This severe vulnerability affecting the Amazon ECR Public Gallery may have opened the repositories to potential "deep #software supply chain" attacks.
Read: https://thehackernews.com/2022/12/serious-attacks-could-have-been-staged.html
Read: https://thehackernews.com/2022/12/serious-attacks-could-have-been-staged.html
🤯19👍10🔥4⚡1
Google launches open source availability of OSV-Scanner, a scanner that aims to offer easy access to vulnerability information about various projects.
Read: https://thehackernews.com/2022/12/google-launches-largest-distributed.html
Read: https://thehackernews.com/2022/12/google-launches-largest-distributed.html
🤔20👏12🔥9👍5⚡2
⚡ Zero-day vulnerability alert!
Apple has released security updates to patch a new "actively exploited" 0-day code execution vulnerability.
Make sure to update your iOS, iPadOS, macOS, tvOS, and Safari to keep your devices secure.
https://thehackernews.com/2022/12/new-actively-exploited-zero-day.html
Apple has released security updates to patch a new "actively exploited" 0-day code execution vulnerability.
Make sure to update your iOS, iPadOS, macOS, tvOS, and Safari to keep your devices secure.
https://thehackernews.com/2022/12/new-actively-exploited-zero-day.html
🔥26👍16😁6⚡4😱4
Warning: Hackers are exploiting a new critical zero-day RCE vulnerability (CVE-2022-27518) in Citrix ADC & Gateway to gain control of affected systems.
https://thehackernews.com/2022/12/hackers-actively-exploiting-citrix-adc.html
It is important that users apply latest security patches immediately to protect against this threat.
https://thehackernews.com/2022/12/hackers-actively-exploiting-citrix-adc.html
It is important that users apply latest security patches immediately to protect against this threat.
👍20😱11⚡2
⚡ Stay protected against new vulnerabilities and zero-day attacks by ensuring your devices are up to date with the latest December 2022 Patch Tuesday security updates from Microsoft, Adobe, Apple, Cisco and other major vendors.
https://thehackernews.com/2022/12/december-2022-patch-tuesday-get-latest.html
https://thehackernews.com/2022/12/december-2022-patch-tuesday-get-latest.html
🔥23👍14👏5⚡3
Researchers reveal attackers use legitimate Microsoft-signed drivers in ransomware and malware campaigns against various companies
Read: https://thehackernews.com/2022/12/ransomware-attackers-use-microsoft.html
Read: https://thehackernews.com/2022/12/ransomware-attackers-use-microsoft.html
⚡16🤯11👍10🔥4
New Go-Based "GoTrim" Botnet Threatens WordPress Sites: Protect Your Admin Account Now!
Details: https://thehackernews.com/2022/12/new-gotrim-botnet-attempting-to-break.html
Details: https://thehackernews.com/2022/12/new-gotrim-botnet-attempting-to-break.html
👍23😱12⚡9😁7
FBI has charged 6 individuals and seized 48 domains linked to DDoS-for-hire service platforms.
Read: https://thehackernews.com/2022/12/fbi-charges-6-seizes-48-domains-linked.html
Read: https://thehackernews.com/2022/12/fbi-charges-6-seizes-48-domains-linked.html
👏23👍8😁6🔥4⚡2
Have you heard about how attackers can use SVG files to secretly sneak QBot malware onto Windows systems?
Read this report for more details: https://thehackernews.com/2022/12/hacking-using-svg-files-to-smuggle-qbot.html
Read this report for more details: https://thehackernews.com/2022/12/hacking-using-svg-files-to-smuggle-qbot.html
🤯32👍9⚡6🔥3😁1
Open source repositories under attack: hackers flood NuGet, NPM, and PyPi with over 144,000 malicious packages
Details: https://thehackernews.com/2022/12/hackers-bombard-open-source.html
Details: https://thehackernews.com/2022/12/hackers-bombard-open-source.html
😱36👍14🤯10⚡9🔥7👏4🤔2
MoneyMonger!
Be on alert for a new Android malware campaign using money-lending apps to blackmail victims with stolen personal information.
Read: https://thehackernews.com/2022/12/android-malware-campaign-leverages.html
Be on alert for a new Android malware campaign using money-lending apps to blackmail victims with stolen personal information.
Read: https://thehackernews.com/2022/12/android-malware-campaign-leverages.html
😱19👍14⚡13🤯7🔥2
Windows users, beware!
Microsoft has reclassified SPNEGO Extended Negotiation Security vulnerability as CRITICAL because it can be exploited to perform RCE attacks via Windows app protocols that use authentication, such as HTTP, SMB, and RDP.
https://thehackernews.com/2022/12/microsoft-reclassifies-spnego-extended.html
Microsoft has reclassified SPNEGO Extended Negotiation Security vulnerability as CRITICAL because it can be exploited to perform RCE attacks via Windows app protocols that use authentication, such as HTTP, SMB, and RDP.
https://thehackernews.com/2022/12/microsoft-reclassifies-spnego-extended.html
🤯41👍18😁9⚡8🤔7🔥5
GitHub is making its secret scanning service available for free to all public repositories and also plans to require 2-factor authentication for "distinct groups of users."
Read: https://thehackernews.com/2022/12/github-announces-free-secret-scanning.html
Read: https://thehackernews.com/2022/12/github-announces-free-secret-scanning.html
👍23👏12😁1
U.S. cybersecurity agency CISA has added two critical vulnerabilities in Veeam Backup & Replication software to its list of known exploited vulnerabilities, as they are actively being exploited in attacks.
Details: https://thehackernews.com/2022/12/cisa-alert-veeam-backup-and-replication.html
Details: https://thehackernews.com/2022/12/cisa-alert-veeam-backup-and-replication.html
👍21😁2🔥1
NIST has formally retired the widely used 27-year-old SHA-1 cryptographic algorithm, bringing cryptographic security into the modern age.
Read: https://thehackernews.com/2022/12/goodbye-sha-1-nist-retires-27-year-old.html
Read: https://thehackernews.com/2022/12/goodbye-sha-1-nist-retires-27-year-old.html
👍48
Microsoft has identified a cross-platform botnet malware that is targeting private Minecraft servers with DDoS attacks.
Details: https://thehackernews.com/2022/12/minecraft-servers-under-attack.html
Details: https://thehackernews.com/2022/12/minecraft-servers-under-attack.html
👍29😱3🤔1🤯1
Chinese MirrorFace APT hacker group has been blamed for a malicious campaign aimed at Japanese political entities.
Read: https://thehackernews.com/2022/12/researchers-uncover-mirrorface-cyber.html
Read: https://thehackernews.com/2022/12/researchers-uncover-mirrorface-cyber.html
👍18😱7👏2🔥1
A former Twitter employee has been sentenced to three and a half years in prison for spying on data about certain individuals and passing it on to the Saudi government.
Read: https://thehackernews.com/2022/12/ex-twitter-employee-gets-35-years-jail.html
Read: https://thehackernews.com/2022/12/ex-twitter-employee-gets-35-years-jail.html
👍37🤯21😁15👏10🔥9⚡4
Researchers have uncovered a new cyberattack campaign targeting Ukrainian government entities via trojanized Windows 10 operating system installers to perform post-exploitation activities.
Read: https://thehackernews.com/2022/12/trojanized-windows-10-installer-used-in.html
Read: https://thehackernews.com/2022/12/trojanized-windows-10-installer-used-in.html
👍34🔥13🤯11🤔3😱3
Multiple high-severity vulnerabilities [CVE-2022-38023, CVE-2022-37966, CVE-2022-37967, CVE-2022-45141] have been discovered in Samba software that could potentially allow hackers to gain control of the affected systems.
Read: https://thehackernews.com/2022/12/samba-issues-security-updates-to-patch.html
Read: https://thehackernews.com/2022/12/samba-issues-security-updates-to-patch.html
👍32😱16🔥10⚡6🤯5😁3🤔2