The Hacker News

Syndikovat obsah
The Hacker News has been internationally recognized as a leading news source dedicated to promoting awareness for security experts and [email protected]
Aktualizace: 49 min 29 sek zpět

Google Chrome Beta Tests New DBSC Protection Against Cookie-Stealing Attacks

3 Duben, 2024 - 15:07
Google on Tuesday said it's piloting a new feature in Chrome called Device Bound Session Credentials (DBSC) to help protect users against session cookie theft by malware. The prototype – currently tested against "some" Google Account users running Chrome Beta – is built with an aim to make it an open web standard, the tech giant's Chromium team said. "By binding authentication sessions to the Newsroomhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Attack Surface Management vs. Vulnerability Management

3 Duben, 2024 - 13:12
Attack surface management (ASM) and vulnerability management (VM) are often confused, and while they overlap, they’re not the same. The main difference between attack surface management and vulnerability management is in their scope: vulnerability management checks a list of known assets, while attack surface management assumes you have unknown assets and so begins with discovery. Let’s look at
Kategorie: Hacking & Security

Attack Surface Management vs. Vulnerability Management

3 Duben, 2024 - 13:12
Attack surface management (ASM) and vulnerability management (VM) are often confused, and while they overlap, they’re not the same. The main difference between attack surface management and vulnerability management is in their scope: vulnerability management checks a list of known assets, while attack surface management assumes you have unknown assets and so begins with discovery. Let’s look at The Hacker Newshttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Mispadu Trojan Targets Europe, Thousands of Credentials Compromised

3 Duben, 2024 - 11:32
The banking trojan known as Mispadu has expanded its focus beyond Latin America (LATAM) and Spanish-speaking individuals to target users in Italy, Poland, and Sweden. Targets of the ongoing campaign include entities spanning finance, services, motor vehicle manufacturing, law firms, and commercial facilities, according to Morphisec. "Despite the geographic expansion, Mexico remains the
Kategorie: Hacking & Security

Mispadu Trojan Targets Europe, Thousands of Credentials Compromised

3 Duben, 2024 - 11:32
The banking trojan known as Mispadu has expanded its focus beyond Latin America (LATAM) and Spanish-speaking individuals to target users in Italy, Poland, and Sweden. Targets of the ongoing campaign include entities spanning finance, services, motor vehicle manufacturing, law firms, and commercial facilities, according to Morphisec. "Despite the geographic expansion, Mexico remains theNewsroomhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Critical Security Flaw Found in Popular LayerSlider WordPress Plugin

3 Duben, 2024 - 07:11
A critical security flaw impacting the LayerSlider plugin for WordPress could be abused to extract sensitive information from databases, such as password hashes. The flaw, designated as CVE-2024-2879, carries a CVSS score of 9.8 out of a maximum of 10.0. It has been described as a case of SQL injection impacting versions from 7.9.11 through 7.10.0. The issue has been addressed in version
Kategorie: Hacking & Security

Critical Security Flaw Found in Popular LayerSlider WordPress Plugin

3 Duben, 2024 - 07:11
A critical security flaw impacting the LayerSlider plugin for WordPress could be abused to extract sensitive information from databases, such as password hashes. The flaw, designated as CVE-2024-2879, carries a CVSS score of 9.8 out of a maximum of 10.0. It has been described as a case of SQL injection impacting versions from 7.9.11 through 7.10.0. The issue has been addressed in version Newsroomhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Malicious Code in XZ Utils for Linux Systems Enables Remote Code Execution

2 Duben, 2024 - 15:18
The malicious code inserted into the open-source library XZ Utils, a widely used package present in major Linux distributions, is also capable of facilitating remote code execution, a new analysis has revealed. The audacious supply chain compromise, tracked as CVE-2024-3094 (CVSS score: 10.0), came to light last week when Microsoft engineer and PostgreSQL developer Andres Freund
Kategorie: Hacking & Security

Malicious Code in XZ Utils for Linux Systems Enables Remote Code Execution

2 Duben, 2024 - 15:18
The malicious code inserted into the open-source library XZ Utils, a widely used package present in major Linux distributions, is also capable of facilitating remote code execution, a new analysis has revealed. The audacious supply chain compromise, tracked as CVE-2024-3094 (CVSS score: 10.0), came to light last week when Microsoft engineer and PostgreSQL developer Andres Freund Newsroomhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Harnessing the Power of CTEM for Cloud Security

2 Duben, 2024 - 13:27
Cloud solutions are more mainstream – and therefore more exposed – than ever before. In 2023 alone, a staggering 82% of data breaches were against public, private, or hybrid cloud environments. What’s more, nearly 40% of breaches spanned multiple cloud environments. The average cost of a cloud breach was above the overall average, at $4.75 million. In a time where cloud has become the de facto
Kategorie: Hacking & Security

Harnessing the Power of CTEM for Cloud Security

2 Duben, 2024 - 13:27
Cloud solutions are more mainstream – and therefore more exposed – than ever before. In 2023 alone, a staggering 82% of data breaches were against public, private, or hybrid cloud environments. What’s more, nearly 40% of breaches spanned multiple cloud environments. The average cost of a cloud breach was above the overall average, at $4.75 million. In a time where cloud has become the de facto The Hacker Newshttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

China-linked Hackers Deploy New 'UNAPIMON' Malware for Stealthy Operations

2 Duben, 2024 - 13:00
A threat activity cluster tracked as Earth Freybug has been observed using a new malware called UNAPIMON to fly under the radar. "Earth Freybug is a cyberthreat group that has been active since at least 2012 that focuses on espionage and financially motivated activities," Trend Micro security researcher Christopher So said in a report published today. "It has been observed to
Kategorie: Hacking & Security

China-linked Hackers Deploy New 'UNAPIMON' Malware for Stealthy Operations

2 Duben, 2024 - 13:00
A threat activity cluster tracked as Earth Freybug has been observed using a new malware called UNAPIMON to fly under the radar. "Earth Freybug is a cyberthreat group that has been active since at least 2012 that focuses on espionage and financially motivated activities," Trend Micro security researcher Christopher So said in a report published today. "It has been observed toNewsroomhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Google to Delete Billions of Browsing Records in 'Incognito Mode' Privacy Lawsuit Settlement

2 Duben, 2024 - 09:08
Google has agreed to purge billions of data records reflecting users' browsing activities to settle a class action lawsuit that claimed the search giant tracked them without their knowledge or consent in its Chrome browser. The class action, filed in 2020, alleged the company misled users by tracking their internet browsing activity who thought that it remained private when using the "
Kategorie: Hacking & Security

Google to Delete Billions of Browsing Records in 'Incognito Mode' Privacy Lawsuit Settlement

2 Duben, 2024 - 09:08
Google has agreed to purge billions of data records reflecting users' browsing activities to settle a class action lawsuit that claimed the search giant tracked them without their knowledge or consent in its Chrome browser. The class action, filed in 2020, alleged the company misled users by tracking their internet browsing activity who thought that it remained private when using the "Newsroomhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Massive Phishing Campaign Strikes Latin America: Venom RAT Targeting Multiple Sectors

2 Duben, 2024 - 06:54
The threat actor known as TA558 has been attributed to a new massive phishing campaign that targets a wide range of sectors in Latin America with the goal of deploying Venom RAT. The attacks primarily singled out hotel, travel, trading, financial, manufacturing, industrial, and government verticals in Spain, Mexico, the United States, Colombia, Portugal, Brazil, Dominican Republic, and
Kategorie: Hacking & Security

Massive Phishing Campaign Strikes Latin America: Venom RAT Targeting Multiple Sectors

2 Duben, 2024 - 06:54
The threat actor known as TA558 has been attributed to a new massive phishing campaign that targets a wide range of sectors in Latin America with the goal of deploying Venom RAT. The attacks primarily singled out hotel, travel, trading, financial, manufacturing, industrial, and government verticals in Spain, Mexico, the United States, Colombia, Portugal, Brazil, Dominican Republic, andNewsroomhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Indian Government Rescues 250 Citizens Forced into Cybercrime in Cambodia

1 Duben, 2024 - 15:51
The Indian government said it has rescued and repatriated about 250 citizens in Cambodia who were held captive and coerced into running cyber scams. The Indian nationals "were lured with employment opportunities to that country but were forced to undertake illegal cyber work," the Ministry of External Affairs (MEA) said in a statement, adding it had rescued 75 people in the past three
Kategorie: Hacking & Security

Indian Government Rescues 250 Citizens Forced into Cybercrime in Cambodia

1 Duben, 2024 - 15:51
The Indian government said it has rescued and repatriated about 250 citizens in Cambodia who were held captive and coerced into running cyber scams. The Indian nationals "were lured with employment opportunities to that country but were forced to undertake illegal cyber work," the Ministry of External Affairs (MEA) said in a statement, adding it had rescued 75 people in the past three Newsroomhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Detecting Windows-based Malware Through Better Visibility

1 Duben, 2024 - 13:20
Despite a plethora of available security solutions, more and more organizations fall victim to Ransomware and other threats. These continued threats aren't just an inconvenience that hurt businesses and end users - they damage the economy, endanger lives, destroy businesses and put national security at risk. But if that wasn’t enough – North Korea appears to be using revenue from cyber
Kategorie: Hacking & Security