APT group SideCopy, known for targeting India & Afghanistan government agencies, has launched a new phishing campaign delivering Action RAT and AuTo Stealer.
Learn more: https://thehackernews.com/2023/03/pakistan-origin-sidecopy-linked-to-new.html
Learn more: https://thehackernews.com/2023/03/pakistan-origin-sidecopy-linked-to-new.html
๐ฑ16๐8โก7๐ฅ5๐คฏ4๐3๐1๐ค1
๐ Microsoft unveils Security Copilot in preview! Powered by OpenAI's GPT-4, it offers end-to-end defense ๐ at machine speed and scale.
Details here: https://thehackernews.com/2023/03/microsoft-introduces-gpt-4-ai-powered.html
Details here: https://thehackernews.com/2023/03/microsoft-introduces-gpt-4-ai-powered.html
๐คฏ48๐8๐ฅ8๐ค8๐ฑ8โก2๐2
APT43, a moderately-sophisticated cyber operator that supports North Korea's regime, engages in financially-motivated cybercrime to fund its operations.
Learn more: https://thehackernews.com/2023/03/north-korean-apt43-group-uses.html
Learn more: https://thehackernews.com/2023/03/north-korean-apt43-group-uses.html
๐คฏ18๐7โก6๐3๐ฑ3
๐ฅ New Chinese-linked #malware, Mรฉlofรฉe, threatens Linux servers!
Uncovered by ExaTrack, it enables remote control over servers and hides itself using kernel-mode rootkits.
Learn more: https://thehackernews.com/2023/03/melofee-researchers-uncover-new-linux.html
Uncovered by ExaTrack, it enables remote control over servers and hides itself using kernel-mode rootkits.
Learn more: https://thehackernews.com/2023/03/melofee-researchers-uncover-new-linux.html
๐20๐ฅ10โก4๐4๐ฑ2
๐จ Google's TAG reveals commercial spyware vendors exploited zero-day vulnerabilities on Android & iOS devices last year.
Learn more: https://thehackernews.com/2023/03/spyware-vendors-caught-exploiting-zero.html
These highly targeted campaigns put dissidents, journalists, & human rights workers at risk.
Learn more: https://thehackernews.com/2023/03/spyware-vendors-caught-exploiting-zero.html
These highly targeted campaigns put dissidents, journalists, & human rights workers at risk.
๐19๐คฏ8โก5๐2๐ฅ1
Beware of ๐ฆ Trojanized TOR installers targeting Russia & Eastern Europe with clipper malware designed to steal cryptocurrencies.
Learn more: https://thehackernews.com/2023/03/trojanized-tor-browser-installers.html
Learn more: https://thehackernews.com/2023/03/trojanized-tor-browser-installers.html
๐คฏ24๐9๐5๐ค5๐ฅ4๐ฑ4โก3๐3
โ ๏ธ ๐จ Active supply chain attack targets popular voice and video conferencing software 3CX Desktop App, affecting hundreds of well-known brands and millions of users.
A multi-stage attack chain has been identified, beginning with a trojanized app and leading to a 3rd stage infostealer DLL, capable of targeting Google Chrome, Microsoft Edge, Brave, and Mozilla Firefox browsers.
Learn more: https://thehackernews.com/2023/03/3cx-desktop-app-targeted-in-supply.html
A multi-stage attack chain has been identified, beginning with a trojanized app and leading to a 3rd stage infostealer DLL, capable of targeting Google Chrome, Microsoft Edge, Brave, and Mozilla Firefox browsers.
Learn more: https://thehackernews.com/2023/03/3cx-desktop-app-targeted-in-supply.html
๐18๐ฅ6๐6๐ค3๐คฏ2โก1
๐จ New cybersecurity threat! AlienFox, a highly modular & constantly evolving toolset distributed on Telegram, enables attackers to harvest API keys & secrets from popular cloud service providers like AWS, Google Workspace, and Microsoft 365.
Learn more: https://thehackernews.com/2023/03/alienfox-malware-targets-api-keys-and.html
Learn more: https://thehackernews.com/2023/03/alienfox-malware-targets-api-keys-and.html
๐ฅ26๐ฑ9๐5โก1๐ค1
๐ฅ A group of academics has uncovered a new fundamental flaw in IEEE 802.11 Wi-Fi protocol standard affecting Linux, FreeBSD, Android & iOS devices.
Read: https://thehackernews.com/2023/03/new-wi-fi-protocol-security-flaw.html
Hackers can hijack TCP connections or intercept web traffic, potentially executing a DoS attack.
Read: https://thehackernews.com/2023/03/new-wi-fi-protocol-security-flaw.html
Hackers can hijack TCP connections or intercept web traffic, potentially executing a DoS attack.
๐ฅ37๐คฏ15๐7๐6๐5โก4๐ค2
RedGolf, a highly-likely Chinese state-sponsored threat group, is using a new custom backdoor called KEYPLUG to target multiple sectors, including US government entities.
Learn more: https://thehackernews.com/2023/03/chinese-redgolf-group-targeting-windows.html
Learn more: https://thehackernews.com/2023/03/chinese-redgolf-group-targeting-windows.html
๐20โก5๐ฅ4๐ค4๐2๐คฏ2
Researchers reveal details on Super FabriXss, a high-risk vulnerability in Azure Service Fabric Explorer that can lead to unauthenticated RCE attacks on containers hosted on nodes.
Learn more: https://thehackernews.com/2023/03/researchers-detail-severe-super.html
Learn more: https://thehackernews.com/2023/03/researchers-detail-severe-super.html
๐ฅ14๐11๐5๐ฑ5๐คฏ1
3CX, has confirmed that multiple versions of its desktop app for Windows & macOS have been affected by a supply chain attack.
The attack appears to have compromised 3CX's software build pipeline.
Learn more: https://thehackernews.com/2023/03/3cx-supply-chain-attack-heres-what-we.html
The attack appears to have compromised 3CX's software build pipeline.
Learn more: https://thehackernews.com/2023/03/3cx-supply-chain-attack-heres-what-we.html
๐ค18๐10๐คฏ9๐2
Cyber Police of Ukraine, along with law enforcement officials from Czechia, have arrested several members of a cybercriminal gang that earned over $4.33 million in illicit profits through phishing scams.
Learn more: https://thehackernews.com/2023/03/cyber-police-of-ukraine-busted-phishing.html
Learn more: https://thehackernews.com/2023/03/cyber-police-of-ukraine-busted-phishing.html
๐31๐ฅ12๐คฏ9๐8๐5๐ฑ1
Cyber espionage group Winter Vivern (aka TA473) targets officials in Europe and U.S. by exploiting unpatched Zimbra vulnerability in gov't webmail portals.
Learn more: https://thehackernews.com/2023/03/winter-vivern-apt-targets-european.html
Learn more: https://thehackernews.com/2023/03/winter-vivern-apt-targets-european.html
๐19๐6๐ค4โก2๐ฅ2๐2
๐ฅ WEBINAR | Become an Incident Response Pro!
Unlock the secrets to bulletproof incident Response โ Master the 6-Phase process with Asaf Perlman, Cynet's IR Leader!
Don't Miss Out โ Save Your Seat: https://thehackernews.com/2023/03/deep-dive-into-6-key-steps-to.html
Unlock the secrets to bulletproof incident Response โ Master the 6-Phase process with Asaf Perlman, Cynet's IR Leader!
Don't Miss Out โ Save Your Seat: https://thehackernews.com/2023/03/deep-dive-into-6-key-steps-to.html
โก10๐10๐8๐ฅ7๐ฑ4๐3๐คฏ3
๐จ Urgent: Hackers are exploiting a high-severity flaw in the Elementor Pro plugin for WordPress, enabling them to take control of WooCommerce enabled sites. Update to version 3.11.7 or 3.12.0 immediately.
Learn more: https://thehackernews.com/2023/04/hackers-exploiting-wordpress-elementor.html
Learn more: https://thehackernews.com/2023/04/hackers-exploiting-wordpress-elementor.html
๐27๐8๐ฑ7๐ค5๐4
๐จ High-risk security flaws in Cacti, Realtek, and IBM Aspera Faspex are being exploited by hackers!
Details: https://thehackernews.com/2023/04/cacti-realtek-and-ibm-aspera-faspex.html
Update your systems ASAP to protect against MooBot and ShellBot attacks.
Details: https://thehackernews.com/2023/04/cacti-realtek-and-ibm-aspera-faspex.html
Update your systems ASAP to protect against MooBot and ShellBot attacks.
๐12๐10๐ฅ4๐ค3๐2
๐จ Microsoft patches Azure Active Directory misconfiguration issue, which exposed high-impact apps to unauthorized access and could have allowed attackers to modify Bing search results.
Learn more: https://thehackernews.com/2023/04/microsoft-fixes-new-azure-ad.html
Learn more: https://thehackernews.com/2023/04/microsoft-fixes-new-azure-ad.html
๐31๐ฑ13๐7๐ฅ6๐ค3๐คฏ2
Italy's data protection watchdog, Garante, temporarily bans OpenAI's ChatGPT, citing data protection concerns & potential violation of GDPR laws.
Learn more: https://thehackernews.com/2023/04/italian-watchdog-bans-openais-chatgpt.html
Despite the ban, apps using OpenAI's tech, such as Microsoft's Bing, are unaffected.
Learn more: https://thehackernews.com/2023/04/italian-watchdog-bans-openais-chatgpt.html
Despite the ban, apps using OpenAI's tech, such as Microsoft's Bing, are unaffected.
๐24๐11๐คฏ10๐6
โ ๏ธ Beware of OpcJacker! This stealthy malware is targeting users through fake websites, promising VPN services and more. Its main functions: keylogging, data theft, and crypto hijacking.
Learn more: https://thehackernews.com/2023/04/crypto-stealing-opcjacker-malware.html
Learn more: https://thehackernews.com/2023/04/crypto-stealing-opcjacker-malware.html
๐23๐ฑ6๐คฏ4๐3
โ ๏ธ Western Digital discloses a network security breach involving unauthorized access to its systems on March 26, 2023.
Learn more: https://thehackernews.com/2023/04/western-digital-hit-by-network-security.html
Investigation underway with the help of cybersecurity experts and law enforcement.
Learn more: https://thehackernews.com/2023/04/western-digital-hit-by-network-security.html
Investigation underway with the help of cybersecurity experts and law enforcement.
๐16๐คฏ14๐12๐ค9๐ฑ8๐ฅ5