β οΈ Alert: EleKtra-Leak cryptojacking campaign is exploiting exposed AWS IAM credentials on public GitHub repositories.
Find details here: https://thehackernews.com/2023/10/elektra-leak-cryptojacking-attacks.html
Find details here: https://thehackernews.com/2023/10/elektra-leak-cryptojacking-attacks.html
π22π±7π₯3
ServiceNow exposes sensitive data due to misconfigurations. Learn how this could've jeopardized your business and the steps to ensure your data is secure.
Read more: https://thehackernews.com/2023/10/servicenow-data-exposure-wake-up-call.html
Read more: https://thehackernews.com/2023/10/servicenow-data-exposure-wake-up-call.html
π17π₯7π6
Join our expert panel of security veterans Emo Gokay, Multi-Cloud Security Engineer at EY Technologies and George Prichici, VP of products at OPSWAT, as they share insights and strategies gathered from the frontlines of securing critical infrastructure from advanced and persistent malware.
Join: https://thehackernews.com/2023/10/new-webinar-5-must-know-trends.html
Join: https://thehackernews.com/2023/10/new-webinar-5-must-know-trends.html
π26π4β‘2
β‘οΈ Pro-Hamas hacktivist group using a new Linux-based malware, BiBi-Linux Wiper, to target Israeli entities amid ongoing conflict.
Read: https://thehackernews.com/2023/10/pro-hamas-hacktivists-targeting-israeli.html
Read: https://thehackernews.com/2023/10/pro-hamas-hacktivists-targeting-israeli.html
π88π€21π₯19π18π€―14π10β‘7
Meta is introducing a paid ad-free subscription for Facebook and Instagram in Europe to comply with data protection laws.
Read details here: https://thehackernews.com/2023/10/meta-launches-paid-ad-free-subscription.html
Read details here: https://thehackernews.com/2023/10/meta-launches-paid-ad-free-subscription.html
π46π18π€6π€―5π1
Canada bans WeChat and Kaspersky apps on government devices, citing privacy and security risks.
Read details: https://thehackernews.com/2023/10/canada-bans-wechat-and-kaspersky-apps.html
Read details: https://thehackernews.com/2023/10/canada-bans-wechat-and-kaspersky-apps.html
π₯38π17π14π7π±1
π€ A malvertising scheme is using compromised websites to trick users into downloading malware-laden PyCharm promoted via Google Ads.
Read details: https://thehackernews.com/2023/10/trojanized-pycharm-software-version.html
Read details: https://thehackernews.com/2023/10/trojanized-pycharm-software-version.html
π19π₯8π±4
β οΈ Alert! Atlassian warns of critical flaw (CVE-2023-22518) in Confluence Data Center and Server. Disconnect publicly accessible instances until patched to avoid data loss.
Learn more: https://thehackernews.com/2023/10/atlassian-warns-of-new-critical.html
Learn more: https://thehackernews.com/2023/10/atlassian-warns-of-new-critical.html
π₯14π7π€―6
π‘οΈ Penetration testing just got a major upgrade. See how PentestPad automates report generation, enhances real-time collaboration, and integrates with your favorite tools.
Read details: https://thehackernews.com/2023/10/pentestpad-platform-for-pentest-teams.html
Read details: https://thehackernews.com/2023/10/pentestpad-platform-for-pentest-teams.html
π21π₯8β‘3
β οΈ Alert: Cybersecurity experts uncover stealthy malware scheme in NuGet package manager. Discover how threat actors deploy SeroXen RAT through rogue packages.
Learn more: https://thehackernews.com/2023/10/malicious-nuget-packages-caught.html
Learn more: https://thehackernews.com/2023/10/malicious-nuget-packages-caught.html
π18π₯8
Arid Viper, a cyber espionage group linked to Hamas, has been spotted targeting Arabic-speaking users with #Android spyware disguised as a dating app.
Learn more: https://thehackernews.com/2023/10/arid-viper-targeting-arabic-android.html
Learn more: https://thehackernews.com/2023/10/arid-viper-targeting-arabic-android.html
π€26π16π8π€―7π₯3π2π±2
Russian-linked hacking group Turla evolves with an upgraded Kazuar backdoorβa multi-threaded, modular tool with extensive capabilitiesβfocusing on anti-analysis, stealth, and evasion techniques.
Learn more: https://thehackernews.com/2023/11/turla-updates-kazuar-backdoor-with.html
Learn more: https://thehackernews.com/2023/11/turla-updates-kazuar-backdoor-with.html
π19π₯10
π¨ ALERT: State-sponsored North Korean hackers are using a sneaky #macOS malware called KANDYKORN to target crypto engineers via Discord.
Learn more: https://thehackernews.com/2023/11/north-korean-hackers-tageting-crypto.html
Learn more: https://thehackernews.com/2023/11/north-korean-hackers-tageting-crypto.html
π€―13π₯5π4
π¨ Security Alert β F5 warns of active exploitation of a critical flaw (CVE-2023-46747) in BIG-IP, enabling attackers to execute system commands.
Learn more: https://thehackernews.com/2023/11/alert-f5-warns-of-active-attacks.html
Protect your networkβpatch now!
Learn more: https://thehackernews.com/2023/11/alert-f5-warns-of-active-attacks.html
Protect your networkβpatch now!
π±15π14
Iranian threat actor "Scarred Manticore" has launched a year-long cyber espionage campaign targeting the Middle East finance, government, military, and telecom sectors.
Learn more: https://thehackernews.com/2023/11/iranian-cyber-espionage-group-targets.html
Learn more: https://thehackernews.com/2023/11/iranian-cyber-espionage-group-targets.html
π15π₯8π€―8β‘1π1π1
Are you an Amazon Web Services (AWS) customer or considering migrating to the cloud?
Then don't miss this #webinar!
Join XMCyber and AWS as we explore the top attack paths and most common #exposures in #AWS, and share best practices for efficiently mitigating these risks.
When: November 2nd, 2023
Register now: https://thn.news/NEhcd6fh
Then don't miss this #webinar!
Join XMCyber and AWS as we explore the top attack paths and most common #exposures in #AWS, and share best practices for efficiently mitigating these risks.
When: November 2nd, 2023
Register now: https://thn.news/NEhcd6fh
Xmcyber
Webinar - AWS: Top Attack Paths in AWS and How to Efficiently Remediate Exposures
π€23π15π€―5
Meet "Prolific Puma," the secretive threat actor behind a dangerous link shortening service with thousands of malicious domains used for phishing and malware distribution.
Learn how this operation evades detection: https://thehackernews.com/2023/11/dns-abuse-exposes-prolific-pumas.html
Learn how this operation evades detection: https://thehackernews.com/2023/11/dns-abuse-exposes-prolific-pumas.html
π17π₯8
π¨ Urgent: Thousands of internet-accessible ActiveMQ instances are at risk.
HelloKitty ransomware group is actively exploiting a critical Remote Code Execution (RCE) flaw, CVE-2023-46604, in Apache ActiveMQ.
Find details here β‘οΈ https://thehackernews.com/2023/11/hellokitty-ransomware-group-exploiting.html
HelloKitty ransomware group is actively exploiting a critical Remote Code Execution (RCE) flaw, CVE-2023-46604, in Apache ActiveMQ.
Find details here β‘οΈ https://thehackernews.com/2023/11/hellokitty-ransomware-group-exploiting.html
π₯15π8π±5π€3
π£ FIRST announces CVSS v4.0, the latest version of the Common Vulnerability Scoring System. Discover how this update addresses critical vulnerabilities.
Details here: https://thehackernews.com/2023/11/first-announces-cvss-40-new.html
Details here: https://thehackernews.com/2023/11/first-announces-cvss-40-new.html
π30
π Researchers uncover vulnerabilities in 34 Windows drivers that non-privileged hackers can exploit to take control of your device and execute code.
Read details: https://thehackernews.com/2023/11/researchers-find-34-windows-drivers.html
Read details: https://thehackernews.com/2023/11/researchers-find-34-windows-drivers.html
π€―20π11π₯5π5β‘2
π΅οΈββοΈ Iranian state-backed hackers, MuddyWater, has evolved its tactics. They're now using N-able's Advanced Monitoring Agent in their latest spear-phishing campaign.
Read details: https://thehackernews.com/2023/11/irans-muddywater-targets-israel-in-new.html
Read details: https://thehackernews.com/2023/11/irans-muddywater-targets-israel-in-new.html
π₯26π7π±7π6π4β‘1