The Internet Systems Consortium (ISC) has released security patches for multiple new vulnerabilities in the BIND DNS software suite that could lead to a DoS condition and system failures.
Read: https://thehackernews.com/2023/01/isc-releases-security-patches-for-new.html
Read: https://thehackernews.com/2023/01/isc-releases-security-patches-for-new.html
🤯25👍13⚡7👏4😱3🤔1
Microsoft urges customers to keep their servers up to date and implement additional security measures, such as enabling Windows Extended Protection & configuring certificate-based signing of #PowerShell serialization payloads.
Read: https://thehackernews.com/2023/01/microsoft-urges-customers-to-secure-on.html
Read: https://thehackernews.com/2023/01/microsoft-urges-customers-to-secure-on.html
⚡34👍28😱7👏6😁2
Gootkit malware continues to evolve and become more sophisticated, with notable changes to the toolkit, adding new components and obfuscations to their infection chains.
Read: https://thehackernews.com/2023/01/gootkit-malware-continues-to-evolve.html
Read: https://thehackernews.com/2023/01/gootkit-malware-continues-to-evolve.html
🔥25👍21😱5😁4⚡3👏3
Urgent Alert — A critical RCE vulnerability in the Realtek Jungle SDK is being weaponized by attackers to hack IoT devices, with 134 MILLION exploitation attempts recorded in the past 2 months alone.
Read: https://thehackernews.com/2023/01/realtek-vulnerability-under-attack-134.html
Read: https://thehackernews.com/2023/01/realtek-vulnerability-under-attack-134.html
🤯16👍8😱7⚡5🔥5😁4
Beware of the latest cyber threat🚨
Hackers are distributing a new Golang-based info stealer malware, known as Titan Stealer, through Telegram channels to other cybercriminals — that can steal browser credentials, crypto wallets, and more.
Read: https://thehackernews.com/2023/01/titan-stealer-new-golang-based.html
Hackers are distributing a new Golang-based info stealer malware, known as Titan Stealer, through Telegram channels to other cybercriminals — that can steal browser credentials, crypto wallets, and more.
Read: https://thehackernews.com/2023/01/titan-stealer-new-golang-based.html
🤯41👍25🔥7⚡5😁5😱5👏3
GitHub reports unauthorized access 💻👮♂️ to Desktop & Atom apps repositories, leading to exposure of encrypted 🔒 code-signing certificates.
Read details: https://thehackernews.com/2023/01/github-breach-hackers-stole-code.html
Read details: https://thehackernews.com/2023/01/github-breach-hackers-stole-code.html
🤯21👍11😱8
Don't risk losing your data!
QNAP has released security updates to address a critical vulnerability (CVE-2022-27596 / CVSS 9.8) in the NAS devices QTS 5.0.1 & QuTS hero h5.0.1 that can be used to inject arbitrary code.
Read: https://thehackernews.com/2023/01/qnap-fixes-critical-vulnerability-in.html
QNAP has released security updates to address a critical vulnerability (CVE-2022-27596 / CVSS 9.8) in the NAS devices QTS 5.0.1 & QuTS hero h5.0.1 that can be used to inject arbitrary code.
Read: https://thehackernews.com/2023/01/qnap-fixes-critical-vulnerability-in.html
👍29🔥8🤯7👏4😁2
Think your EDR and antivirus have got you covered? Think again!
Researchers have uncovered a shellcode-based packer service that has been helping hackers hide their malware for the past 6 years, including Trickbot, Emotet, REvil, Formbook & AgentTesla.
https://thehackernews.com/2023/01/researchers-uncover-packer-that-helped.html
Researchers have uncovered a shellcode-based packer service that has been helping hackers hide their malware for the past 6 years, including Trickbot, Emotet, REvil, Formbook & AgentTesla.
https://thehackernews.com/2023/01/researchers-uncover-packer-that-helped.html
👍33🔥13🤯10🤔8⚡6
Two more supply chain vulnerabilities disclosed in AMI MegaRAC BMC software, affecting multiple server brands.
Read: https://thehackernews.com/2023/02/additional-supply-chain-vulnerabilities.html
Read: https://thehackernews.com/2023/02/additional-supply-chain-vulnerabilities.html
👍19🤔9🔥7😱5
Hackers abused Microsoft's "Verified Publisher" accounts to create malicious OAuth apps as part of a vicious scheme aimed at infiltrating organizations' cloud environments and stealing email.
https://thehackernews.com/2023/02/hackers-abused-microsofts-verified.html
https://thehackernews.com/2023/02/hackers-abused-microsofts-verified.html
😱26👍15🤯3😁1
Prilex POS malware has evolved to block contactless payments and force victims to use physical cards for transactions in order to steal payment information.
Read: https://thehackernews.com/2023/02/prilex-pos-malware-evolves-to-block.html
Read: https://thehackernews.com/2023/02/prilex-pos-malware-evolves-to-block.html
👍24🤯9🔥5🤔4👏3😁3😱1
⚡ New SH1MMER Chromebook exploit can unenroll 🔓 enterprise or school managed ChromeOS 💻 devices from admin control.
https://thehackernews.com/2023/02/new-sh1mmer-exploit-for-chromebook.html
https://thehackernews.com/2023/02/new-sh1mmer-exploit-for-chromebook.html
😱23👍16🔥13😁8🤔3
Researchers discover new vulnerabilities in the ImageMagick image processing program that could lead to DoS (CVE-2022-44267) or arbitrary remote file leaks (CVE-2022-44268).
https://thehackernews.com/2023/02/researchers-uncover-new-bugs-in-popular.html
https://thehackernews.com/2023/02/researchers-uncover-new-bugs-in-popular.html
👍24🔥6😱6
🚨 HeadCrab Alert! A new stealthy botnet malware that is undetectable by various antivirus solutions has infected over 1,200 Redis servers worldwide for illegal cryptocurrency mining.
Read: https://thehackernews.com/2023/02/new-threat-stealthy-headcrab-malware.html
Read: https://thehackernews.com/2023/02/new-threat-stealthy-headcrab-malware.html
😁24👍14⚡2
North Korean Lazarus hacking group exploited unpatched Zimbra devices to invade healthcare research institutions, universities, and technology companies in various industries, including energy, research, and defense.
https://thehackernews.com/2023/02/north-korean-hackers-exploit-unpatched.html
https://thehackernews.com/2023/02/north-korean-hackers-exploit-unpatched.html
👏17👍10⚡8🔥8
Attention: Cyber criminals are actively exploiting known vulnerabilities in Oracle E-Business Suite (CVE-2022-21587) and SugarCRM (CVE-2023-22952) systems. Update now!
Read: https://thehackernews.com/2023/02/cisa-alert-oracle-e-business-suite-and.html
Read: https://thehackernews.com/2023/02/cisa-alert-oracle-e-business-suite-and.html
👍26😁5👏3
A new critical authentication vulnerability (CVE-2023-22501) has been discovered in Atlassian's Jira Service Management Server and Data Center products that could allow attackers to gain unauthorized access to vulnerable instances.
Read: https://thehackernews.com/2023/02/atlassians-jira-software-found.html
Read: https://thehackernews.com/2023/02/atlassians-jira-software-found.html
🔥18👍15👏1😁1
Iranian nation-state hacking group OilRig has increased its cyberattacks on Middle Eastern government organizations, wielding a backdoor with new data exfiltration capabilities.
Read: https://thehackernews.com/2023/02/iranian-oilrig-hackers-using-new.html
Read: https://thehackernews.com/2023/02/iranian-oilrig-hackers-using-new.html
👍15😁11🔥7👏1🤯1
A new critical authentication #vulnerability (CVE-2023-22501) has been discovered in Atlassian's Jira Service Management Server and Data Center products that could allow attackers to gain unauthorized access to vulnerable instances.
Read: https://thehackernews.com/2023/02/atlassians-jira-software-found.html
Read: https://thehackernews.com/2023/02/atlassians-jira-software-found.html
👍22🔥11🤔3👏2
Watch out! Microsoft OneNote documents are the latest weapon of choice for cybercriminals to spread malware.
From AsyncRAT to FormBook, the list of malware families delivered via OneNote attacks is growing rapidly.
Read: https://thehackernews.com/2023/02/post-macro-world-sees-rise-in-microsoft.html
From AsyncRAT to FormBook, the list of malware families delivered via OneNote attacks is growing rapidly.
Read: https://thehackernews.com/2023/02/post-macro-world-sees-rise-in-microsoft.html
🤯25👍9⚡5👏1