β‘οΈ Ex-NSA employeeβworking as an Information Systems Security Designerβhas pleaded guilty to attempting to transmit classified defense information to Russia, seeking $85,000 in exchange.
Read details here: https://thehackernews.com/2023/10/ex-nsa-employee-pleads-guilty-to.html
Read details here: https://thehackernews.com/2023/10/ex-nsa-employee-pleads-guilty-to.html
π€―39π20π11π9π₯7β‘5π±5
π¨ Urgent: Proof-of-concept (PoC) exploits have been publicly released for the recently discovered vulnerabilities in VMware Aria Operations, Citrix NetScaler ADC, and NetScaler Gateway.
Read: https://thehackernews.com/2023/10/alert-poc-exploits-released-for-citrix.html
Don't waitβapply fixes now and safeguard your systems.
Read: https://thehackernews.com/2023/10/alert-poc-exploits-released-for-citrix.html
Don't waitβapply fixes now and safeguard your systems.
π₯18π8β‘4π€4π€―4π±2
Cybercriminals are targeting Brazil's popular PIX payment system using a new malware called GoPIX, delivered to users via malvertising campaigns when they search for "WhatsApp web."
Learn more π https://thehackernews.com/2023/10/malvertising-campaign-targets-brazils.html
Learn more π https://thehackernews.com/2023/10/malvertising-campaign-targets-brazils.html
π₯16β‘4π4π€―3
π¨ VMware releases crucial security updates to fix a new critical vulnerability (CVE-2023-34048) in vCenter Server.
Details in the article: https://thehackernews.com/2023/10/act-now-vmware-releases-patch-for.html
Protect your systems from remote code execution.
Details in the article: https://thehackernews.com/2023/10/act-now-vmware-releases-patch-for.html
Protect your systems from remote code execution.
π17π16π₯1
CloudTrail and Server Access Logs provide critical insights into Amazon S3 security. Find out how to use them effectively to prevent ransomware attacks.
Read: https://thehackernews.com/2023/10/the-rise-of-s3-ransomware-how-to.html
Read: https://thehackernews.com/2023/10/the-rise-of-s3-ransomware-how-to.html
π21π€―1
Popular online services like Grammarly, Vidio, and Bukalapak faced critical security vulnerabilities in their OAuth implementation that could have allowed hackers to hijack user accounts.
Find details here: https://thehackernews.com/2023/10/critical-oauth-flaws-uncovered-in.html
Find details here: https://thehackernews.com/2023/10/critical-oauth-flaws-uncovered-in.html
π±17π10π9
β οΈ WARNING β Winter Vivern, a notorious nation-state hacker group with links to Belarus and Russia, exploiting a zero-day flaw in Roundcube webmail software to steal email messages.
Learn more: https://thehackernews.com/2023/10/nation-state-hackers-exploiting-zero.html
Learn more: https://thehackernews.com/2023/10/nation-state-hackers-exploiting-zero.html
π17π€―11π3π2π₯1
π¨ Meet YoroTrooper: A mysterious threat actor with ties to Kazakhstan. Learn how they're using custom tools and stealthy tactics to infiltrate state-owned entities across CIS countries.
Read: https://thehackernews.com/2023/10/yorotrooper-researchers-warn-of.html
Read: https://thehackernews.com/2023/10/yorotrooper-researchers-warn-of.html
π€―9π5π4
π Healthcare IT professionals, take note.
A critical RCE vulnerability (CVE-2023-43208) has been uncovered in Mirth Connect, a healthcare data integration platform.
Read: https://thehackernews.com/2023/10/critical-flaw-in-nextgens-mirth-connect.html
Update to version 4.4.1 immediately to prevent unauthorized access.
A critical RCE vulnerability (CVE-2023-43208) has been uncovered in Mirth Connect, a healthcare data integration platform.
Read: https://thehackernews.com/2023/10/critical-flaw-in-nextgens-mirth-connect.html
Update to version 4.4.1 immediately to prevent unauthorized access.
π17π₯3π±3
π¨ ALERT: Iranian threat actor, Tortoiseshell, strikes again with new malware, IMAPLoader.
This .NET malware uses email as a command-and-control channel and targets maritime and logistics sectors.
Learn more: https://thehackernews.com/2023/10/iranian-group-tortoiseshell-launches.html
This .NET malware uses email as a command-and-control channel and targets maritime and logistics sectors.
Learn more: https://thehackernews.com/2023/10/iranian-group-tortoiseshell-launches.html
π₯19π11π€―11π4π€2β‘1
π’ Upcoming Webinars Alert:
1οΈβ£ Kickstart your SaaS Security Strategies
2οΈβ£ Dive into the State of Web App Security
3οΈβ£ Lock down your Financial Data
Reserve your seat now: https://www.linkedin.com/pulse/expert-led-cybersecurity-webinars-saas-web-apps-financial-gfrif/
1οΈβ£ Kickstart your SaaS Security Strategies
2οΈβ£ Dive into the State of Web App Security
3οΈβ£ Lock down your Financial Data
Reserve your seat now: https://www.linkedin.com/pulse/expert-led-cybersecurity-webinars-saas-web-apps-financial-gfrif/
Linkedin
Expert-led Cybersecurity Webinars: SaaS, Web Apps, and Financial Data Security
We're excited to bring you a series of upcoming webinars, designed to empower you with the latest insights and strategies in the ever-evolving world of cybersecurity.
β‘16π16π€―6π±4
π¨Cloudflare thwarts massive DDoS attacks exceeding 100M requests/second.
Find out how HTTP/2 Rapid Reset flaw triggered a 65% increase in Q3 attacks.
Read more: https://thehackernews.com/2023/10/record-breaking-100-million-rps-ddos.html
Find out how HTTP/2 Rapid Reset flaw triggered a 65% increase in Q3 attacks.
Read more: https://thehackernews.com/2023/10/record-breaking-100-million-rps-ddos.html
π€―25π15π€6π₯2
π Web security matters more than ever. Don't miss this eye-opening case study by Reflectiz, revealing the hidden risks of rogue pixels on websites.
Privacy violations can happen even without hacking.
Learn more: https://thehackernews.com/2023/10/the-danger-of-forgotten-pixels-on.html
Privacy violations can happen even without hacking.
Learn more: https://thehackernews.com/2023/10/the-danger-of-forgotten-pixels-on.html
π21π₯2π2β‘1
Microsoft warns of Scattered Spider, a financially motivated hacking crew that infiltrates firms worldwide using SMS phishing, SIM swapping, and by posing as new employees, leading to data breaches and takeovers.
Find out more: https://thehackernews.com/2023/10/microsoft-warns-as-scattered-spider.html
Find out more: https://thehackernews.com/2023/10/microsoft-warns-as-scattered-spider.html
π±15π11π₯7
β οΈ Alert β Researchers expose new "iLeakage" side-channel attack targeting iOS, iPadOS, and macOS devices running on Apple's A and M-series CPUs.
Discover how sensitive data can be extracted using this new Safari exploit.
Read: https://thehackernews.com/2023/10/ileakage-new-safari-exploit-impacts.html
Discover how sensitive data can be extracted using this new Safari exploit.
Read: https://thehackernews.com/2023/10/ileakage-new-safari-exploit-impacts.html
π€―30π10π9π₯2
β‘ Urgent β F5 warns of a critical vulnerability (CVE-2023-46747) in BIG-IP, allowing unauthenticated remote code execution.
Learn more: https://thehackernews.com/2023/10/f5-issues-warning-big-ip-vulnerability.html
Learn more: https://thehackernews.com/2023/10/f5-issues-warning-big-ip-vulnerability.html
π₯24π15π€―9π€1
π€ Google expands Vulnerability Rewards Program to address vulnerabilities and attack scenarios tailored to generative artificial intelligence (AI) systems, while also strengthening the supply chain.
Learn more: https://thehackernews.com/2023/10/google-expands-its-bug-bounty-program.html
Learn more: https://thehackernews.com/2023/10/google-expands-its-bug-bounty-program.html
π26π₯7π7
Continuous monitoring is key. Discover how Fidelis Security's Network Detection and Response (NDR) solutions offer real-time threat detection to help you stay ahead of cyber threats.
Read: https://thehackernews.com/2023/10/how-to-keep-your-business-running-in.html
Read: https://thehackernews.com/2023/10/how-to-keep-your-business-running-in.html
π₯12π11π8π€5π±3
π¨ North Korea's Lazarus Group strikes again. Discover how they hacked a software vendor using known security flaws.
Read more: https://thehackernews.com/2023/10/n-korean-lazarus-group-targets-software.html
Read more: https://thehackernews.com/2023/10/n-korean-lazarus-group-targets-software.html
π29π18π9
Wiretapping attempt discovered on XMPP-based messaging service involving Hetzner and Linode hosting providers in Germany. Evidence points to a lawful foreign police request.
Learn more: https://thehackernews.com/2023/10/researchers-uncover-wiretapping-of-xmpp.html
Learn more: https://thehackernews.com/2023/10/researchers-uncover-wiretapping-of-xmpp.html
π26π€―14π±9β‘7π6π₯1
π Beware! A new cyber threat is using bogus MSIX Windows app packages for popular software like Google Chrome, Microsoft Edge, Brave, Grammarly, and Cisco Webex to spread a dangerous malware called GHOSTPULSE.
Learn more β https://thehackernews.com/2023/10/hackers-using-msix-app-packages-to.html
Learn more β https://thehackernews.com/2023/10/hackers-using-msix-app-packages-to.html
π26π±5π3π€―3π₯2