injection bug that allows attackers to execute unauthorized code or commands by sending specially crafted”}]]  – Read...

0

CISA Adds Critical Flaw in BeyondTrust Software to Exploited Vulnerabilities List – [email protected] (The Hacker News)

– [[{“value”:”The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Thursday added a critical security flaw impacting BeyondTrust Privileged Remote Access (PRA) and Remote Support (RS) products to the Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation in the wild. The vulnerability, tracked as CVE-2024-12356 (CVSS score: 9.8), is a command injection flaw that”}]]  – Read More  –...

0

Study finds ‘significant uptick’ in cybersecurity disclosures to SEC – Greg Otto

– [[{“value”:” The introduction of new cybersecurity disclosure rules by the U.S. Securities and Exchange Commission has led to a significant uptick in the number of reported cybersecurity incidents from public companies, according to a leading U.S. law firm that specializes in finance and M&A activity. Analysis by Paul Hastings LLP found that since the disclosure law went into effect...

0

Israeli court to hear U.S. extradition request for alleged LockBit developer – Greg Otto

– [[{“value”:” An Israeli Court is set to deliberate a significant extradition case involving Rostislav Panev, an Israeli citizen alleged to be involved with the notorious LockBit ransomware gang. According to Israeli news outlet Ynet, a U.S. extradition request was made public Thursday claiming that between 2019 and 2024, Panev served as a software developer for LockBit. During this period,...

0

Web Hacking Service ‘Araneida’ Tied to Turkish IT Firm – BrianKrebs

– [[{“value”:” Cybercriminals are selling hundreds of thousands of credential sets stolen with the help of a cracked version of Acunetix, a powerful commercial web app vulnerability scanner, new research finds. The cracked software is being resold as a cloud-based attack tool by at least two different services, one of which KrebsOnSecurity traced to an information technology firm based in...

0

Chinese cyber center points finger at U.S. over alleged cyberattacks to steal trade secrets – Tim Starks

– [[{“value”:” China’s national cyber incident response center accused the U.S. government of launching cyberattacks against two Chinese tech companies in a bid to steal trade secrets. In a notice Wednesday, the National Computer Network Emergency Response Technical Team/Coordination Center of China (CNCERT) said a suspected U.S. intelligence agency was behind the attacks, and that CNCERT had “handled” them, according...

0

Smashing Security podcast #398: Fake CAPTCHAs, Harmageddon, and Krispy Kreme – Graham Cluley

– [[{“value”:”This week, we delve into the dark world of fake CAPTCHAs designed to hijack your computer. Plus, the AI safety clock is ticking down – is doomsday closer than we think? And to top it off, we uncover the sticky situation of Krispy Kreme facing a ransomware attack. All this and more is discussed in the latest jam-packed edition...

0

Ukrainian sentenced to five years in jail for work on Raccoon Stealer – Greg Otto

– [[{“value”:” Ukrainian national Mark Sokolovsky was sentenced Wednesday to five years in federal prison for his role in operating Raccoon Infostealer malware, which infiltrated millions of computers worldwide to steal personal data. According to court documents, Sokolovsky, 28, was integral to operations that allowed the leasing of Raccoon Infostealer for $200 per month, payable via cryptocurrency. Users predominantly deployed...

0

Thousands Download Malicious npm Libraries Impersonating Legitimate Tools – [email protected] (The Hacker News)

– [[{“value”:”Threat actors have been observed uploading malicious typosquats of legitimate npm packages such as typescript-eslint and @types/node that have racked up thousands of downloads on the package registry. The counterfeit versions, named @typescript_eslinter/eslint and types-node, are engineered to download a trojan and retrieve second-stage payloads, respectively. “While typosquatting attacks are”}]]  – Read More  – The Hacker News 

0

Juniper Warns of Mirai Botnet Targeting SSR Devices with Default Passwords – [email protected] (The Hacker News)

– [[{“value”:”Juniper Networks is warning that Session Smart Router (SSR) products with default passwords are being targeted as part of a malicious campaign that deploys the Mirai botnet malware. The company said it’s issuing the advisory after “several customers” reported anomalous behavior on their Session Smart Network (SSN) platforms on December 11, 2024. “These systems have been infected with the...

0

Fortinet Warns of Critical FortiWLM Flaw That Could Lead to Admin Access Exploits – [email protected] (The Hacker News)

– [[{“value”:”Fortinet has issued an advisory for a now-patched critical security flaw impacting Wireless LAN Manager (FortiWLM) that could lead to disclosure of sensitive information. The vulnerability, tracked as CVE-2023-34990, carries a CVSS score of 9.6 out of a maximum of 10.0. “A relative path traversal [CWE-23] in FortiWLM may allow a remote unauthenticated attacker to read sensitive files,” the”}]] ...

0

UAC-0125 Abuses Cloudflare Workers to Distribute Malware Disguised as Army+ App – [email protected] (The Hacker News)

– [[{“value”:”The Computer Emergency Response Team of Ukraine (CERT-UA) has disclosed that a threat actor it tracks as UAC-0125 is leveraging Cloudflare Workers service to trick military personnel in the country into downloading malware disguised as Army+, a mobile app that was introduced by the Ministry of Defence back in August 2024 in an effort to make the armed forces...

0

Dutch DPA Fines Netflix €4.75 Million for GDPR Violations Over Data Transparency – [email protected] (The Hacker News)

– [[{“value”:”The Dutch Data Protection Authority (DPA) on Wednesday fined video on-demand streaming service Netflix €4.75 million ($4.93 million) for not giving consumers enough information about how it used their data between 2018 and 2020. An investigation launched by the DPA in 2019 found that the tech giant did not inform customers clearly enough in its privacy statement about what...

0

CISA Mandates Cloud Security for Federal Agencies by 2025 Under Binding Directive 25-01 – [email protected] (The Hacker News)

– [[{“value”:”The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued Binding Operational Directive (BOD) 25-01, ordering federal civilian agencies to secure their cloud environments and abide by Secure Cloud Business Applications (SCuBA) secure configuration baselines. “Recent cybersecurity incidents highlight the significant risks posed by misconfigurations and weak security controls,”}]]  – Read More  – The Hacker News 

0

Russia bans cybersecurity company Recorded Future – Tim Starks

– [[{“value”:” Russia banned the cybersecurity company Recorded Future on Wednesday, labeling it an “undesirable” organization — much to its CEO’s delight. The company stands accused of collaborating with the Central Intelligence Agency, Ukraine and other countries.  “They provide information and technical support for the propaganda campaign launched by the West against Russia,” Russia’s Office of Prosecutor General said in...

0

CISA pushes guide for high-value targets to secure mobile devices – Greg Otto

– [[{“value”:” The Cybersecurity and Infrastructure Security Agency unveiled a detailed set of guidelines Wednesday to safeguard the mobile communications of high-value government targets in the wake of the ongoing Salt Typhoon telecom breach. The guide aims to help both political and federal leadership harden their communications and avoid any data interception by the Chinese-linked espionage group. As of earlier...

0

HubPhish Exploits HubSpot Tools to Target 20,000 European Users for Credential Theft – [email protected] (The Hacker News)

– [[{“value”:”Cybersecurity researchers have disclosed a new phishing campaign that has targeted European companies with an aim to harvest account credentials and take control of the victims’ Microsoft Azure cloud infrastructure. The campaign has been codenamed HubPhish by Palo Alto Networks Unit 42 owing to the abuse of HubSpot tools in the attack chain. Targets include at least 20,000 automotive,...

0

BeyondTrust Issues Urgent Patch for Critical Vulnerability in PRA and RS Products – [email protected] (The Hacker News)

– [[{“value”:”BeyondTrust has disclosed details of a critical security flaw in Privileged Remote Access (PRA) and Remote Support (RS) products that could potentially lead to the execution of arbitrary commands. Privileged Remote Access controls, manages, and audits privileged accounts and credentials, offering zero trust access to on-premises and cloud resources by internal, external, and third-party users.”}]]  – Read More  –...

0

How to Lose a Fortune with Just One Bad Click – BrianKrebs

– [[{“value”:” Image: Shutterstock, iHaMoo. Adam Griffin is still in disbelief over how quickly he was robbed of nearly $500,000 in cryptocurrencies. A scammer called using a real Google phone number to warn his Gmail account was being hacked, sent email security alerts directly from google.com, and ultimately seized control over the account by convincing him to click “yes” to...