The Hacker News

Syndikovat obsah
The Hacker News has been internationally recognized as a leading news source dedicated to promoting awareness for security experts and [email protected]
Aktualizace: 25 min 49 sek zpět

Dark Web Malware Logs Expose 3,300 Users Linked to Child Abuse Sites

8 Červenec, 2024 - 17:08
An analysis of information-stealing malware logs published on the dark web has led to the discovery of thousands of consumers of child sexual abuse material (CSAM), indicating how such information could be used to combat serious crimes. "Approximately 3,300 unique users were found with accounts on known CSAM sources," Recorded Future said in a proof-of-concept (PoC) report published last week. "Newsroomhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

New Ransomware-as-a-Service 'Eldorado' Targets Windows and Linux Systems

8 Červenec, 2024 - 15:15
An emerging ransomware-as-a-service (RaaS) operation called Eldorado comes with locker variants to encrypt files on Windows and Linux systems. Eldorado first appeared on March 16, 2024, when an advertisement for the affiliate program was posted on the ransomware forum RAMP, Singapore-headquartered Group-IB said. The cybersecurity firm, which infiltrated the ransomware group, noted that its
Kategorie: Hacking & Security

New Ransomware-as-a-Service 'Eldorado' Targets Windows and Linux Systems

8 Červenec, 2024 - 15:15
An emerging ransomware-as-a-service (RaaS) operation called Eldorado comes with locker variants to encrypt files on Windows and Linux systems. Eldorado first appeared on March 16, 2024, when an advertisement for the affiliate program was posted on the ransomware forum RAMP, Singapore-headquartered Group-IB said. The cybersecurity firm, which infiltrated the ransomware group, noted that its Newsroomhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

5 Key Questions CISOs Must Ask Themselves About Their Cybersecurity Strategy

8 Červenec, 2024 - 13:00
Events like the recent massive CDK ransomware attack – which shuttered car dealerships across the U.S. in late June 2024 – barely raise public eyebrows anymore.  Yet businesses, and the people that lead them, are justifiably jittery. Every CISO knows that cybersecurity is an increasingly hot topic for executives and board members alike. And when the inevitable CISO/Board briefing rolls
Kategorie: Hacking & Security

5 Key Questions CISOs Must Ask Themselves About Their Cybersecurity Strategy

8 Červenec, 2024 - 13:00
Events like the recent massive CDK ransomware attack – which shuttered car dealerships across the U.S. in late June 2024 – barely raise public eyebrows anymore.  Yet businesses, and the people that lead them, are justifiably jittery. Every CISO knows that cybersecurity is an increasingly hot topic for executives and board members alike. And when the inevitable CISO/Board briefing rolls The Hacker Newshttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Experts Warn of Mekotio Banking Trojan Targeting Latin American Countries

8 Červenec, 2024 - 11:53
Financial institutions in Latin America are being threatened by a banking trojan called Mekotio (aka Melcoz). That's according to findings from Trend Micro, which said it recently observed a surge in cyber attacks distributing the Windows malware. Mekotio, known to be actively put to use since 2015, is known to target Latin American countries like Brazil, Chile, Mexico, Spain, Peru, and Portugal
Kategorie: Hacking & Security

Experts Warn of Mekotio Banking Trojan Targeting Latin American Countries

8 Červenec, 2024 - 11:53
Financial institutions in Latin America are being threatened by a banking trojan called Mekotio (aka Melcoz). That's according to findings from Trend Micro, which said it recently observed a surge in cyber attacks distributing the Windows malware. Mekotio, known to be actively put to use since 2015, is known to target Latin American countries like Brazil, Chile, Mexico, Spain, Peru, and PortugalNewsroomhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Critical Unpatched Flaws Disclosed in Popular Gogs Open-Source Git Service

8 Červenec, 2024 - 08:55
Four unpatched security flaws, including three critical ones, have been disclosed in the Gogs open-source, self-hosted Git service that could enable an authenticated attacker to breach susceptible instances, steal or wipe source code, and even plant backdoors. The vulnerabilities, according to SonarSource researchers Thomas Chauchefoin and Paul Gerste, are listed below - CVE-2024-39930 (CVSS
Kategorie: Hacking & Security

Critical Unpatched Flaws Disclosed in Popular Gogs Open-Source Git Service

8 Červenec, 2024 - 08:55
Four unpatched security flaws, including three critical ones, have been disclosed in the Gogs open-source, self-hosted Git service that could enable an authenticated attacker to breach susceptible instances, steal or wipe source code, and even plant backdoors. The vulnerabilities, according to SonarSource researchers Thomas Chauchefoin and Paul Gerste, are listed below - CVE-2024-39930 (CVSS Newsroomhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Apple Removes VPN Apps from Russian App Store Amid Government Pressure

8 Červenec, 2024 - 08:28
Apple removed a number of virtual private network (VPN) apps in Russia from its App Store on July 4, 2024, following a request by Russia's state communications watchdog Roskomnadzor, Russian news media reported. This includes the mobile apps of 25 VPN service providers, including Hidemy.name VPN, Le VPN, NordVPN, PIA VPN, Planet VPN, Proton VPN, Red Shield VPN, according to Interfax and
Kategorie: Hacking & Security

Apple Removes VPN Apps from Russian App Store Amid Government Pressure

8 Červenec, 2024 - 08:28
Apple removed a number of virtual private network (VPN) apps in Russia from its App Store on July 4, 2024, following a request by Russia's state communications watchdog Roskomnadzor, Russian news media reported. This includes the mobile apps of 25 VPN service providers, including Hidemy.name VPN, Le VPN, NordVPN, PIA VPN, Planet VPN, Proton VPN, Red Shield VPN, according to Interfax and Newsroomhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Webinar Alert: Learn How ITDR Solutions Stop Sophisticated Identity Attacks

5 Červenec, 2024 - 14:30
Identity theft isn't just about stolen credit cards anymore. Today, cybercriminals are using advanced tactics to infiltrate organizations and cause major damage with compromised credentials. The stakes are high: ransomware attacks, lateral movement, and devastating data breaches. Don't be caught off guard. Join us for a groundbreaking webinar that will change the way you approach cybersecurity.
Kategorie: Hacking & Security

Webinar Alert: Learn How ITDR Solutions Stop Sophisticated Identity Attacks

5 Červenec, 2024 - 14:30
Identity theft isn't just about stolen credit cards anymore. Today, cybercriminals are using advanced tactics to infiltrate organizations and cause major damage with compromised credentials. The stakes are high: ransomware attacks, lateral movement, and devastating data breaches. Don't be caught off guard. Join us for a groundbreaking webinar that will change the way you approach cybersecurity. The Hacker Newshttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

OVHcloud Hit with Record 840 Million PPS DDoS Attack Using MikroTik Routers

5 Červenec, 2024 - 14:20
French cloud computing firm OVHcloud said it mitigated a record-breaking distributed denial-of-service (DDoS) attack in April 2024 that reached a packet rate of 840 million packets per second (Mpps). This is just above the previous record of 809 million Mpps reported by Akamai as targeting a large European bank in June 2020. The 840 Mpps DDoS attack is said to have been a combination of a TCP
Kategorie: Hacking & Security

OVHcloud Hit with Record 840 Million PPS DDoS Attack Using MikroTik Routers

5 Červenec, 2024 - 14:20
French cloud computing firm OVHcloud said it mitigated a record-breaking distributed denial-of-service (DDoS) attack in April 2024 that reached a packet rate of 840 million packets per second (Mpps). This is just above the previous record of 809 million Mpps reported by Akamai as targeting a large European bank in June 2020. The 840 Mpps DDoS attack is said to have been a combination of a TCP Newsroomhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Blueprint for Success: Implementing a CTEM Operation

5 Červenec, 2024 - 13:00
The attack surface isn’t what it once was and it’s becoming a nightmare to protect. A constantly expanding and evolving attack surface means risk to the business has skyrocketed and current security measures are struggling to keep it protected. If you’ve clicked on this article, there’s a good chance you’re looking for solutions to manage this risk. In 2022, a new framework was coined by Gartner
Kategorie: Hacking & Security

Blueprint for Success: Implementing a CTEM Operation

5 Červenec, 2024 - 13:00
The attack surface isn’t what it once was and it’s becoming a nightmare to protect. A constantly expanding and evolving attack surface means risk to the business has skyrocketed and current security measures are struggling to keep it protected. If you’ve clicked on this article, there’s a good chance you’re looking for solutions to manage this risk. In 2022, a new framework was coined by GartnerThe Hacker Newshttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

GootLoader Malware Still Active, Deploys New Versions for Enhanced Attacks

5 Červenec, 2024 - 10:40
The malware known as GootLoader continues to be in active use by threat actors looking to deliver additional payloads to compromised hosts. "Updates to the GootLoader payload have resulted in several versions of GootLoader, with GootLoader 3 currently in active use," cybersecurity firm Cybereason said in an analysis published last week. "While some of the particulars of GootLoader payloads have
Kategorie: Hacking & Security

GootLoader Malware Still Active, Deploys New Versions for Enhanced Attacks

5 Červenec, 2024 - 10:40
The malware known as GootLoader continues to be in active use by threat actors looking to deliver additional payloads to compromised hosts. "Updates to the GootLoader payload have resulted in several versions of GootLoader, with GootLoader 3 currently in active use," cybersecurity firm Cybereason said in an analysis published last week. "While some of the particulars of GootLoader payloads have Newsroomhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Polyfill[.]io Attack Impacts Over 380,000 Hosts, Including Major Companies

5 Červenec, 2024 - 06:18
The supply chain attack targeting the widely-used Polyfill[.]io JavaScript library is broader in scope than previously thought, with new findings from Censys showing that over 380,000 hosts are embedding a polyfill script linking to the malicious domain as of July 2, 2024. This includes references to "https://cdn.polyfill[.]io" or "https://cdn.polyfill[.]com" in their HTTP responses, the attack
Kategorie: Hacking & Security