🔒 Multiple vulnerabilities, called "PixieFail," found in UEFI firmware used by major manufacturers like AMI and Intel. Attackers can exploit these vulnerabilities to gain control, steal data, or cause damage.
Details ➡️ https://thehackernews.com/2024/01/pixiefail-uefi-flaws-expose-millions-of.html
Details ➡️ https://thehackernews.com/2024/01/pixiefail-uefi-flaws-expose-millions-of.html
🤯12👍8👏8
Remember those annoying texts you keep approving? They might be hacker traps!
Learn about MFA spamming and expert tips ➡️ https://thehackernews.com/2024/01/mfa-spamming-and-fatigue-when-security.html
Learn about MFA spamming and expert tips ➡️ https://thehackernews.com/2024/01/mfa-spamming-and-fatigue-when-security.html
🔥11👍6🤯5🤔4
⚠️ Developers, beware! Hackers can poison AI models and software. Vulnerabilities found in TensorFlow CI/CD pipeline allow #malware upload and token theft.
Learn about the AI/ML threat: https://thehackernews.com/2024/01/tensorflow-cicd-flaw-exposed-supply.html
Learn about the AI/ML threat: https://thehackernews.com/2024/01/tensorflow-cicd-flaw-exposed-supply.html
👏15😱7👍5😁5
Russian Spy Group Now Deploying Custom "SPICA" Backdoor!
TAG exposes COLDRIVER's evolution from phishing to malware attacks targeting Ukraine, NATO, and beyond.
Learn their sneaky tactics: https://thehackernews.com/2024/01/russian-coldriver-hackers-expand-beyond.html
TAG exposes COLDRIVER's evolution from phishing to malware attacks targeting Ukraine, NATO, and beyond.
Learn their sneaky tactics: https://thehackernews.com/2024/01/russian-coldriver-hackers-expand-beyond.html
👏11👍6😱4
A new attack targets Docker servers and uses a combo of cryptocurrency mining and website traffic generation for profit. It could leave a backdoor for attackers to exploit later.
Patch your systems and monitor for suspicious activity: https://thehackernews.com/2024/01/new-docker-malware-steals-cpu-for.html
Patch your systems and monitor for suspicious activity: https://thehackernews.com/2024/01/new-docker-malware-steals-cpu-for.html
🤯16👍9🔥9
🆘 Patch your Ivanti ASAP! CISA urges action, especially for government agencies.
A critical flaw (CVE-2023-35082) in Ivanti EPMM is being exploited in the wild, giving attackers access to your data.
Don't wait, read more: https://thehackernews.com/2024/01/us-cybersecurity-agency-warns-of.html
A critical flaw (CVE-2023-35082) in Ivanti EPMM is being exploited in the wild, giving attackers access to your data.
Don't wait, read more: https://thehackernews.com/2024/01/us-cybersecurity-agency-warns-of.html
👍14👏7
Ransomware, hardware failure, human error - the data loss threats in Exchange Servers are real.
Protect your Exchange Server from financial ruin & reputational nightmares with these 5 backup methods & proactive measures: https://thehackernews.com/2024/01/preventing-data-loss-backup-and.html
Protect your Exchange Server from financial ruin & reputational nightmares with these 5 backup methods & proactive measures: https://thehackernews.com/2024/01/preventing-data-loss-backup-and.html
👍12🔥7
RAT Alert! Malicious "oscompatible" package on npm deployed a sophisticated trojan on Windows machines. It steals data, hides your screen, and even disables shutdowns
Read details here: https://thehackernews.com/2024/01/npm-trojan-bypasses-uac-installs.html
Read details here: https://thehackernews.com/2024/01/npm-trojan-bypasses-uac-installs.html
👍20🤯8🤔3
Thinking of downloading a pirated copy of that software?
⚠️ Think again. A new backdoor malware has been discovered in pirated macOS apps, granting hackers full control of users' devices.
Learn more: https://thehackernews.com/2024/01/experts-warn-of-macos-backdoor-hidden.html
⚠️ Think again. A new backdoor malware has been discovered in pirated macOS apps, granting hackers full control of users' devices.
Learn more: https://thehackernews.com/2024/01/experts-warn-of-macos-backdoor-hidden.html
😁35🤔9⚡5😱5👍4
🛡️ TA866 is back with thousands of invoice-themed, booby-trapped emails targeting users with WasabiSeed and Screenshotter malware to spy on your screen and steal valuable data.
Learn more: https://thehackernews.com/2024/01/invoice-phishing-alert-ta866-deploys.html
Learn more: https://thehackernews.com/2024/01/invoice-phishing-alert-ta866-deploys.html
👍16😁4
🔐 Microsoft discloses Russian APT infiltrated its systems through a test account, stealing emails and attachments of senior executives and others in cybersecurity and legal departments.
Find details here ➡️ https://thehackernews.com/2024/01/microsofts-top-execs-emails-breached-in.html
Find details here ➡️ https://thehackernews.com/2024/01/microsofts-top-execs-emails-breached-in.html
😁23🔥11😱9👍8👏4
🚨CISA issues emergency directive against two major zero-day actively exploited flaws in Ivanti products.
Learn more: https://thehackernews.com/2024/01/cisa-issues-emergency-directive-to.html
Patch your Ivanti Connect Secure and Policy Secure ASAP.
Learn more: https://thehackernews.com/2024/01/cisa-issues-emergency-directive-to.html
Patch your Ivanti Connect Secure and Policy Secure ASAP.
👍22🤯4
Age ain't nothin' but a number... for vulnerabilities, that is. 35% of serious flaws linger for months! Time to prioritize patching.
Learn how in "Security Navigator 24" - https://thehackernews.com/2024/01/52-of-serious-vulnerabilities-we-find.html
Learn how in "Security Navigator 24" - https://thehackernews.com/2024/01/52-of-serious-vulnerabilities-we-find.html
👍19
Alert! New Java malware "NS-STEALER" uses bots to steal your logins and wallet data from popular browsers and exfiltrates secrets via Discord.
Learn more: https://thehackernews.com/2024/01/ns-stealer-uses-discord-bots-to.html
Learn more: https://thehackernews.com/2024/01/ns-stealer-uses-discord-bots-to.html
👍17
FTC bans another data broker, InMarket, for selling our movements without consent. Protect yourself: learn how they track you & what you can do
Read: https://thehackernews.com/2024/01/ftc-bans-inmarket-for-selling-precise.html
Read: https://thehackernews.com/2024/01/ftc-bans-inmarket-for-selling-precise.html
👍7
Hackers Feast on Unpatched ActiveMQ! CVE-2023-46604, a critical remote code execution flaw, is back in the spotlight.
Learn more: https://thehackernews.com/2024/01/apache-activemq-flaw-exploited-in-new.html
Update your Apache ASAP or risk ransomware, rootkits, and botnets.
Learn more: https://thehackernews.com/2024/01/apache-activemq-flaw-exploited-in-new.html
Update your Apache ASAP or risk ransomware, rootkits, and botnets.
👍9😁6
Java & Android libraries vulnerable to new supply chain attack — MavenGate!
Hackers can hijack popular abandoned libraries & inject malware into your apps.
Click to read more: https://thehackernews.com/2024/01/hackers-hijack-popular-java-and-android.html
Hackers can hijack popular abandoned libraries & inject malware into your apps.
Click to read more: https://thehackernews.com/2024/01/hackers-hijack-popular-java-and-android.html
😱19🤯7👍4
North Korea's ScarCruft targeting media & experts.
A new attack campaign using fake threat reports & infected ZIPs aimed at gathering intel on defense strategies.
Find details here: https://thehackernews.com/2024/01/north-korean-hackers-weaponize-fake.html
A new attack campaign using fake threat reports & infected ZIPs aimed at gathering intel on defense strategies.
Find details here: https://thehackernews.com/2024/01/north-korean-hackers-weaponize-fake.html
👍9🤔5😱5👏2
Cybercrime Marketplace Mastermind, 21, Walks Free (Mostly) – Fitzpatrick, the Creator of BreachForums, Avoids Prison but Faces 20 Years of Supervision.
Read: https://thehackernews.com/2024/01/breachforums-founder-sentenced-to-20.html
Read: https://thehackernews.com/2024/01/breachforums-founder-sentenced-to-20.html
🤔7👍4⚡3
Apple fixes first "in-the-wild" zero-day of 2024. Update iPhones, iPads, and Macs NOW!
Details: https://thehackernews.com/2024/01/apple-issues-patch-for-critical-zero.html
Details: https://thehackernews.com/2024/01/apple-issues-patch-for-critical-zero.html
🤯15👍9😁2
Atlassian Confluence RCE flaw under active attack (CVE-2023-22527). Hackers are scanning the web within 3 days of disclosure.
Learn more ➡️ https://thehackernews.com/2024/01/40000-attacks-in-3-days-critical.html
Patch NOW - Don't wait for a "whoami" knock at your server door.
Learn more ➡️ https://thehackernews.com/2024/01/40000-attacks-in-3-days-critical.html
Patch NOW - Don't wait for a "whoami" knock at your server door.
😱11👍6😁3