The Hacker News

Syndikovat obsah
The Hacker News has been internationally recognized as a leading news source dedicated to promoting awareness for security experts and hackersSwati Khandelwal
Aktualizace: 52 min 49 sek zpět

New Orchard Botnet Uses Bitcoin Founder’s Account Info to Generate Malicious Domains

8 Srpen, 2022 - 15:55
A new botnet named Orchard has been observed using Bitcoin creator Satoshi Nakamoto's account transaction information to generate domain names to conceal its command-and-control (C2) infrastructure. "Because of the uncertainty of Bitcoin transactions, this technique is more unpredictable than using the common time-generated [domain generation algorithms], and thus more difficult to defend Ravie Lakshmanan
Kategorie: Hacking & Security

The Benefits of Building a Mature and Diverse Blue Team

8 Srpen, 2022 - 15:43
A few days ago, a friend and I were having a rather engaging conversation that sparked my excitement. We were discussing my prospects of becoming a red teamer as a natural career progression. The reason I got stirred up is not that I want to change either my job or my position, as I am a happy camper being part of Cymulate's blue team. What upset me was that my friend could not grasp the idea The Hacker News
Kategorie: Hacking & Security

Researchers Uncover Classiscam Scam-as-a-Service Operations in Singapore

8 Srpen, 2022 - 15:37
A sophisticated scam-as-a-service operation dubbed Classiscam has now infiltrated into Singapore, more than 1.5 years after expanding to Europe. "Scammers posing as legitimate buyers approach sellers with the request to purchase goods from their listings and the ultimate aim of stealing payment data," Group-IB said in a report shared with The Hacker News. The cybersecurity firm called the Ravie Lakshmanan
Kategorie: Hacking & Security

Meta Cracks Down on Cyber Espionage Operations in South Asia Abusing Facebook

8 Srpen, 2022 - 09:00
Facebook parent company Meta disclosed that it took action against two espionage operations in South Asia that leveraged its social media platforms to distribute malware to potential targets. The first set of activities is what the company described as "persistent and well-resourced" and undertaken by a hacking group tracked under the moniker Bitter APT (aka APT-C-08 or T-APT-17) targeting Ravie Lakshmanan
Kategorie: Hacking & Security

New IoT RapperBot Malware Targeting Linux Servers via SSH Brute-Forcing Attack

7 Srpen, 2022 - 06:29
A new IoT botnet malware dubbed RapperBot has been observed rapidly evolving its capabilities since it was first discovered in mid-June 2022. "This family borrows heavily from the original Mirai source code, but what separates it from other IoT malware families is its built-in capability to brute force credentials and gain access to SSH servers instead of Telnet as implemented in Mirai," Ravie Lakshmanan
Kategorie: Hacking & Security

Hackers Exploit Twitter Vulnerability to Exposes 5.4 Million Accounts

6 Srpen, 2022 - 11:10
Twitter on Friday revealed that a now-patched zero-day bug was used to link phone numbers and emails to user accounts on the social media platform. "As a result of the vulnerability, if someone submitted an email address or phone number to Twitter's systems, Twitter's systems would tell the person what Twitter account the submitted email addresses or phone number was associated with, if any," Ravie Lakshmanan
Kategorie: Hacking & Security

Slack Resets Passwords After a Bug Exposed Hashed Passwords for Some Users

6 Srpen, 2022 - 10:44
Slack said it took the step of resetting passwords for about 0.5% of its users after a flaw exposed salted password hashes when creating or revoking shared invitation links for workspaces. "When a user performed either of these actions, Slack transmitted a hashed version of their password to other workspace members," the enterprise communication and collaboration platform said in an alert on 4thRavie Lakshmanan
Kategorie: Hacking & Security

Iranian Hackers Likely Behind Disruptive Cyberattacks Against Albanian Government

5 Srpen, 2022 - 16:37
A threat actor working to further Iranian goals is said to have been behind a set of damaging cyberattacks against Albanian government services in mid-July 2022. Cybersecurity firm Mandiant said the malicious activity against a NATO state represented a "geographic expansion of Iranian disruptive cyber operations." The July 17 attacks, according to Albania's National Agency of Information SocietyRavie Lakshmanan
Kategorie: Hacking & Security

Emergency Alert System Flaws Could Let Attackers Transmit Fake Messages

5 Srpen, 2022 - 12:24
The U.S. Department of Homeland Security (DHS) has warned of critical security vulnerabilities in Emergency Alert System (EAS) encoder/decoder devices. If left unpatched, the issues could allow an adversary to issue fraudulent emergency alerts over TV, radio, and cable networks. The August 1 advisory comes courtesy of DHS' Federal Emergency Management Agency (FEMA). CYBIR security researcher KenRavie Lakshmanan
Kategorie: Hacking & Security

Resolving Availability vs. Security, a Constant Conflict in IT

5 Srpen, 2022 - 12:20
Conflicting business requirements is a common problem – and you find it in every corner of an organization, including in information technology. Resolving these conflicts is a must, but it isn’t always easy – though sometimes there is a novel solution that helps. In IT management there is a constant struggle between security and operations teams. Yes, both teams ultimately want to have secure The Hacker News
Kategorie: Hacking & Security

A Growing Number of Malware Attacks Leveraging Dark Utilities 'C2-as-a-Service'

5 Srpen, 2022 - 12:06
A nascent service called Dark Utilities has already attracted 3,000 users for its ability to provide command-and-control (C2) services with the goal of commandeering compromised systems. "It is marketed as a means to enable remote access, command execution, distributed denial-of-service (DDoS) attacks and cryptocurrency mining operations on infected systems," Cisco Talos said in a report shared Ravie Lakshmanan
Kategorie: Hacking & Security

CISA Adds Zimbra Email Vulnerability to its Exploited Vulnerabilities Catalog

5 Srpen, 2022 - 07:54
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Thursday added a recently disclosed high-severity vulnerability in the Zimbra email suite to its Known Exploited Vulnerabilities Catalog, citing evidence of active exploitation. The issue in question is CVE-2022-27924 (CVSS score: 7.5), a command injection flaw in the platform that could lead to the execution of arbitrary Ravie Lakshmanan
Kategorie: Hacking & Security

Who Has Control: The SaaS App Admin Paradox

4 Srpen, 2022 - 17:50
Imagine this: a company-wide lockout to the company CRM, like Salesforce, because the organization's external admin attempts to disable MFA for themselves. They don't think to consult with the security team and don't consider the security implications, only the ease which they need for their team to use their login.  This CRM, however, defines MFA as a top-tier security setting; for example, The Hacker News
Kategorie: Hacking & Security

Critical RCE Bug Could Let Hackers Remotely Take Over DrayTek Vigor Routers

4 Srpen, 2022 - 15:10
As many as 29 different router models from DrayTek have been identified as affected by a new critical, unauthenticated remote code execution vulnerability that, if successfully exploited, could lead to full compromise of the devices and unauthorized access to the broader network. "The attack can be performed without user interaction if the management interface of the device has been configured Ravie Lakshmanan
Kategorie: Hacking & Security

New Woody RAT Malware Being Used to Target Russian Organizations

4 Srpen, 2022 - 14:55
An unknown threat actor has been targeting Russian entities with a newly discovered remote access trojan called Woody RAT for at least a year as part of a spear-phishing campaign. The advanced custom backdoor is said to be delivered via either of two methods: archive files or Microsoft Office documents leveraging the now-patched "Follina" support diagnostic tool vulnerability (CVE-2022-30190) inRavie Lakshmanan
Kategorie: Hacking & Security

Hackers Exploited Atlassian Confluence Bug to Deploy Ljl Backdoor for Espionage

4 Srpen, 2022 - 12:24
A threat actor is said to have "highly likely" exploited a security flaw in an outdated Atlassian Confluence server to deploy a never-before-seen backdoor against an unnamed organization in the research and technical services sector. The attack, which transpired over a seven-day-period during the end of May, has been attributed to a threat activity cluster tracked by cybersecurity firm DeepwatchRavie Lakshmanan
Kategorie: Hacking & Security

Three Common Mistakes That May Sabotage Your Security Training

4 Srpen, 2022 - 09:58
Phishing incidents are on the rise. A report from IBM shows that phishing was the most popular attack vector in 2021, resulting in one in five employees falling victim to phishing hacking techniques. The Need for Security Awareness Training  Although technical solutions protect against phishing threats, no solution is 100% effective. Consequently, companies have no choice but to involve their The Hacker News
Kategorie: Hacking & Security

Cisco Business Routers Found Vulnerable to Critical Remote Hacking Flaws

4 Srpen, 2022 - 07:11
Cisco on Wednesday rolled out patches to address eight security vulnerabilities, three of which could be weaponized by an unauthenticated attacker to gain remote code execution (RCE) or cause a denial-of-service (DoS) condition on affected devices. The most critical of the flaws impact Cisco Small Business RV160, RV260, RV340, and RV345 Series routers. Tracked as CVE-2022-20842 (CVSS score: 9.8)Ravie Lakshmanan
Kategorie: Hacking & Security

Single-Core CPU Cracked Post-Quantum Encryption Candidate Algorithm in Just an Hour

3 Srpen, 2022 - 18:09
A late-stage candidate encryption algorithm that was meant to withstand decryption by powerful quantum computers in the future has been trivially cracked by using a computer running Intel Xeon CPU in an hour's time. The algorithm in question is SIKE — short for Supersingular Isogeny Key Encapsulation — which made it to the fourth round of the Post-Quantum Cryptography (PQC) standardization Ravie Lakshmanan
Kategorie: Hacking & Security

VirusTotal Reveals Most Impersonated Software in Malware Attacks

3 Srpen, 2022 - 14:36
Threat actors are increasingly mimicking legitimate applications like Skype, Adobe Reader, and VLC Player as a means to abuse trust relationships and increase the likelihood of a successful social engineering attack. Other most impersonated legitimate apps by icon include 7-Zip, TeamViewer, CCleaner, Microsoft Edge, Steam, Zoom, and WhatsApp, an analysis from VirusTotal has revealed. "One of theRavie Lakshmanan
Kategorie: Hacking & Security