Attention Android users: Beware of the latest version of GravityRAT! It disguises itself as messaging apps, stealing WhatsApp backups, deleting call logs, and files.
Learn more about it here: https://thehackernews.com/2023/06/warning-gravityrat-android-trojan.html
Learn more about it here: https://thehackernews.com/2023/06/warning-gravityrat-android-trojan.html
π15π€10β‘3π₯2
Vidar malware evolves to conceal its tracks! Threat actors behind Vidar are changing their backend infrastructure, rotating IP addresses and utilizing VPN servers.
Learn more about this info-stealer: https://thehackernews.com/2023/06/vidar-malware-using-new-tactics-to.html
Learn more about this info-stealer: https://thehackernews.com/2023/06/vidar-malware-using-new-tactics-to.html
π11π9π₯9β‘1
New findings reveal that ransomware actors, cryptocurrency scammers, and nation-state hackers are exploiting cloud mining services to launder cryptocurrencies.
Learn details here: https://thehackernews.com/2023/06/ransomware-hackers-and-scammers.html
Learn details here: https://thehackernews.com/2023/06/ransomware-hackers-and-scammers.html
π15π10β‘4π€2π₯1
π¨ Progress Software discloses 3rd critical flaw in MOVEit Transfer appβSQL injectionβallowing unauthorized access & escalated privileges.
https://thehackernews.com/2023/06/third-flaw-uncovered-in-moveit-transfer.html
Meanwhile, Cl0p ransomware gang exploits MOVEit flaws, targets 27 hacked companies, incl. U.S. federal agencies.
https://thehackernews.com/2023/06/third-flaw-uncovered-in-moveit-transfer.html
Meanwhile, Cl0p ransomware gang exploits MOVEit flaws, targets 27 hacked companies, incl. U.S. federal agencies.
π14π€―13π2β‘1π₯1π±1
Mandiant's latest report uncovers UNC4841, an espionage actor linked to the People's Republic of China, exploiting a recently patched zero-day flaw in Barracuda Email Security Gateway.
Find out how this skilled group targeted organizations worldwide: https://thehackernews.com/2023/06/chinese-unc4841-group-exploits-zero-day.html
Find out how this skilled group targeted organizations worldwide: https://thehackernews.com/2023/06/chinese-unc4841-group-exploits-zero-day.html
π13π12π€5β‘1π₯1
The U.S. Department of Justice charges a 20-year-old Russian national for deploying LockBit ransomware worldwide. The suspect was arrested in Arizona last month.
Read details: https://thehackernews.com/2023/06/20-year-old-russian-lockbit-ransomware.html
Read details: https://thehackernews.com/2023/06/20-year-old-russian-lockbit-ransomware.html
π±28π10π9π5β‘4π₯2π€2
π ChamelGang's new weapon unveiled: ChamelDoH. This powerful Linux backdoor uses DNS-over-HTTPS for covert communication.
Discover how this previously undocumented backdoor infiltrates, executes remote commands, and evades detection: https://thehackernews.com/2023/06/chameldoh-new-linux-backdoor-utilizing.html
Discover how this previously undocumented backdoor infiltrates, executes remote commands, and evades detection: https://thehackernews.com/2023/06/chameldoh-new-linux-backdoor-utilizing.html
π€―23π11π₯11β‘3π±1
Romanian Diicot hackers now equipped with off-the-shelf botnet, ready to launch DDoS attacks. Their activities span cryptojacking and doxxing rival hacking groups.
Learn more: https://thehackernews.com/2023/06/from-cryptojacking-to-ddos-attacks.html
Learn more: https://thehackernews.com/2023/06/from-cryptojacking-to-ddos-attacks.html
π36π€9π±5π₯4
Microsoft has officially confirmed that Layer 7 DDoS attacks caused disruptions in Azure, Outlook, and OneDrive services.
Read details here: https://thehackernews.com/2023/06/microsoft-blames-massive-ddos-attack.html
Read details here: https://thehackernews.com/2023/06/microsoft-blames-massive-ddos-attack.html
π₯30π€―13π7π6β‘3π1
Sustained cyber-espionage attacks targeting Middle East and Africa governmental entities! Sophisticated techniques involving credential theft and MS Exchange email exfiltration used to obtain highly sensitive information.
Read details: https://thehackernews.com/2023/06/state-backed-hackers-employ-advanced.html
Read details: https://thehackernews.com/2023/06/state-backed-hackers-employ-advanced.html
π±12π10π€―5π₯4β‘2π2
New sophisticated toolkit targeting Apple macOS systems discovered by cybersecurity researchers. Undetected malicious artifacts pose a serious threat, while permission checks raise concerns about a complex attack.
Read details: https://thehackernews.com/2023/06/researchers-discover-new-sophisticated.html
Read details: https://thehackernews.com/2023/06/researchers-discover-new-sophisticated.html
π16π€9π₯6π4
New malware alert! Mystic stealer targets 40 web browsers, 70 browser extensions, cryptocurrency wallets, Steam, and Telegram. It employs anti-analysis techniques and defense evasion, reflecting current malware trends.
Details: https://thehackernews.com/2023/06/new-mystic-stealer-malware-targets-40.html
Details: https://thehackernews.com/2023/06/new-mystic-stealer-malware-targets-40.html
π20π₯6π±6π€―4π3
Weak access controls, network misconfigurations & more. Infrastructure as Code (IaC) Security is crucial!
Checkmarx's AI Guided Remediation for IaC Security & KICS provides actionable steps & advice for faster remediation.
Learn more: https://thehackernews.com/2023/06/introducing-ai-guided-remediation-for.html
Checkmarx's AI Guided Remediation for IaC Security & KICS provides actionable steps & advice for faster remediation.
Learn more: https://thehackernews.com/2023/06/introducing-ai-guided-remediation-for.html
π13π₯7π4β‘3
Warning: Android users in Pakistan are facing a sophisticated attack. Fake apps, like "iKHfaa VPN" and "nSure Chat," are being used to extract personal data and compromise devices.
Read details here: https://thehackernews.com/2023/06/rogue-android-apps-target-pakistani.html
Read details here: https://thehackernews.com/2023/06/rogue-android-apps-target-pakistani.html
π21π₯6π6β‘3π3π±3
β‘ Over 100,000 OpenAI ChatGPT account credentials have been compromised and sold on the dark web.
Cybercriminals are targeting the valuable information stored in these accounts.
Read details: https://thehackernews.com/2023/06/over-100000-stolen-chatgpt-account.html
Take necessary precautions to safeguard your data.
Cybercriminals are targeting the valuable information stored in these accounts.
Read details: https://thehackernews.com/2023/06/over-100000-stolen-chatgpt-account.html
Take necessary precautions to safeguard your data.
π₯23π22π€―19π6π±4β‘2π1
π Take action now! ASUS has released firmware updates to fix nine security bugs impacting router models.
Key fixes: CVE-2018-1160 and CVE-2022-26376. Update firmware, disable WAN services, and conduct regular audits for maximum security.
Read details: https://thehackernews.com/2023/06/asus-releases-patches-to-fix-critical.html
Key fixes: CVE-2018-1160 and CVE-2022-26376. Update firmware, disable WAN services, and conduct regular audits for maximum security.
Read details: https://thehackernews.com/2023/06/asus-releases-patches-to-fix-critical.html
π13π₯12π4
π¨ Experts expose a year-long cyber operation targeting an East Asian IT firm, deploying custom malware called RDStealer to compromise data and steal credentials.
Learn more: https://thehackernews.com/2023/06/experts-uncover-year-long-cyber-attack.html
Learn more: https://thehackernews.com/2023/06/experts-uncover-year-long-cyber-attack.html
π8π₯6π3
β οΈ Attention Zyxel NAS users! A new critical vulnerability (CVE-2023-27992) could allow attackers to run arbitrary commands on affected systems.
Read details: https://thehackernews.com/2023/06/zyxel-releases-urgent-security-updates.html
Don't waitβapply the security update immediately!
Read details: https://thehackernews.com/2023/06/zyxel-releases-urgent-security-updates.html
Don't waitβapply the security update immediately!
π12π7π₯3π±3β‘2π€―1
Quick Serve Restaurants depend on shared resources and consistency. As threat actors target food chains, securing #SaaS apps is crucial.
Learn how SSPMs manage data, detect misconfigurations, enhance security, and protect your SaaS stack.
https://thehackernews.com/2023/06/saas-in-real-world-how-global-food.html
Learn how SSPMs manage data, detect misconfigurations, enhance security, and protect your SaaS stack.
https://thehackernews.com/2023/06/saas-in-real-world-how-global-food.html
π€10π6π₯6π±2
Three new security vulnerabilities in Wago and Schneider Electric products have been disclosed, part of the broader OT:ICEFALL issues affecting 13 vendors.
Find out more: https://thehackernews.com/2023/06/researchers-expose-new-severe-flaws-in.html
Find out more: https://thehackernews.com/2023/06/researchers-expose-new-severe-flaws-in.html
π₯10π€―6π5π€3
π¨ Attention network admins! #VMware's Aria Operations for Networks is under attack. The critical vulnerability (CVE-2023-20887) is being actively exploited, putting your network at high risk.
Learn more: https://thehackernews.com/2023/06/alert-hackers-exploiting-critical.html
Upgrade NOW to prevent RCE attacks.
Learn more: https://thehackernews.com/2023/06/alert-hackers-exploiting-critical.html
Upgrade NOW to prevent RCE attacks.
π16π₯9π€4π2