North Korea-linked Lazarus Group targeted a South Korean financial firm by exploiting a zero-day vulnerability in certificate software.
Learn more: https://thehackernews.com/2023/03/lazarus-group-exploits-zero-day.html
Learn more: https://thehackernews.com/2023/03/lazarus-group-exploits-zero-day.html
👍28🔥9⚡6😁2
⚡ Severe flaws have been uncovered in the popular Jenkins Automation Server, affecting all versions prior to 2.319.2.
Dubbed "CorePlague," the flaws could lead to code execution attacks and potentially compromise your server completely.
https://thehackernews.com/2023/03/jenkins-security-alert-new-security.html
Dubbed "CorePlague," the flaws could lead to code execution attacks and potentially compromise your server completely.
https://thehackernews.com/2023/03/jenkins-security-alert-new-security.html
⚡23👍12😁3🤔1😱1
🚨Attention! Fortinet has released security patches for 15 new flaws, including a critical vulnerability (CVE-2023-25610) affecting FortiOS and FortiProxy that could allow attackers to take control of affected systems.
Details: https://thehackernews.com/2023/03/new-critical-flaw-in-fortios-and.html
Details: https://thehackernews.com/2023/03/new-critical-flaw-in-fortios-and.html
🤔15👍11⚡6🔥4🤯3
8220 Gang hackers are now using a new weapon in their arsenal — ScrubCrypt Crypter — to carry out cryptojacking attacks by exploiting the Oracle WebLogic vulnerability.
Read details: https://thehackernews.com/2023/03/new-scrubcrypt-crypter-used-in.html
Read details: https://thehackernews.com/2023/03/new-scrubcrypt-crypter-used-in.html
👍10⚡8🔥7😱6😁1
Iranian hacking group is posing as a U.S. think tank to target women involved in Middle East political affairs and human rights.
Learn more: https://thehackernews.com/2023/03/iranian-hackers-target-women-involved.html
Learn more: https://thehackernews.com/2023/03/iranian-hackers-target-women-involved.html
🤯27😱12⚡10👍10🔥3🤔2👏1
⚠️Heads up, folks! IceFire, a Windows-based ransomware strain, is now targeting Linux-powered enterprise networks by exploiting a vulnerability in IBM Aspera Faspex file-sharing software.
Learn more: https://thehackernews.com/2023/03/icefire-linux-ransomware.html
Learn more: https://thehackernews.com/2023/03/icefire-linux-ransomware.html
👍31⚡7😁4🔥2
Researchers warn of security vulnerabilities in remote desktop programs such as Sunlogin and AweSun being exploited by threat actors to deploy the PlugX malware.
Read details: https://thehackernews.com/2023/03/hackers-exploiting-remote-desktop.html
Read details: https://thehackernews.com/2023/03/hackers-exploiting-remote-desktop.html
👍29⚡8🤯6😁5👏3🔥1
North Korean hackers using new malware families to target media and technology organizations in the U.S. and Europe.
Learn more: https://thehackernews.com/2023/03/north-korean-unc2970-hackers-expands.html
Learn more: https://thehackernews.com/2023/03/north-korean-unc2970-hackers-expands.html
🤯21👍10⚡8😁4🔥3😱3👏2🤔1
Cybersecurity experts are warning about a new variant of the Android banking trojan, Xenomorph, which has surfaced with new capabilities to target more than 400 banking and financial institutions.
Read: https://thehackernews.com/2023/03/xenomorph-android-banking-trojan.html
Read: https://thehackernews.com/2023/03/xenomorph-android-banking-trojan.html
👍22⚡7👏6😱6🤔4🔥3
A new China-linked hacking campaign has been observed targeting unpatched devices to drop malware and establish long-term persistence.
Read details: https://thehackernews.com/2023/03/china-linked-hackers-targeting.html
Read details: https://thehackernews.com/2023/03/china-linked-hackers-targeting.html
⚡17👍9🤯6👏4😁3
👏 International law enforcement authorities shut down the online infrastructure of the cross-platform NetWire RAT and arrested a Croatian national believed to be the site's administrator.
Learn more: https://thehackernews.com/2023/03/international-law-enforcement-takes.html
Learn more: https://thehackernews.com/2023/03/international-law-enforcement-takes.html
👍28⚡9👏8🤯5😱5🤔4
Heads up! An updated version of the Prometei modular malware has infected over 10,000 systems globally since Nov 2022 in Brazil, Indonesia, and Turkey.
Learn more: https://thehackernews.com/2023/03/new-version-of-prometei-botnet-infects.html
Learn more: https://thehackernews.com/2023/03/new-version-of-prometei-botnet-infects.html
👍33😱11⚡9🔥4😁4🤯1
🚨 Attention all! Malware downloader BATLOADER has been found abusing Google Ads to deliver secondary payloads like Vidar Stealer and Ursnif.
Learn more: https://thehackernews.com/2023/03/batloader-malware-uses-google-ads-to.html
Learn more: https://thehackernews.com/2023/03/batloader-malware-uses-google-ads-to.html
🤯31👍23😁12⚡9🔥9🤔9
Dark Pink APT actor is back in action, using the KamiKakaBot malware to target government and military entities in Southeast Asia.
Learn more: https://thehackernews.com/2023/03/kamikakabot-malware-used-in-latest-dark.html
Learn more: https://thehackernews.com/2023/03/kamikakabot-malware-used-in-latest-dark.html
🔥22👍11⚡5👏1
Knock knock, who's there? Akuvox E11. And apparently, a dozen security flaws too! 😱
Check out this article to learn more: https://thehackernews.com/2023/03/researchers-uncover-over-dozen-security.html
Check out this article to learn more: https://thehackernews.com/2023/03/researchers-uncover-over-dozen-security.html
🔥20😁12👍6⚡5🤔4🤯2😱2
Beware of AI-generated YouTube videos! Threat actors are using them to spread stealer malware like Raccoon, RedLine, and Vidar.
Learn more: https://thehackernews.com/2023/03/warning-ai-generated-youtube-video.html
Learn more: https://thehackernews.com/2023/03/warning-ai-generated-youtube-video.html
👍28🤯12😁10⚡3
Cyber criminals are using fake ChatGPT-branded Chrome extensions to distribute malware and hijack Facebook accounts.
Learn more: https://thehackernews.com/2023/03/fake-chatgpt-chrome-extension-hijacking.html
Learn more: https://thehackernews.com/2023/03/fake-chatgpt-chrome-extension-hijacking.html
🔥53😁18👍15😱10⚡7🤔6👏4🤯2
A malicious cyber operation has been targeting websites aimed at East Asian audiences and redirecting visitors to adult-themed content.
Learn more: https://thehackernews.com/2023/03/large-scale-cyber-attack-hijacks-east.html
Learn more: https://thehackernews.com/2023/03/large-scale-cyber-attack-hijacks-east.html
😁25👍12🔥9⚡7🤔5
Fortinet researchers have discovered an advanced and highly targeted threat actor that is exploiting a zero-day security vulnerability (CVE-2022-41328) in FortiOS. This flaw could potentially result in the execution of arbitrary code.
Learn more: https://thehackernews.com/2023/03/fortinet-fortios-flaw-exploited-in.html
Learn more: https://thehackernews.com/2023/03/fortinet-fortios-flaw-exploited-in.html
👍30😁9🔥8👏4😱2⚡1
🚨 Heads up, everyone!
Cybercriminal group DEV-1101 is using an open-source AiTM phishing kit to launch attacks at scale. It can bypass MFA protections and steal passwords and session cookies.
Learn more about this: https://thehackernews.com/2023/03/microsoft-warns-of-large-scale-use-of.html
Cybercriminal group DEV-1101 is using an open-source AiTM phishing kit to launch attacks at scale. It can bypass MFA protections and steal passwords and session cookies.
Learn more about this: https://thehackernews.com/2023/03/microsoft-warns-of-large-scale-use-of.html
😱19🤯10👍8⚡4😁3🔥2
GoBruteforcer, a new Golang-based malware, is using brute-force attacks to target web servers running phpMyAdmin, MySQL, FTP, and Postgres.
Learn more: https://thehackernews.com/2023/03/gobruteforcer-new-golang-based-malware.html
Learn more: https://thehackernews.com/2023/03/gobruteforcer-new-golang-based-malware.html
👍31🔥13🤔5😱4👏2