โ ๏ธ Six critical security flaws have been discovered in the Ollama AI framework, enabling potential model poisoning and theft. With a staggering number of unpatched instances, itโs crucial to filter internet-facing endpoints effectively.
Read: https://thehackernews.com/2024/11/critical-flaws-in-ollama-ai-framework.html
Read: https://thehackernews.com/2024/11/critical-flaws-in-ollama-ai-framework.html
๐8๐4โก2
๐ป Don't miss out on our latest #cybersecurity newsletter!
This week, we're diving into the chaos as hackers ramp up attacks, including North Korean ransomware collaboration and evasive password spraying tactics.
https://thehackernews.com/2024/11/thn-recap-top-cybersecurity-threats.html
This week, we're diving into the chaos as hackers ramp up attacks, including North Korean ransomware collaboration and evasive password spraying tactics.
https://thehackernews.com/2024/11/thn-recap-top-cybersecurity-threats.html
๐ฅ10๐8๐3๐คฏ3โก1
Google warns of active exploitation of CVE-2024-43093 in Android.
This #vulnerability allows unauthorized access to critical directories, emphasizing the need for timely updates and patching processes.
https://thehackernews.com/2024/11/google-warns-of-actively-exploited-cve.html
This #vulnerability allows unauthorized access to critical directories, emphasizing the need for timely updates and patching processes.
https://thehackernews.com/2024/11/google-warns-of-actively-exploited-cve.html
๐ฅ16๐11๐4โก3๐ฑ2๐ค1
Canadian authorities have arrested Alexander "Connor" Moucka, a suspect in the Snowflake data breach that impacted around 165 organizations, including major corporations like AT&T and Ticketmaster, some of which were extorted for large sums.
https://thehackernews.com/2024/11/canadian-suspect-arrested-over.html
https://thehackernews.com/2024/11/canadian-suspect-arrested-over.html
๐21๐คฏ6โก3๐3
Synology has released a patch for a critical zero-day vulnerability (CVE-2024-10443) affecting millions of NAS devices, which allows remote code execution without user interaction.
Read: https://thehackernews.com/2024/11/synology-urges-patch-for-critical-zero.html
Read: https://thehackernews.com/2024/11/synology-urges-patch-for-critical-zero.html
๐14โก3๐ฑ3
๐จ Hundreds of typosquatted versions targeting npm developers are attempting to deliver cross-platform #malware by employing Ethereum smart contracts for command-and-control (C2) communications.
Read: https://thehackernews.com/2024/11/malware-campaign-uses-ethereum-smart.html
Read: https://thehackernews.com/2024/11/malware-campaign-uses-ethereum-smart.html
โก5๐4๐1
The Android banking malware "ToxicPanda" has infected over 1,500 devices, facilitating fraudulent transactions by bypassing security measures.
It disguises itself as legitimate apps and intercepts OTPs for unauthorized access.
Read: https://thehackernews.com/2024/11/new-android-banking-malware-toxicpanda.html
It disguises itself as legitimate apps and intercepts OTPs for unauthorized access.
Read: https://thehackernews.com/2024/11/new-android-banking-malware-toxicpanda.html
๐ฅ9๐7๐5
Explore how Zero Trust security transforms #cybersecurity by eliminating implicit trust, scrutinizing access requests, and continuously monitoring users to mitigate insider threats and enhance security posture.
Read: https://thehackernews.com/2024/11/leveraging-wazuh-for-zero-trust-security.html
Read: https://thehackernews.com/2024/11/leveraging-wazuh-for-zero-trust-security.html
๐15
The FBI is seeking public assistance to identify those behind cyber intrusions linked to Chinese APT groups that have exploited vulnerabilities in edge devices and networks for cyber espionage against critical infrastructure.
Learn more: https://thehackernews.com/2024/11/fbi-seeks-public-help-to-identify.html
Learn more: https://thehackernews.com/2024/11/fbi-seeks-public-help-to-identify.html
๐25๐11โก2๐ฅ2
Google Cloud will enforce mandatory multi-factor authentication (MFA) for all users by the end of 2025
Learn more: https://thehackernews.com/2024/11/google-cloud-to-enforce-multi-factor.html
Learn more: https://thehackernews.com/2024/11/google-cloud-to-enforce-multi-factor.html
๐26โก9๐7๐ค4๐คฏ1
South Korea fined Meta $15.67 million for sharing sensitive data from 980,000 users with advertisers without proper consent.
Learn more: https://thehackernews.com/2024/11/south-korea-fines-meta-1567m-for.html
Learn more: https://thehackernews.com/2024/11/south-korea-fines-meta-1567m-for.html
๐28๐7๐ฅ5โก4๐ฑ3๐2
INTERPOL has taken down over 22,000 malicious servers in its Operation Synergia II, targeting phishing, ransomware, and malware.
Learn more: https://thehackernews.com/2024/11/interpols-operation-synergia-ii.html
Learn more: https://thehackernews.com/2024/11/interpols-operation-synergia-ii.html
๐22โก6๐4๐ค3๐คฏ2๐ฑ1
Continuous Threat Exposure Management (CTEM) is no longer optionalโit's essential!
As threats evolve, CTEM empowers organizations to proactively identify and mitigate vulnerabilities before they lead to costly breaches. ๐
Read the full article to discover how to keep CTEM on your 2025 budget radar: https://thehackernews.com/2024/11/9-steps-to-get-ctem-on-your-2025.html
As threats evolve, CTEM empowers organizations to proactively identify and mitigate vulnerabilities before they lead to costly breaches. ๐
Read the full article to discover how to keep CTEM on your 2025 budget radar: https://thehackernews.com/2024/11/9-steps-to-get-ctem-on-your-2025.html
๐9โก6๐6
๐จ Warning: New Winos 4.0 malware is targeting users through ๐ฎ gaming applications. This advanced framework can take control of compromised systems and harvest sensitive data, targeting educational organizations and cryptocurrency wallets.
Read: https://thehackernews.com/2024/11/new-winos-40-malware-infects-gamers.html
Read: https://thehackernews.com/2024/11/new-winos-40-malware-infects-gamers.html
๐7๐ฅ4๐2๐คฏ2
๐ฅ Did you know? Advanced threat actors can breach identity systems in days.
Learn about SaaS and cloud vulnerabilities. Join our LIVE WEBINAR to learn crucial strategies for securing your identity infrastructure.
๐ Join now: https://thehacker.news/identity-based-attacks
Learn about SaaS and cloud vulnerabilities. Join our LIVE WEBINAR to learn crucial strategies for securing your identity infrastructure.
๐ Join now: https://thehacker.news/identity-based-attacks
thehacker.news
How LUCR-3 (Scattered Spider) Orchestrates Identity-Based Attacks Across Multiple Environments
Uncovering the Tactics Advanced Attackers Use to Exploit SaaS and Cloud Vulnerabilities
๐17๐7
๐ Canada orders TikTok to shut down operations over national security concerns.
Read more here: https://thehackernews.com/2024/11/canada-orders-tiktok-to-shut-down.html
Read more here: https://thehackernews.com/2024/11/canada-orders-tiktok-to-shut-down.html
๐26๐14โก8๐5๐ค5๐ฅ1
๐ฉ๏ธ Cyber Alert: VEILDrive Attack!
A new attack exploits Microsoft SaaS tools like Teams and OneDrive, enabling malware distribution through trusted channels.
Read the article: https://thehackernews.com/2024/11/veildrive-attack-exploits-microsoft.html
A new attack exploits Microsoft SaaS tools like Teams and OneDrive, enabling malware distribution through trusted channels.
Read the article: https://thehackernews.com/2024/11/veildrive-attack-exploits-microsoft.html
๐14โก10๐6
๐จ Cisco has issued updates for CVE-2024-20418, a critical vulnerability in Ultra-Reliable Wireless Backhaul Access Points (CVSS: 10.0) that allows unauthorized root command execution.
Read: https://thehackernews.com/2024/11/cisco-releases-patch-for-critical-urwb.html
Update to version 17.15.1 ASAP to protect your network!
Read: https://thehackernews.com/2024/11/cisco-releases-patch-for-critical-urwb.html
Update to version 17.15.1 ASAP to protect your network!
๐13โก6๐3๐ฅ3๐ฑ1
๐ป๐ Developers, beware!
A malicious package named "fabrice" has been discovered on PyPI, stealthily stealing AWS credentials for over three years.
With more than 37,100 downloads, this typosquatting threat poses serious risks.
Read: https://thehackernews.com/2024/11/malicious-pypi-package-fabrice-found.html
A malicious package named "fabrice" has been discovered on PyPI, stealthily stealing AWS credentials for over three years.
With more than 37,100 downloads, this typosquatting threat poses serious risks.
Read: https://thehackernews.com/2024/11/malicious-pypi-package-fabrice-found.html
๐ฑ13๐8โก3๐คฏ2
๐จ Cyber alert: The CopyRh(ight)adamantys phishing campaign is leveraging copyright themes to spread the Rhadamanthys stealer, while Kaspersky reveals SteelFox #malware, exploiting vulnerable drivers for data theft.
Learn more: https://thehackernews.com/2024/11/steelfox-and-rhadamanthys-malware-use.html
Learn more: https://thehackernews.com/2024/11/steelfox-and-rhadamanthys-malware-use.html
โก6๐ฅ5๐2