FBI has confirmed that the North Korean state-sponsored hacking group known as Lazarus Group and APT38 are responsible for the theft of $100 million in cryptocurrency assets from Harmony Horizon Bridge.
Details: https://thehackernews.com/2023/01/fbi-says-north-korean-hackers-behind.html
Details: https://thehackernews.com/2023/01/fbi-says-north-korean-hackers-behind.html
π35π±26π₯11π€7β‘5π5
Chinese-speaking actor behind DragonSpark attacks targeting organizations in East Asia using Golang malware and unusual techniques to evade detection.
Read details: https://thehackernews.com/2023/01/chinese-hackers-utilize-golang-malware.html
Read details: https://thehackernews.com/2023/01/chinese-hackers-utilize-golang-malware.html
π33β‘11π3π2π€2π€―2
VMware releases patch for 4 vulnerabilities in vRealize Log Insight, including 2 critical flaws (CVE-2022-31706 and CVE-2022-31704) that could lead to remote code execution attacks.
Read details: https://thehackernews.com/2023/01/vmware-releases-patches-for-critical.html
Read details: https://thehackernews.com/2023/01/vmware-releases-patches-for-critical.html
π30π2
LastPassβ parent company GoTo (formerly LogMeIn) has experienced a data breach in which cybercriminals stole customers' encrypted backups and an encryption key used to secure data for some customers.
Read: https://thehackernews.com/2023/01/lastpass-parent-company-goto-suffers.html
Read: https://thehackernews.com/2023/01/lastpass-parent-company-goto-suffers.html
π€―52π₯16π13π±9π7β‘5
North Korean group APT38 is targeting cryptocurrency holders by using credential harvesting as a new weapon in its quest for crypto riches.
Read details: https://thehackernews.com/2023/01/north-korean-hackers-turn-to-credential.html
Read details: https://thehackernews.com/2023/01/north-korean-hackers-turn-to-credential.html
π20π€―11π₯5π5π€4
Warning: A massive malware campaign has infected more than 4,500 WordPress websites and is redirecting their visitors to sketchy ad pages.
Read: https://thehackernews.com/2023/01/over-4500-wordpress-sites-hacked-to.html
Keep your website secure and always be cautious of suspicious links.
Read: https://thehackernews.com/2023/01/over-4500-wordpress-sites-hacked-to.html
Keep your website secure and always be cautious of suspicious links.
π38π±14π₯9π5β‘3π1π€―1
ALERT: Two federal agencies in the U.S. have fallen victim to a widespread malicious campaign using RMM software for phishing scams.
Read details: https://thehackernews.com/2023/01/us-federal-agencies-fall-victim-to.html
Read details: https://thehackernews.com/2023/01/us-federal-agencies-fall-victim-to.html
π€―27π8π±8β‘7π₯7π4
New research has uncovered connections between the operations of Moses Staff and Abraham's Ax, two politically motivated hacktivist groups.
Read details: https://thehackernews.com/2023/01/researchers-uncover-connection-bw-moses.html
Read details: https://thehackernews.com/2023/01/researchers-uncover-connection-bw-moses.html
π12β‘3π₯2
Researchers have released proof-of-concept exploit code for a high-severity security vulnerability (CVE-2022-34689) in the Windows CryptoAPI, which was discovered by the NSA and NCSC.
Read details: https://thehackernews.com/2023/01/researchers-release-poc-exploit-for.html
Read details: https://thehackernews.com/2023/01/researchers-release-poc-exploit-for.html
π22π±10β‘3π₯1
Researchers have identified a new Python-based malware that uses WebSockets for both command and control communication and data exfiltration.
Read details: https://thehackernews.com/2023/01/pyration-new-python-based-rat-utilizes.html
Read details: https://thehackernews.com/2023/01/pyration-new-python-based-rat-utilizes.html
π22π₯8β‘5π2
Google shuts down pro-Chinese influence operation DRAGONBRIDGE, with over 50,000 instances of activity dismantled in 2022.
Read: https://thehackernews.com/2023/01/google-takes-down-50000-instances-of.html
Read: https://thehackernews.com/2023/01/google-takes-down-50000-instances-of.html
π40π9π₯2β‘1π€―1π±1
π₯ Victory against cybercrime!
International law enforcement agencies have taken down the infrastructure behind the HIVE ransomware-as-a-service operation in a joint effort across 13 countries.
Details: https://thehackernews.com/2023/01/hive-ransomware-infrastructure-seized.html
International law enforcement agencies have taken down the infrastructure behind the HIVE ransomware-as-a-service operation in a joint effort across 13 countries.
Details: https://thehackernews.com/2023/01/hive-ransomware-infrastructure-seized.html
π73π15π₯15π±11π€―1
U.K.'s cybersecurity agency has issued a warning about cyberattacks by Russian & Iranian state-sponsored hacker groups targeting key sectors, including defense, government organizations & even academia, journalists, think tanks and activists.
https://thehackernews.com/2023/01/british-cyber-agency-warns-of-russian.html
https://thehackernews.com/2023/01/british-cyber-agency-warns-of-russian.html
π16π€―16β‘5π5
PlugX just got sneakier!
Cybersecurity researchers uncover a new variant that infects attached USB media devices to spread the malware to other systems.
Read details: https://thehackernews.com/2023/01/researchers-discover-new-plugx-malware.html
Cybersecurity researchers uncover a new variant that infects attached USB media devices to spread the malware to other systems.
Read details: https://thehackernews.com/2023/01/researchers-discover-new-plugx-malware.html
π19π₯12β‘6π3π1
Cybersecurity researchers have uncovered the true identity of the threat actor behind the Golden Chickens malware-as-a-service.
Read details: https://thehackernews.com/2023/01/experts-uncover-identity-of-mastermind.html
Read details: https://thehackernews.com/2023/01/experts-uncover-identity-of-mastermind.html
π27π12β‘6π±5π2π€―2
Ukraine is under attack from a new Golang-based data wiper malware called "SwiftSlicer." The attackers have been identified as Sandworm, a known nation-state group with ties to the Russian military.
Read: https://thehackernews.com/2023/01/ukraine-hit-with-new-golang-based.html
Read: https://thehackernews.com/2023/01/ukraine-hit-with-new-golang-based.html
π±32π23π12π₯9β‘6π€3π€―3π2
The Internet Systems Consortium (ISC) has released security patches for multiple new vulnerabilities in the BIND DNS software suite that could lead to a DoS condition and system failures.
Read: https://thehackernews.com/2023/01/isc-releases-security-patches-for-new.html
Read: https://thehackernews.com/2023/01/isc-releases-security-patches-for-new.html
π€―25π13β‘7π4π±3π€1
Microsoft urges customers to keep their servers up to date and implement additional security measures, such as enabling Windows Extended Protection & configuring certificate-based signing of #PowerShell serialization payloads.
Read: https://thehackernews.com/2023/01/microsoft-urges-customers-to-secure-on.html
Read: https://thehackernews.com/2023/01/microsoft-urges-customers-to-secure-on.html
β‘34π28π±7π6π2
Gootkit malware continues to evolve and become more sophisticated, with notable changes to the toolkit, adding new components and obfuscations to their infection chains.
Read: https://thehackernews.com/2023/01/gootkit-malware-continues-to-evolve.html
Read: https://thehackernews.com/2023/01/gootkit-malware-continues-to-evolve.html
π₯25π21π±5π4β‘3π3
Urgent Alert β A critical RCE vulnerability in the Realtek Jungle SDK is being weaponized by attackers to hack IoT devices, with 134 MILLION exploitation attempts recorded in the past 2 months alone.
Read: https://thehackernews.com/2023/01/realtek-vulnerability-under-attack-134.html
Read: https://thehackernews.com/2023/01/realtek-vulnerability-under-attack-134.html
π€―16π8π±7β‘5π₯5π4
Beware of the latest cyber threatπ¨
Hackers are distributing a new Golang-based info stealer malware, known as Titan Stealer, through Telegram channels to other cybercriminals β that can steal browser credentials, crypto wallets, and more.
Read: https://thehackernews.com/2023/01/titan-stealer-new-golang-based.html
Hackers are distributing a new Golang-based info stealer malware, known as Titan Stealer, through Telegram channels to other cybercriminals β that can steal browser credentials, crypto wallets, and more.
Read: https://thehackernews.com/2023/01/titan-stealer-new-golang-based.html
π€―41π25π₯7β‘5π5π±5π3