β οΈ Alert! Atlassian warns of critical flaw (CVE-2023-22518) in Confluence Data Center and Server. Disconnect publicly accessible instances until patched to avoid data loss.
Learn more: https://thehackernews.com/2023/10/atlassian-warns-of-new-critical.html
Learn more: https://thehackernews.com/2023/10/atlassian-warns-of-new-critical.html
π₯14π7π€―6
π‘οΈ Penetration testing just got a major upgrade. See how PentestPad automates report generation, enhances real-time collaboration, and integrates with your favorite tools.
Read details: https://thehackernews.com/2023/10/pentestpad-platform-for-pentest-teams.html
Read details: https://thehackernews.com/2023/10/pentestpad-platform-for-pentest-teams.html
π21π₯8β‘3
β οΈ Alert: Cybersecurity experts uncover stealthy malware scheme in NuGet package manager. Discover how threat actors deploy SeroXen RAT through rogue packages.
Learn more: https://thehackernews.com/2023/10/malicious-nuget-packages-caught.html
Learn more: https://thehackernews.com/2023/10/malicious-nuget-packages-caught.html
π18π₯8
Arid Viper, a cyber espionage group linked to Hamas, has been spotted targeting Arabic-speaking users with #Android spyware disguised as a dating app.
Learn more: https://thehackernews.com/2023/10/arid-viper-targeting-arabic-android.html
Learn more: https://thehackernews.com/2023/10/arid-viper-targeting-arabic-android.html
π€26π16π8π€―7π₯3π2π±2
Russian-linked hacking group Turla evolves with an upgraded Kazuar backdoorβa multi-threaded, modular tool with extensive capabilitiesβfocusing on anti-analysis, stealth, and evasion techniques.
Learn more: https://thehackernews.com/2023/11/turla-updates-kazuar-backdoor-with.html
Learn more: https://thehackernews.com/2023/11/turla-updates-kazuar-backdoor-with.html
π19π₯10
π¨ ALERT: State-sponsored North Korean hackers are using a sneaky #macOS malware called KANDYKORN to target crypto engineers via Discord.
Learn more: https://thehackernews.com/2023/11/north-korean-hackers-tageting-crypto.html
Learn more: https://thehackernews.com/2023/11/north-korean-hackers-tageting-crypto.html
π€―13π₯5π4
π¨ Security Alert β F5 warns of active exploitation of a critical flaw (CVE-2023-46747) in BIG-IP, enabling attackers to execute system commands.
Learn more: https://thehackernews.com/2023/11/alert-f5-warns-of-active-attacks.html
Protect your networkβpatch now!
Learn more: https://thehackernews.com/2023/11/alert-f5-warns-of-active-attacks.html
Protect your networkβpatch now!
π±15π14
Iranian threat actor "Scarred Manticore" has launched a year-long cyber espionage campaign targeting the Middle East finance, government, military, and telecom sectors.
Learn more: https://thehackernews.com/2023/11/iranian-cyber-espionage-group-targets.html
Learn more: https://thehackernews.com/2023/11/iranian-cyber-espionage-group-targets.html
π15π₯8π€―8β‘1π1π1
Are you an Amazon Web Services (AWS) customer or considering migrating to the cloud?
Then don't miss this #webinar!
Join XMCyber and AWS as we explore the top attack paths and most common #exposures in #AWS, and share best practices for efficiently mitigating these risks.
When: November 2nd, 2023
Register now: https://thn.news/NEhcd6fh
Then don't miss this #webinar!
Join XMCyber and AWS as we explore the top attack paths and most common #exposures in #AWS, and share best practices for efficiently mitigating these risks.
When: November 2nd, 2023
Register now: https://thn.news/NEhcd6fh
Xmcyber
Webinar - AWS: Top Attack Paths in AWS and How to Efficiently Remediate Exposures
π€23π15π€―5
Meet "Prolific Puma," the secretive threat actor behind a dangerous link shortening service with thousands of malicious domains used for phishing and malware distribution.
Learn how this operation evades detection: https://thehackernews.com/2023/11/dns-abuse-exposes-prolific-pumas.html
Learn how this operation evades detection: https://thehackernews.com/2023/11/dns-abuse-exposes-prolific-pumas.html
π17π₯8
π¨ Urgent: Thousands of internet-accessible ActiveMQ instances are at risk.
HelloKitty ransomware group is actively exploiting a critical Remote Code Execution (RCE) flaw, CVE-2023-46604, in Apache ActiveMQ.
Find details here β‘οΈ https://thehackernews.com/2023/11/hellokitty-ransomware-group-exploiting.html
HelloKitty ransomware group is actively exploiting a critical Remote Code Execution (RCE) flaw, CVE-2023-46604, in Apache ActiveMQ.
Find details here β‘οΈ https://thehackernews.com/2023/11/hellokitty-ransomware-group-exploiting.html
π₯15π8π±5π€3
π£ FIRST announces CVSS v4.0, the latest version of the Common Vulnerability Scoring System. Discover how this update addresses critical vulnerabilities.
Details here: https://thehackernews.com/2023/11/first-announces-cvss-40-new.html
Details here: https://thehackernews.com/2023/11/first-announces-cvss-40-new.html
π30
π Researchers uncover vulnerabilities in 34 Windows drivers that non-privileged hackers can exploit to take control of your device and execute code.
Read details: https://thehackernews.com/2023/11/researchers-find-34-windows-drivers.html
Read details: https://thehackernews.com/2023/11/researchers-find-34-windows-drivers.html
π€―20π11π₯5π5β‘2
π΅οΈββοΈ Iranian state-backed hackers, MuddyWater, has evolved its tactics. They're now using N-able's Advanced Monitoring Agent in their latest spear-phishing campaign.
Read details: https://thehackernews.com/2023/11/irans-muddywater-targets-israel-in-new.html
Read details: https://thehackernews.com/2023/11/irans-muddywater-targets-israel-in-new.html
π₯26π7π±7π6π4β‘1
Simplify SaaS Security.
Discover, assess, and control your organization's SaaS usage with Wing Security's "Essential SSPM" tool. A freemium model that makes securing your cloud-based operations easy.
Read more: https://thehackernews.com/2023/11/saas-security-is-now-accessible-and.html
Discover, assess, and control your organization's SaaS usage with Wing Security's "Essential SSPM" tool. A freemium model that makes securing your cloud-based operations easy.
Read more: https://thehackernews.com/2023/11/saas-security-is-now-accessible-and.html
π22π₯5π€4
Mozi botnet's sudden drop in malicious activity traced back to a mysterious "kill switch."
Read more β‘οΈ https://thehackernews.com/2023/11/mysterious-kill-switch-disrupts-mozi.html
Read more β‘οΈ https://thehackernews.com/2023/11/mysterious-kill-switch-disrupts-mozi.html
π₯16π8π€3π2
β‘ Alert: 48 malicious npm packages discovered. They can secretly compromise your system with a reverse shell.
Read details: https://thehackernews.com/2023/11/48-malicious-npm-packages-found.html
Read details: https://thehackernews.com/2023/11/48-malicious-npm-packages-found.html
π₯23π10π±3π1
π¨ Beware: WhatsApp mods for #Android hiding a dangerous spyware, CanesSpy!
Your phone could be compromised without you knowing.
Find out more: https://thehackernews.com/2023/11/canesspy-spyware-discovered-in-modified.html
Your phone could be compromised without you knowing.
Find out more: https://thehackernews.com/2023/11/canesspy-spyware-discovered-in-modified.html
π27π₯10π5π€―2
β οΈ ALERT: Cybercriminals are using compromised business accounts to lure victims with "revealing photos of young women," distributing NodeStealer malware.
Protect your account, read the full story: https://thehackernews.com/2023/11/nodestealer-malware-hijacking-facebook.html
Protect your account, read the full story: https://thehackernews.com/2023/11/nodestealer-malware-hijacking-facebook.html
π21π€2
Discover how predictive AI is shaping the future of cybersecurity. Learn how BlackBerry's Cylance AI is outperforming the competition in malware protection.
Read the article now: https://thehackernews.com/2023/11/predictive-ai-in-cybersecurity-outcomes.html
Read the article now: https://thehackernews.com/2023/11/predictive-ai-in-cybersecurity-outcomes.html
π19π₯6π4π3π€2
π¨Kinsing hackers exploit the new Linux flaw, Looney Tunables (CVE-2023-4911), to breach cloud environments for root access.
Read more β‘οΈ https://thehackernews.com/2023/11/kinsing-actors-exploit-linux-flaw-to.html
Read more β‘οΈ https://thehackernews.com/2023/11/kinsing-actors-exploit-linux-flaw-to.html
π€―16π15π₯6π±5π3