A new study by cybersecurity experts shows that analyzing metadata of malicious LNK files can elp identify relationships b/w threat actors.
Read: https://thehackernews.com/2023/01/new-research-delves-into-world-of.html
LNK files have become a popular method for initial access to deliver & execute malware payloads.
Read: https://thehackernews.com/2023/01/new-research-delves-into-world-of.html
LNK files have become a popular method for initial access to deliver & execute malware payloads.
π₯20π13π±6β‘2
Another day, another vulnerability!
Researchers have uncovered a new vulnerability affecting multiple services related to Microsoft Azure, which could result in RCE attacks, data theft, and lateral movement within Azure services.
https://thehackernews.com/2023/01/new-microsoft-azure-vulnerability.html
Researchers have uncovered a new vulnerability affecting multiple services related to Microsoft Azure, which could result in RCE attacks, data theft, and lateral movement within Azure services.
https://thehackernews.com/2023/01/new-microsoft-azure-vulnerability.html
π₯46π15π±10π€―7β‘5π5π5π€4
Researchers are warning of a new Chinese #malware called "BOLDMOVE" that exploited a recently discovered vulnerability in Fortinet FortiOS SSL-VPN (CVE-2022-42475) as a zero-day to attack government entities & managed service providers.
https://thehackernews.com/2023/01/new-chinese-malware-spotted-exploiting.html
https://thehackernews.com/2023/01/new-chinese-malware-spotted-exploiting.html
π34π€14π₯9π€―5β‘2
Big fines for WhatsApp!
Irish Data Protection Commission imposed a β¬5.5 million penalty for violating data protection laws when processing users' personal information.
Details: https://thehackernews.com/2023/01/whatsapp-hit-with-55-million-fine-for.html
Irish Data Protection Commission imposed a β¬5.5 million penalty for violating data protection laws when processing users' personal information.
Details: https://thehackernews.com/2023/01/whatsapp-hit-with-55-million-fine-for.html
π43π22π11π₯10
Russian state-sponsored cyber espionage group Gamaredon is back and targeting Ukraine's military and law enforcement entities through Telegram.
Read: https://thehackernews.com/2023/01/gamaredon-group-launches-cyberattacks.html
Read: https://thehackernews.com/2023/01/gamaredon-group-launches-cyberattacks.html
π₯41π19π€11β‘8π€―6π4π±4π1
Beware of 'Roaming Mantis' cybercriminals spreading an updated version of its mobile malware, called "Wroba", β it now hijacks DNS settings of connected Wi-Fi routers for malicious attacks.
Read details: https://thehackernews.com/2023/01/roaming-mantis-spreading-mobile-malware.html
Read details: https://thehackernews.com/2023/01/roaming-mantis-spreading-mobile-malware.html
π47π€―18π9π±8β‘6π€3
Researchers have successfully shut down a large-scale AD fraud scheme known as VASTFLUX, which targeted a total of 11 million devices and involved over 1,700 spoofed apps.
Details: https://thehackernews.com/2023/01/massive-ad-fraud-scheme-targeted-over.html
Details: https://thehackernews.com/2023/01/massive-ad-fraud-scheme-targeted-over.html
π23π17π₯9β‘6π±6
New findings indicate that the Sliver C2 framework is gaining popularity among threat actors as a versatile alternative to traditional C2 tools such as Cobalt Strike and Metasploit.
Read details: https://thehackernews.com/2023/01/threat-actors-turn-to-sliver-as-open.html
Read details: https://thehackernews.com/2023/01/threat-actors-turn-to-sliver-as-open.html
π30β‘8
Researchers report two vulnerabilities in Samsung's Galaxy Store app that could be exploited to secretly install malicious apps or redirect users to fake landing pages on the Internet.
Read details: https://thehackernews.com/2023/01/samsung-galaxy-store-app-found.html
Read details: https://thehackernews.com/2023/01/samsung-galaxy-store-app-found.html
π€―38π17π±9π8π€3π1
Over the next few months, millions of people around the world will have access to end-to-end encrypted chats on Facebook Messenger, as well as access to new additional features.
Read details: https://thehackernews.com/2023/01/facebook-introduces-new-features-for.html
Read details: https://thehackernews.com/2023/01/facebook-introduces-new-features-for.html
π42π15π€5π3
Apple has released updates for a security vulnerability in Webkit that affects older iPhone & iPad devices.
Read: https://thehackernews.com/2023/01/apple-issues-updates-for-older-devices.html
This vulnerability is currently being exploited, so it is important to update your device immediately.
Read: https://thehackernews.com/2023/01/apple-issues-updates-for-older-devices.html
This vulnerability is currently being exploited, so it is important to update your device immediately.
π40π7π±5π4π₯3
Cybercriminals are always evolving their tactics, and the Emotet operation is no exception.
Emotet malware now using new tactics to fly under the radar and act as a conduit for other dangerous malware like Bumblebee and IcedID.
Read: https://thehackernews.com/2023/01/emotet-malware-makes-comeback-with-new.html
Emotet malware now using new tactics to fly under the radar and act as a conduit for other dangerous malware like Bumblebee and IcedID.
Read: https://thehackernews.com/2023/01/emotet-malware-makes-comeback-with-new.html
π₯23π9π3β‘2π€―1π±1
FBI has confirmed that the North Korean state-sponsored hacking group known as Lazarus Group and APT38 are responsible for the theft of $100 million in cryptocurrency assets from Harmony Horizon Bridge.
Details: https://thehackernews.com/2023/01/fbi-says-north-korean-hackers-behind.html
Details: https://thehackernews.com/2023/01/fbi-says-north-korean-hackers-behind.html
π35π±26π₯11π€7β‘5π5
Chinese-speaking actor behind DragonSpark attacks targeting organizations in East Asia using Golang malware and unusual techniques to evade detection.
Read details: https://thehackernews.com/2023/01/chinese-hackers-utilize-golang-malware.html
Read details: https://thehackernews.com/2023/01/chinese-hackers-utilize-golang-malware.html
π33β‘11π3π2π€2π€―2
VMware releases patch for 4 vulnerabilities in vRealize Log Insight, including 2 critical flaws (CVE-2022-31706 and CVE-2022-31704) that could lead to remote code execution attacks.
Read details: https://thehackernews.com/2023/01/vmware-releases-patches-for-critical.html
Read details: https://thehackernews.com/2023/01/vmware-releases-patches-for-critical.html
π30π2
LastPassβ parent company GoTo (formerly LogMeIn) has experienced a data breach in which cybercriminals stole customers' encrypted backups and an encryption key used to secure data for some customers.
Read: https://thehackernews.com/2023/01/lastpass-parent-company-goto-suffers.html
Read: https://thehackernews.com/2023/01/lastpass-parent-company-goto-suffers.html
π€―52π₯16π13π±9π7β‘5
North Korean group APT38 is targeting cryptocurrency holders by using credential harvesting as a new weapon in its quest for crypto riches.
Read details: https://thehackernews.com/2023/01/north-korean-hackers-turn-to-credential.html
Read details: https://thehackernews.com/2023/01/north-korean-hackers-turn-to-credential.html
π20π€―11π₯5π5π€4
Warning: A massive malware campaign has infected more than 4,500 WordPress websites and is redirecting their visitors to sketchy ad pages.
Read: https://thehackernews.com/2023/01/over-4500-wordpress-sites-hacked-to.html
Keep your website secure and always be cautious of suspicious links.
Read: https://thehackernews.com/2023/01/over-4500-wordpress-sites-hacked-to.html
Keep your website secure and always be cautious of suspicious links.
π38π±14π₯9π5β‘3π1π€―1
ALERT: Two federal agencies in the U.S. have fallen victim to a widespread malicious campaign using RMM software for phishing scams.
Read details: https://thehackernews.com/2023/01/us-federal-agencies-fall-victim-to.html
Read details: https://thehackernews.com/2023/01/us-federal-agencies-fall-victim-to.html
π€―27π8π±8β‘7π₯7π4
New research has uncovered connections between the operations of Moses Staff and Abraham's Ax, two politically motivated hacktivist groups.
Read details: https://thehackernews.com/2023/01/researchers-uncover-connection-bw-moses.html
Read details: https://thehackernews.com/2023/01/researchers-uncover-connection-bw-moses.html
π12β‘3π₯2
Researchers have released proof-of-concept exploit code for a high-severity security vulnerability (CVE-2022-34689) in the Windows CryptoAPI, which was discovered by the NSA and NCSC.
Read details: https://thehackernews.com/2023/01/researchers-release-poc-exploit-for.html
Read details: https://thehackernews.com/2023/01/researchers-release-poc-exploit-for.html
π22π±10β‘3π₯1