🚨 Alert: Docker API Under Attack! Threat actors are exploiting Docker Engine API vulnerabilities to build a powerful DDoS botnet called OracleIV.
Learn more: https://thehackernews.com/2023/11/alert-oracleiv-ddos-botnet-targets.html
Learn more: https://thehackernews.com/2023/11/alert-oracleiv-ddos-botnet-targets.html
👏11😱6👍4
Traditional cybersecurity measures might not cut it anymore!
Upgrade your defense with continuous monitoring techniques like RBVM, EASM, and Cyber Threat Intelligence.
Learn how: 👉 https://thehackernews.com/2023/11/the-importance-of-continuous-security.html
#cybersecuritytips #informationsecurity
Upgrade your defense with continuous monitoring techniques like RBVM, EASM, and Cyber Threat Intelligence.
Learn how: 👉 https://thehackernews.com/2023/11/the-importance-of-continuous-security.html
#cybersecuritytips #informationsecurity
👍17🔥5⚡2🤔1
🔒💻 Researchers found a vulnerability in AMD's SEV technology, called CacheWarp (CVE-2023-20592), that allows privilege escalation and remote code execution in virtual machines.
📰 Full story: https://thehackernews.com/2023/11/cachewarp-attack-new-vulnerability-in.html
📰 Full story: https://thehackernews.com/2023/11/cachewarp-attack-new-vulnerability-in.html
😱12👍9🔥4😁2
🆘 VMware raises the alarm about an UNPATCHED security flaw (CVE-2023-34060) in Cloud Director, which could allow attackers to bypass authentication on SSH and appliance management console ports.
Learn more ➡️ https://thehackernews.com/2023/11/urgent-vmware-warns-of-unpatched.html
Learn more ➡️ https://thehackernews.com/2023/11/urgent-vmware-warns-of-unpatched.html
👍22🔥5⚡1
🛡️ Microsoft's November 2023 Security Update:
🔐 63 vulnerabilities addressed
🚨 5 zero-days
💥 3 actively exploited in-the-wild
📊 Severity ratings: 3 Critical, 56 Important, 4 Moderate
Get the scoop on the latest vulnerabilities: https://thehackernews.com/2023/11/alert-microsoft-releases-patch-updates.html
🔐 63 vulnerabilities addressed
🚨 5 zero-days
💥 3 actively exploited in-the-wild
📊 Severity ratings: 3 Critical, 56 Important, 4 Moderate
Get the scoop on the latest vulnerabilities: https://thehackernews.com/2023/11/alert-microsoft-releases-patch-updates.html
🔥19👍18🤯6⚡1
🛡️ Did you know? Effective cloud vulnerability management combines Application Security and Cloud Security insights.
Learn more in the 2023 Cloud Vulnerability Report: https://thn.news/opcmhnAH
Learn more in the 2023 Cloud Vulnerability Report: https://thn.news/opcmhnAH
wiz.io
The 2023 Cloud Vulnerability Report | Wiz
Wiz is the unified cloud security platform with prevention and response capabilities, enabling security and development teams to build faster and more securely.
👍16🔥1
⚠️ New PoC exploit for CVE-2023-46604 flaw in Apache ActiveMQ could let attackers stealthily execute malicious code.
CVSS score: 10.0! Are your servers secure?
Learn more about this critical vulnerability: https://thehackernews.com/2023/11/new-poc-exploit-for-apache-activemq.html
CVSS score: 10.0! Are your servers secure?
Learn more about this critical vulnerability: https://thehackernews.com/2023/11/new-poc-exploit-for-apache-activemq.html
🤯9👍7🔥3😁2⚡1
🚨 Insider Threats are a growing concern for organizations. Varonis reveals a unique approach using a data security triad.
Learn how sensitivity, access, and activity can protect your organization's most valuable assets.
Read: https://thehackernews.com/2023/11/three-ways-varonis-helps-you-fight.html
Learn how sensitivity, access, and activity can protect your organization's most valuable assets.
Read: https://thehackernews.com/2023/11/three-ways-varonis-helps-you-fight.html
👍16🔥8
U.S. Government Dismantles Global IPStorm Botnet Network!
From Windows to Linux, Mac, and Android, the botnet turned infected devices into proxies for illegal activities.
Click to learn more: https://thehackernews.com/2023/11/us-takes-down-ipstorm-botnet-russian.html
From Windows to Linux, Mac, and Android, the botnet turned infected devices into proxies for illegal activities.
Click to learn more: https://thehackernews.com/2023/11/us-takes-down-ipstorm-botnet-russian.html
👍19😱9👏6🔥5⚡3😁1🤔1
Denmark's energy sector hit by massive cyberattack.
In May 2023, 22 Danish energy sector companies were simultaneously targeted in a sophisticated, coordinated cyber attack.
Learn more about their tactics and history: https://thehackernews.com/2023/11/russian-hackers-launch-largest-ever.html
In May 2023, 22 Danish energy sector companies were simultaneously targeted in a sophisticated, coordinated cyber attack.
Learn more about their tactics and history: https://thehackernews.com/2023/11/russian-hackers-launch-largest-ever.html
😱21👍10🤔6⚡1
🛡️ Novel attack methods targeting Google Workspace and Cloud Platform could lead to ransomware, data exfiltration, and password recovery attacks from a single compromised machine.
Discover how these attacks unfold: https://thehackernews.com/2023/11/hackers-could-exploit-google-workspace.html
Discover how these attacks unfold: https://thehackernews.com/2023/11/hackers-could-exploit-google-workspace.html
🤔11👍4🔥3😁1
U.S. agencies warn of Rhysida ransomware double extortion attacks on multiple industries, including education, manufacturing, IT, and government sectors.
Explore the details: https://thehackernews.com/2023/11/cisa-and-fbi-issue-warning-about.html
Explore the details: https://thehackernews.com/2023/11/cisa-and-fbi-issue-warning-about.html
👍15🤔3⚡2😁1
🚨 Are your ex-employees still accessing company data?
Discover how Nudge Security revolutionizes offboarding by identifying and securing unmanaged accounts, safeguarding your sensitive data.
Read: https://thehackernews.com/2023/11/how-to-automate-hardest-parts-of.html
Don't let your company's security be an afterthought!
Discover how Nudge Security revolutionizes offboarding by identifying and securing unmanaged accounts, safeguarding your sensitive data.
Read: https://thehackernews.com/2023/11/how-to-automate-hardest-parts-of.html
Don't let your company's security be an afterthought!
👍15😁9⚡8
🕵️♂️ Meet DarkCasino: From Zero-Day Exploit to APT Threat.
Cybersecurity experts classify DarkCasino as a powerful APT group after exploiting a WinRAR flaw.
Learn more: https://thehackernews.com/2023/11/experts-uncover-darkcasino-new-emerging.html
Cybersecurity experts classify DarkCasino as a powerful APT group after exploiting a WinRAR flaw.
Learn more: https://thehackernews.com/2023/11/experts-uncover-darkcasino-new-emerging.html
👍18😁8🤔5
🚨 ALERT: Four groups exploited a zero-day vulnerability in Zimbra Collaboration email software to steal email data, credentials, and tokens.
🛠️ Find out how: https://thehackernews.com/2023/11/zero-day-flaw-in-zimbra-email-software.html
Governments in Greece, Moldova, Tunisia, Vietnam, and Pakistan were targeted.
🛠️ Find out how: https://thehackernews.com/2023/11/zero-day-flaw-in-zimbra-email-software.html
Governments in Greece, Moldova, Tunisia, Vietnam, and Pakistan were targeted.
👍14🔥8
Kubernetes isn't just a tool; it's a target now!
Join this wxpert-led cybersecurity WEBINAR on fighting cloud security threats – essential knowledge for every IT security pro.
🔗 Click here to register: https://thn.news/2L7nEtoM
Join this wxpert-led cybersecurity WEBINAR on fighting cloud security threats – essential knowledge for every IT security pro.
🔗 Click here to register: https://thn.news/2L7nEtoM
thehacker.news
Navigating the Cloud Attack Landscape: 2023 Trends, Techniques, and Tactics
From Zenbleed to Kubernetes attacks - 2023 is proving a challenging year for cloud security. Get equipped with with strategies to combat these threats
👍29😁6🔥2
🚨 CISA adds 3 security flaws to its KEV catalog due to active exploitation.
CVE-2023-1671: Enables arbitrary code execution.
CVE-2023-2551: Affects WebLogic Server.
CVE-2023-36584: Associated with pro-Russian APT's spear-phishing.
Read: https://thehackernews.com/2023/11/cisa-adds-three-security-flaws-with.html
CVE-2023-1671: Enables arbitrary code execution.
CVE-2023-2551: Affects WebLogic Server.
CVE-2023-36584: Associated with pro-Russian APT's spear-phishing.
Read: https://thehackernews.com/2023/11/cisa-adds-three-security-flaws-with.html
👍15🔥7⚡3
🕵️♂️ U.S. agencies warn about Scattered Spider cybercriminals using advanced phishing to steal data and extort victims.
Learn their tactics, protect your organization: https://thehackernews.com/2023/11/us-cybersecurity-agencies-warn-of.html
Learn their tactics, protect your organization: https://thehackernews.com/2023/11/us-cybersecurity-agencies-warn-of.html
👍19🔥4👏2🤔1
🐍⚠️ WARNING for Python Devs!
📦 27 FAKE packages found on PyPI.
🕵️♂️ Masquerading as legit, downloaded thousands of times.
Learn how they embed malware in images using steganography.
🔗 Read more: https://thehackernews.com/2023/11/27-malicious-pypi-packages-with.html
📦 27 FAKE packages found on PyPI.
🕵️♂️ Masquerading as legit, downloaded thousands of times.
Learn how they embed malware in images using steganography.
🔗 Read more: https://thehackernews.com/2023/11/27-malicious-pypi-packages-with.html
🔥23🤯20👍7🤔7👏2⚡1
⚡ FCC enforces new regulation:
🔒 Wireless providers MUST now authenticate you before transferring phone numbers. Why? To SHIELD you from SIM-swapping attacks and port-out frauds.
Learn more: https://thehackernews.com/2023/11/fcc-enforces-stronger-rules-to-protect.html
🔒 Wireless providers MUST now authenticate you before transferring phone numbers. Why? To SHIELD you from SIM-swapping attacks and port-out frauds.
Learn more: https://thehackernews.com/2023/11/fcc-enforces-stronger-rules-to-protect.html
👍26😁6🔥5👏3
⚠️ Operation SEO#LURKER: Cybercriminals are using fake Google ads to trick users searching for software like WinSCP into downloading #malware.
Read details: https://thehackernews.com/2023/11/beware-malicious-google-ads-trick.html
Read details: https://thehackernews.com/2023/11/beware-malicious-google-ads-trick.html
👍33⚡6😁5🔥4🤯4👏2