π¨ Cisco patches a serious flaw in Unity Connection (CVE-2024-20272, CVSS 7.3).
Don't let attackers compromise your system. Check if your version is affected and update now.
Full details here π https://thehackernews.com/2024/01/cisco-fixes-high-risk-vulnerability.html
Don't let attackers compromise your system. Check if your version is affected and update now.
Full details here π https://thehackernews.com/2024/01/cisco-fixes-high-risk-vulnerability.html
π12β‘5π2
β οΈ Urgent Alert: Chinese hackers exploiting two NEW ZERO-DAY vulnerabilities (CVE-2023-46805 & CVE-2024-21887) in Ivanti Connect Secure and Policy Secure.
Read more: https://thehackernews.com/2024/01/chinese-hackers-exploit-zero-day-flaws.html
Patches incoming, but immediate action (temporary workarounds) is needed.
Read more: https://thehackernews.com/2024/01/chinese-hackers-exploit-zero-day-flaws.html
Patches incoming, but immediate action (temporary workarounds) is needed.
π₯16π€―7π6π3π€2
Mandiant's X account fell to a brute-force password attack due to a gap in 2FA policy during team transitions.
More: https://thehackernews.com/2024/01/mandiants-x-account-was-hacked-using.html
Hackers used it for phishing, stealing almost $900K in Solana tokens.
A reminder that small oversights can cause significant breaches.
More: https://thehackernews.com/2024/01/mandiants-x-account-was-hacked-using.html
Hackers used it for phishing, stealing almost $900K in Solana tokens.
A reminder that small oversights can cause significant breaches.
π±13β‘8π6π₯4π2
π Attention Mac users! Atomic Stealer malware gets updated to evade detection with payload encryption, stealing your passwords and sensitive info.
Learn more: https://thehackernews.com/2024/01/atomic-stealer-gets-upgrade-targeting.html
Learn more: https://thehackernews.com/2024/01/atomic-stealer-gets-upgrade-targeting.html
π±13π7π3π₯2
π Ransomware incidents hit a new high in 2023, targeting major players like MGM & Johnson Controls. Discover how #GenAI is revolutionizing cyber threats and why your organization should be concerned.
Read insights here: https://thehackernews.com/2024/01/there-is-ransomware-armageddon-coming.html
Read insights here: https://thehackernews.com/2024/01/there-is-ransomware-armageddon-coming.html
π€10π5π4π1
π¨ FBot, a new Python-based hacking tool, is targeting major platforms like AWS, Microsoft 365, and PayPal. It's designed for credential harvesting and account hijacking.
Discover more about it: https://thehackernews.com/2024/01/new-python-based-fbot-hacking-toolkit.html
Discover more about it: https://thehackernews.com/2024/01/new-python-based-fbot-hacking-toolkit.html
π10π€―6π2
π₯ Researchers develop a Proof-of-Concept code targeting a critical flaw in Apache OfBiz ERP system, enabling execution of a stealthy, memory-resident payload.
Learn more: https://thehackernews.com/2024/01/new-poc-exploit-for-apache-ofbiz.html
Learn more: https://thehackernews.com/2024/01/new-poc-exploit-for-apache-ofbiz.html
π11π€6π3
Unravel the complexities of cloud security and reveal the attack paths and risks lurking in cloud environments and connected assets.
Learn how to proactively strengthen your defenses with Uptycs experts Sudarsan Kannan and Andre Rall in their upcoming #webinar βMastering Cloud Security''.
Join Now: https://thehackernews.co/3SeXdo8
Learn how to proactively strengthen your defenses with Uptycs experts Sudarsan Kannan and Andre Rall in their upcoming #webinar βMastering Cloud Security''.
Join Now: https://thehackernews.co/3SeXdo8
π₯10π9
Cybercriminals are increasingly using GitHub for malicious activities such as payload delivery and command-and-control operations.
Learn more about this evolving 'living-off-trusted-sites' threat. β‘οΈ https://thehackernews.com/2024/01/threat-actors-increasingly-abusing.html
Learn more about this evolving 'living-off-trusted-sites' threat. β‘οΈ https://thehackernews.com/2024/01/threat-actors-increasingly-abusing.html
π₯14π13π€―4
π» SharePoint users, beware!
U.S. cybersecurity agency warns of active exploitation of a critical Microsoft SharePoint flaw that can let attackers gain admin rights without any user action.
π οΈ Patch now: https://thehackernews.com/2024/01/act-now-cisa-flags-active-exploitation.html
U.S. cybersecurity agency warns of active exploitation of a critical Microsoft SharePoint flaw that can let attackers gain admin rights without any user action.
π οΈ Patch now: https://thehackernews.com/2024/01/act-now-cisa-flags-active-exploitation.html
π8π5π±5
π¨ New cyberattack targeting Apache Hadoop & Flink using misconfigurations to deploy crypto miners.
A crafty blend of packers & rootkits keeps this malware under the radar.
Dive into the details here: https://thehackernews.com/2024/01/cryptominers-targeting-misconfigured.html
A crafty blend of packers & rootkits keeps this malware under the radar.
Dive into the details here: https://thehackernews.com/2024/01/cryptominers-targeting-misconfigured.html
π13π₯7
Mike Tyson and Cybersecurity: More in Common Than You Think!
Learn how Tyson's famous words apply to cybersecurity preparedness; and how BAS keeps your security in fighting shape against evolving threats.
Read the full story at https://thehackernews.com/2024/01/applying-tyson-principle-to.html
Learn how Tyson's famous words apply to cybersecurity preparedness; and how BAS keeps your security in fighting shape against evolving threats.
Read the full story at https://thehackernews.com/2024/01/applying-tyson-principle-to.html
β‘9π4π2
GitLab users, beware! Security updates released to address critical vulnerabilities (CVE-2023-7028 and CVE-2023-5356).
One of these could allow account takeover without user interaction.
Find details here: https://thehackernews.com/2024/01/urgent-gitlab-releases-patch-for.html
One of these could allow account takeover without user interaction.
Find details here: https://thehackernews.com/2024/01/urgent-gitlab-releases-patch-for.html
β‘12π7
β οΈ Medusa ransomware escalates tactics beyond data leaks, now threatening physical violence.
Targeting tech companies, healthcare, and education sectors, it exploits flaws and employs "living off the land" techniques to remain undetected.
Read: https://thehackernews.com/2024/01/medusa-ransomware-on-rise-from-data.html
Targeting tech companies, healthcare, and education sectors, it exploits flaws and employs "living off the land" techniques to remain undetected.
Read: https://thehackernews.com/2024/01/medusa-ransomware-on-rise-from-data.html
π9π€―7β‘5π4π±2
β‘ Nation-state hackers weaponizing Ivanti Connect Secure VPN zero-days to deploy five malware families in a targeted cyber espionage campaign.
Learn more: https://thehackernews.com/2024/01/nation-state-actors-weaponize-ivanti.html
Patch ASAP!
Learn more: https://thehackernews.com/2024/01/nation-state-actors-weaponize-ivanti.html
Patch ASAP!
π₯14π9π±6β‘2
β οΈ Your cloud account could be mining cryptocurrency without you knowing!
29-year-old Ukrainian arrested for a major cryptojacking scheme, netting over $2 MILLION in profits.
Read details: https://thehackernews.com/2024/01/29-year-old-ukrainian-cryptojacking.html
29-year-old Ukrainian arrested for a major cryptojacking scheme, netting over $2 MILLION in profits.
Read details: https://thehackernews.com/2024/01/29-year-old-ukrainian-cryptojacking.html
π€―34π₯8π±8π4β‘1
π¨ Critical Update! Juniper Networks addresses a major 9.8-rated RCE vulnerability in SRX Series firewalls & EX Series switches.
CVE-2024-21591 details here: https://thehackernews.com/2024/01/critical-rce-vulnerability-uncovered-in.html
CVE-2024-21591 details here: https://thehackernews.com/2024/01/critical-rce-vulnerability-uncovered-in.html
π₯17π6π6π€1
Denmark's energy sector faced cyber threats in 2023 due to an old Zyxel firewall vulnerability. Forescout's report suggests Sandworm group may not be responsible.
Insightful details here β‘οΈ https://thehackernews.com/2024/01/new-findings-challenge-attribution-in.html
Insightful details here β‘οΈ https://thehackernews.com/2024/01/new-findings-challenge-attribution-in.html
π₯13π12
Environmental services hit by a massive 61,839% increase in DDoS attacks.
Gaming, gambling, telecoms... no industry is safe from HTTP DDoS attacks.
Read this latest report to understand the scope of these threats: https://thehackernews.com/2024/01/ddos-attacks-on-environmental-services.html
Gaming, gambling, telecoms... no industry is safe from HTTP DDoS attacks.
Read this latest report to understand the scope of these threats: https://thehackernews.com/2024/01/ddos-attacks-on-environmental-services.html
π15π8β‘5π₯5
β οΈ Over 7,100 WordPress sites have been hit by the 'Balada Injector' #malware, which exploits sites using a vulnerable version of the Popup Builder plugin.
Read More β‘οΈ https://thehackernews.com/2024/01/balada-injector-infects-over-7100.html
Read More β‘οΈ https://thehackernews.com/2024/01/balada-injector-infects-over-7100.html
π16π6π₯2