Cisco has just released a security update to fix a critical vulnerability (CVE-2023-20078) in its IP Phone 6800, 7800, 7900, and 8800 Series products.
Learn more: https://thehackernews.com/2023/03/critical-flaw-in-cisco-ip-phone-series.html
Learn more: https://thehackernews.com/2023/03/critical-flaw-in-cisco-ip-phone-series.html
🔥23👍8🤔2⚡1
Lucky Mouse hackers strike again with a new Linux version of SysUpdate malware toolkit that can now bypass security measures and evade reverse engineering.
Learn more: https://thehackernews.com/2023/03/sysupdate-malware-strikes-again-with.html
Learn more: https://thehackernews.com/2023/03/sysupdate-malware-strikes-again-with.html
🤯17👍15⚡9😁3👏2
A malicious Python package has been found on PyPI containing a fully-featured information stealer and remote access trojan.
Learn more: https://thehackernews.com/2023/03/experts-identify-fully-featured-info.html
Learn more: https://thehackernews.com/2023/03/experts-identify-fully-featured-info.html
🔥27👍11😱4⚡3🤔1
Watch out! A new cryptojacking scheme is in town, preying on poorly configured Redis database servers and using the trusted file transfer service transfer[.]sh to sneak in their malicious payloads.
Learn more: https://thehackernews.com/2023/03/new-cryptojacking-campaign-leverages.html
Learn more: https://thehackernews.com/2023/03/new-cryptojacking-campaign-leverages.html
👍19🤯5🔥4⚡3🤔3
Beware of SCARLETEEL!
The latest cyber attack 🔒👨💻 targeting containerized 💻 environments to steal proprietary data and software but using crypto-miner malware to distract defenders.
Learn more: https://thehackernews.com/2023/03/hackers-exploit-containerized.html
The latest cyber attack 🔒👨💻 targeting containerized 💻 environments to steal proprietary data and software but using crypto-miner malware to distract defenders.
Learn more: https://thehackernews.com/2023/03/hackers-exploit-containerized.html
🔥19👍9😁9⚡6
China-based hackers Mustang Panda are using a new custom backdoor called MQsTTang in their latest social engineering campaign against European entities.
Learn more: https://thehackernews.com/2023/03/chinese-hackers-targeting-european.html
Learn more: https://thehackernews.com/2023/03/chinese-hackers-targeting-european.html
🤔8👍7⚡6🔥5👏4🤯2
🚨 ALERT: Royal ransomware is back and targeting U.S. and international organizations!
It infiltrates networks, disables #antivirus software and steals data before deploying ransomware.
Learn how to protect yourself with CISA's latest advisory: https://thehackernews.com/2023/03/us-cybersecurity-agency-raises-alarm.html
It infiltrates networks, disables #antivirus software and steals data before deploying ransomware.
Learn how to protect yourself with CISA's latest advisory: https://thehackernews.com/2023/03/us-cybersecurity-agency-raises-alarm.html
👍26😱10⚡9👏3😁3
Heads up, techies! Experts have uncovered 2 severe vulnerabilities in TPM 2.0 library that could impact billions of devices, including enterprise computers, IoT devices, and embedded systems.
Read: https://thehackernews.com/2023/03/new-flaws-in-tpm-20-library-pose-threat.html
Read: https://thehackernews.com/2023/03/new-flaws-in-tpm-20-library-pose-threat.html
🤯33👍17⚡7🔥7😁3
A new ATM #malware strain dubbed FiXS has been observed targeting Mexican banks.
It is hidden inside a not-malicious-looking program, is vendor-agnostic, and is capable of infecting any teller machine that supports CEN/XFS.
Learn more: https://thehackernews.com/2023/03/new-fixs-atm-malware-targeting-mexican.html
It is hidden inside a not-malicious-looking program, is vendor-agnostic, and is capable of infecting any teller machine that supports CEN/XFS.
Learn more: https://thehackernews.com/2023/03/new-fixs-atm-malware-targeting-mexican.html
⚡23👍14😱6🔥4🤯4
Ready to bust the 9 most dangerous myths about file-based attacks?
Join our upcoming WEBINAR and become a hero in the fight against patient zero infections and zero-day security events!
Watch it here: https://thehacker.news/file-based-threats-webinar
Join our upcoming WEBINAR and become a hero in the fight against patient zero infections and zero-day security events!
Watch it here: https://thehacker.news/file-based-threats-webinar
thehacker.news
A MythBusting Special — 9 Myths about File-based Threats
Cybersecurity Webinar: Say goodbye to the myths and hello to the facts - Register for our webinar on file-based threats now!
👍47⚡9😱7🔥4🤔1
⚡ Researchers have discovered new side-channel attacks on the CRYSTALS-Kyber encryption algorithm, which the U.S. government selected last year as a quantum-resistant algorithm.
Learn more: https://thehackernews.com/2023/03/experts-discover-flaw-in-us-govts.html
Learn more: https://thehackernews.com/2023/03/experts-discover-flaw-in-us-govts.html
👍21⚡7🔥6😁6🤯2
Researchers warn that "insufficient" forensic visibility into Google Cloud Platform could leave organizations blind to potential data exfiltration attacks.
Learn more: https://thehackernews.com/2023/03/experts-reveal-google-cloud-platforms.html
Learn more: https://thehackernews.com/2023/03/experts-reveal-google-cloud-platforms.html
👍27⚡4😁4😱1
Suspected core members of the DoppelPaymer ransomware group, responsible for numerous large-scale cyberattacks, have been arrested by German and Ukrainian authorities with support of Dutch police & the FBI.
Read: https://thehackernews.com/2023/03/core-members-of-doppelpaymer-ransomware.html
Read: https://thehackernews.com/2023/03/core-members-of-doppelpaymer-ransomware.html
👍32⚡8🤯5👏4😱3
🚨 Heads up, fashionistas!
If you're using the Shein shopping app, beware of a recent bug that has been capturing and transmitting your clipboard contents to a remote server.
Learn more: https://thehackernews.com/2023/03/sheins-android-app-caught-transmitting.html
If you're using the Shein shopping app, beware of a recent bug that has been capturing and transmitting your clipboard contents to a remote server.
Learn more: https://thehackernews.com/2023/03/sheins-android-app-caught-transmitting.html
😁15👍12🤔8⚡3🤯1
Recent LastPass breach was caused by a simple mistake - an engineer's failure to update Plex software on his home computer.
Read: https://thehackernews.com/2023/03/lastpass-hack-engineers-failure-to.html
This is a stark reminder of the importance of keeping software up to date to prevent vulnerabilities from being exploited.
Read: https://thehackernews.com/2023/03/lastpass-hack-engineers-failure-to.html
This is a stark reminder of the importance of keeping software up to date to prevent vulnerabilities from being exploited.
🤯52👍14😁12👏10⚡5
🚨 ALERT! If you're using MeetsApp or MeetUp on your Android device, you need to be aware of this!
Pakistani hackers are using these apps to target political and military personalities in India with CapraRAT backdoor.
Learn more: https://thehackernews.com/2023/03/transparent-tribe-hackers-distribute.html
Pakistani hackers are using these apps to target political and military personalities in India with CapraRAT backdoor.
Learn more: https://thehackernews.com/2023/03/transparent-tribe-hackers-distribute.html
👍34😱10⚡9🔥9😁6🤯1
Cybersecurity researchers have discovered a new information stealer, dubbed "SYS01stealer," targeting critical government infrastructure employees, manufacturing companies, and other sectors.
Learn more about it here: https://thehackernews.com/2023/03/sys01stealer-new-threat-using-facebook.html
Learn more about it here: https://thehackernews.com/2023/03/sys01stealer-new-threat-using-facebook.html
👍26🤯8⚡3👏3😁2
Chinese cyberespionage hackers are targeting high-profile government entities in Southeast Asia with a new version of the Soul modular framework.
Learn more: https://thehackernews.com/2023/03/sharp-panda-using-new-soul-framework.html
Learn more: https://thehackernews.com/2023/03/sharp-panda-using-new-soul-framework.html
😱16👍7🔥5⚡3🤯3👏2
CISA has added 3 more flaws to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation:
CVE-2022-35914 - Teclib GLPI RCE
CVE-2022-33891 - Apache Spark Command Injection
CVE-2022-28810 - Zoho ADSelfService Plus RCE
Read: https://thehackernews.com/2023/03/cisas-kev-catalog-updated-with-3-new.html
CVE-2022-35914 - Teclib GLPI RCE
CVE-2022-33891 - Apache Spark Command Injection
CVE-2022-28810 - Zoho ADSelfService Plus RCE
Read: https://thehackernews.com/2023/03/cisas-kev-catalog-updated-with-3-new.html
👍24🔥8⚡6😁4
North Korea-linked Lazarus Group targeted a South Korean financial firm by exploiting a zero-day vulnerability in certificate software.
Learn more: https://thehackernews.com/2023/03/lazarus-group-exploits-zero-day.html
Learn more: https://thehackernews.com/2023/03/lazarus-group-exploits-zero-day.html
👍28🔥9⚡6😁2