Researchers have uncovered a multi-stage attack involving infected sites, fake Chrome updates, and a JScript downloader to deploy the BadSpace malware.
Learn how to spot and avoid these deceptive prompts: https://thehackernews.com/2024/06/hackers-exploit-legitimate-websites-to.html
Learn how to spot and avoid these deceptive prompts: https://thehackernews.com/2024/06/hackers-exploit-legitimate-websites-to.html
π₯12π10π5π±5β‘1
Researchers reveal 3-year cyber espionage campaign by China-linked Velvet Ant group, exploiting F5 BIG-IP for persistence and deploying PlugX malware variants.
Read details: https://thehackernews.com/2024/06/china-linked-hackers-infiltrate-east.html
Read details: https://thehackernews.com/2024/06/china-linked-hackers-infiltrate-east.html
π₯15π6
ASUS releases crucial updates for multiple router models to address critical authentication bypass and buffer overflow vulnerabilities.
Read: https://thehackernews.com/2024/06/asus-patches-critical-authentication.html
Read: https://thehackernews.com/2024/06/asus-patches-critical-authentication.html
π₯14π11
Learn how integrating security early in DevOps with DevSecOps practices enhances productivity and ensures software integrity
Read: https://thehackernews.com/2024/06/what-is-devsecops-and-why-is-it.html
Read: https://thehackernews.com/2024/06/what-is-devsecops-and-why-is-it.html
π₯15π10
π¨ Major cybercrime busts!
1οΈβ£ Two extradited to Singapore for mobile malware, 4,000+ victims.
2οΈβ£ Taiwan arrests 4 for unauthorized bank transfers, $1.33M seized.
3οΈβ£ U.S. charges 2 for Empire Market, $430M in illegal trades.
Read: https://thehackernews.com/2024/06/singapore-police-extradites-malaysians.html
1οΈβ£ Two extradited to Singapore for mobile malware, 4,000+ victims.
2οΈβ£ Taiwan arrests 4 for unauthorized bank transfers, $1.33M seized.
3οΈβ£ U.S. charges 2 for Empire Market, $430M in illegal trades.
Read: https://thehackernews.com/2024/06/singapore-police-extradites-malaysians.html
π€―17π16π4
VMware has released patches for Cloud Foundation, vCenter Server, and vSphere ESXi to fix critical flaws that could allow RCE and privilege escalation.
Learn more about CVE-2024-37079, CVE-2024-37080 & CVE-2024-37081βand secure your infrastructure now.
https://thehackernews.com/2024/06/vmware-issues-patches-for-cloud.html
Learn more about CVE-2024-37079, CVE-2024-37080 & CVE-2024-37081βand secure your infrastructure now.
https://thehackernews.com/2024/06/vmware-issues-patches-for-cloud.html
π13π₯7β‘5
Researchers uncover a new malware campaign targeting exposed Docker API endpoints to deliver cryptocurrency miners and remote access tools.
Learn more: https://thehackernews.com/2024/06/new-malware-targets-exposed-docker-apis.html
Learn more: https://thehackernews.com/2024/06/new-malware-targets-exposed-docker-apis.html
π20π±4β‘3
Cybercriminals exploit free software lures, SEO tricks and social engineering tactics to deploy Hijack Loader, Vidar Stealer, and other malware, targeting unsuspecting users.
Read: https://thehackernews.com/2024/06/cybercriminals-exploit-free-software.html
Read: https://thehackernews.com/2024/06/cybercriminals-exploit-free-software.html
π13π₯7β‘6
EU's controversial proposal to scan private messages for CSAM detection raises alarms for end-to-end encryption.
Signal Foundation president warns of severe risks. Learn more: https://thehackernews.com/2024/06/signal-foundation-warns-against-eus.html
Signal Foundation president warns of severe risks. Learn more: https://thehackernews.com/2024/06/signal-foundation-warns-against-eus.html
π€―21π6π₯6π±5π2
Explore the latest trends in SaaS security investment and challenges. Discover how enterprises are enhancing their security strategies to protect critical data and operations.
Read: https://thehackernews.com/2024/06/the-annual-saas-security-report-2025.html
Read: https://thehackernews.com/2024/06/the-annual-saas-security-report-2025.html
π13π±8π₯5π€―3
π¨ Attention: Researchers uncover security flaws in the Mailcow mail server suite, affecting all versions prior to 2024-04.
These vulnerabilities allow for arbitrary code execution and admin account takeover.
Find details here: https://thehackernews.com/2024/06/mailcow-mail-server-flaws-expose.html
These vulnerabilities allow for arbitrary code execution and admin account takeover.
Find details here: https://thehackernews.com/2024/06/mailcow-mail-server-flaws-expose.html
π₯8π±7π5π4
β οΈ Alert: A new large-scale scam by "markopolo" targets cryptocurrency users with malware-infected applications like Vortax to deliver information stealers such as Rhadamanthys, StealC, and Atomic #macOS Stealer.
π Don't fall for itβget details: https://thehackernews.com/2024/06/warning-markopolos-scam-targeting.html
π Don't fall for itβget details: https://thehackernews.com/2024/06/warning-markopolos-scam-targeting.html
π±10π8π₯4
Void Arachne targets Chinese-speaking users with malicious VPN installers.
This sophisticated attack employs SEO poisoning and promotes compromised MSI files containing nudifiers, deepfake porno-generating software, and AI voice and facial technologies.
https://thehackernews.com/2024/06/void-arachne-uses-deepfakes-and-ai-to.html
This sophisticated attack employs SEO poisoning and promotes compromised MSI files containing nudifiers, deepfake porno-generating software, and AI voice and facial technologies.
https://thehackernews.com/2024/06/void-arachne-uses-deepfakes-and-ai-to.html
π±15π₯9π6π3
Explore the dangers of Google Tag Manager misconfigurations with real-world examples.
Learn how to safeguard your data and comply with privacy laws.
Read: https://thehackernews.com/2024/06/new-case-study-unmanaged-gtm-tags.html
Learn how to safeguard your data and comply with privacy laws.
Read: https://thehackernews.com/2024/06/new-case-study-unmanaged-gtm-tags.html
π12π9π±4π€3
China-linked cyber espionage group UNC3886 exploits zero-day vulnerabilities in Fortinet, Ivanti, and VMware devices and evading detection with advanced techniques.
Discover how they operate: https://thehackernews.com/2024/06/chinese-cyber-espionage-group-exploits.html
Discover how they operate: https://thehackernews.com/2024/06/chinese-cyber-espionage-group-exploits.html
π₯17π8π6π±1
β‘ Kraken exchange hacked: $3 Million stolen due to zero-day flaw. Researcher exploits bug, extorts company, refuses to return funds.
Read: https://thehackernews.com/2024/06/kraken-crypto-exchange-hit-by-3-million.html
Kraken working with law enforcement, calls actions criminal.
Read: https://thehackernews.com/2024/06/kraken-crypto-exchange-hit-by-3-million.html
Kraken working with law enforcement, calls actions criminal.
π37π9π±9β‘3π€3
Discover the latest evasive malware loader, SquidLoader, targeting Chinese organizations via phishing emails. Learn about its advanced anti-analysis techniques and the ongoing threat of loader malware.
Details β‘οΈ https://thehackernews.com/2024/06/experts-uncover-new-evasive-squidloader.html
Details β‘οΈ https://thehackernews.com/2024/06/experts-uncover-new-evasive-squidloader.html
π₯9π5π2π€―2π€1π±1
π Fickle Stealer, a new Rust-based malware, and AZStealer, an open-source Python stealer, target sensitive data from crypto wallets, browsers, and more through multiple attack chains and exfiltration methods.
Learn more: https://thehackernews.com/2024/06/new-rust-based-fickle-malware-uses.html
Learn more: https://thehackernews.com/2024/06/new-rust-based-fickle-malware-uses.html
π₯11π±5π4π2
Chinese-linked cyber espionage groups have been uncovered in a long-term infiltration of telecom operators in Asia since 2021, deploying custom malware and stealing credentials.
Read: https://thehackernews.com/2024/06/chinese-cyber-espionage-targets-telecom.html
Read: https://thehackernews.com/2024/06/chinese-cyber-espionage-targets-telecom.html
π₯10π8π±7π2π€―2
Explore the challenges MSPs face with too many cybersecurity tools and discover how Guardz's unified platform simplifies operations and enhances security.
Read: https://thehackernews.com/2024/06/tool-overload-why-msps-are-still.html
Read: https://thehackernews.com/2024/06/tool-overload-why-msps-are-still.html
π13π7π±3π€2π1