Cyberveillecurated by Decio
Nuage de tags
Mur d'images
Quotidien
Flux RSS
  • Flux RSS
  • Daily Feed
  • Weekly Feed
  • Monthly Feed
Filtres

Liens par page

  • 20 links
  • 50 links
  • 100 links

Filtres

Untagged links
page 2 / 4
69 résultats taggé thehackernews  ✕
BreachForums Returns Just Weeks After FBI Seizure - Honeypot or Blunder? https://thehackernews.com/2024/05/breachforums-returns-just-weeks-after.html
29/05/2024 09:58:27
QRCode
archive.org

The online criminal bazaar BreachForums has been resurrected merely two weeks after a U.S.-led coordinated law enforcement action dismantled and seized control of its infrastructure.

Cybersecurity researchers and dark web trackers Brett Callow, Dark Web Informer, and FalconFeeds revealed the site's online return at breachforums[.]st – one of the dismantled sites – by a user named ShinyHunters, who has since offered for sale a 1.3 TB database containing details of allegedly 560 million Ticketmaster customers for $500,000.

thehackernews EN 2024 BreachForums Ticketmaster customers return darkweb
Cyber Criminals Exploit GitHub and FileZilla to Deliver Malware Cocktail https://thehackernews.com/2024/05/cyber-criminals-exploit-github-and.html
25/05/2024 21:59:33
QRCode
archive.org

A "multi-faceted campaign" has been observed abusing legitimate services like GitHub and FileZilla to deliver an array of stealer malware and banking trojans such as Atomic (aka AMOS), Vidar, Lumma (aka LummaC2), and Octo by impersonating credible software like 1Password, Bartender 5, and Pixelmator Pro.

thehackernews EN 2024 GitHub FileZilla AMOS impersonating software 1Password fake
Critical Flaws in Cacti Framework Could Let Attackers Execute Malicious Code https://thehackernews.com/2024/05/critical-flaws-in-cacti-framework-could.html
20/05/2024 11:41:33
QRCode
archive.org

The maintainers of the Cacti open-source network monitoring and fault management framework have addressed a dozen security flaws, including two critical issues that could lead to the execution of arbitrary code.

thehackernews EN cacti vulnerability CVE-2024-25641 CVE-2024-29895
Mirai Botnet Exploits Ivanti Connect Secure Flaws for Malicious Payload Delivery https://thehackernews.com/2024/05/mirai-botnet-exploits-ivanti-connect.html?m=1
12/05/2024 13:10:11
QRCode
archive.org

Ivanti Connect Secure (ICS) devices are under attack! Two critical vulnerabilities are being exploited to deploy the notorious Mirai botnet.

thehackernews EN 2024 Mirai Botnet Ivanti Connect Payload
Kremlin-Backed APT28 Targets Polish Institutions in Large-Scale Malware Campaign https://thehackernews.com/2024/05/kremlin-backed-apt28-targets-polish.html?m=1
12/05/2024 13:08:34
QRCode
archive.org

Russia-Linked APT28 Strikes Poland with Malware Campaign Polish government bodies were hit by a sophisticated malware attack orchestrated by the infam

thehackernews EN 2024 APT28 Poland Malware
Raspberry Robin Returns: New Malware Campaign Spreading Through WSF Files https://thehackernews.com/2024/04/raspberry-robin-returns-new-malware.html?m=1
14/04/2024 15:30:37
QRCode
archive.org

Researchers uncover a fresh wave of the Raspberry Robin campaign spreading malware through malicious Windows Script Files (WSFs) since March 2024.
#attacks #breach #computer #cyber #data #hack #hacker #hacking #how #information #malware #network #news #ransomware #security #software #the #to #today #updates #vulnerability

thehackernews 2024 EN Raspberry-Robin WSF return
Fortinet Rolls Out Critical Security Patches for FortiClientLinux Vulnerability https://thehackernews.com/2024/04/fortinet-has-released-patches-to.html?m=1
11/04/2024 09:41:13
QRCode
archive.org

If you use FortiClientLinux, update immediately. Critical vulnerability could let attackers run code on your system. Patch now, get the details here.

thehackernews EN 2024 FortiClientLinux Fortinet CVE-2023-45590
Apple Updates Spyware Alert System to Warn Victims of Mercenary Attacks https://thehackernews.com/2024/04/apple-expands-spyware-alert-system-to.html?m=1
11/04/2024 09:21:10
QRCode
archive.org

Apple's updated spyware alert system now warns individual users of potential targeting by mercenary spyware attacks.

thehackernews EN 2024 Apple alert-system Warn Victims mercenary-spyware
Critical Security Flaw Found in Popular LayerSlider WordPress Plugin https://thehackernews.com/2024/04/critical-security-flaw-found-in-popular.html
07/04/2024 21:59:57
QRCode
archive.org

A critical security flaw impacting the LayerSlider plugin for WordPress could be abused to extract sensitive information from databases, such as password hashes.

The flaw, designated as CVE-2024-2879, carries a CVSS score of 9.8 out of a maximum of 10.0. It has been described as a case of SQL injection impacting versions from 7.9.11 through 7.10.0.

The issue has been addressed in version 7.10.1 released on March 27, 2024, following responsible disclosure on March 25. "This update includes important security fixes," the maintainers of LayerSlider said in their release notes.

LayerSlider is a visual web content editor, a graphic design software, and a digital visual effects that allows users to create animations and rich content for their websites. According to its own site, the plugin is used by "millions of users worldwide."

thehackernews EN 2024 WordPress LayerSlider CVE-2024-2879
China-linked Hackers Deploy New 'UNAPIMON' Malware for Stealthy Operations https://thehackernews.com/2024/04/china-linked-hackers-deploy-new.html
03/04/2024 16:55:15
QRCode
archive.org

A threat activity cluster tracked as Earth Freybug has been observed using a new malware called UNAPIMON to fly under the radar.

"Earth Freybug is a cyberthreat group that has been active since at least 2012 that focuses on espionage and financially motivated activities," Trend Micro security researcher Christopher So said in a report published today.

thehackernews EN 2024 China-linked UNAPIMON APT41Malware
Key Lesson from Microsoft's Password Spray Hack: Secure Every Account https://thehackernews.com/2024/03/key-lesson-from-microsofts-password.html
30/03/2024 17:26:24
QRCode
archive.org

In January 2024, Microsoft discovered they'd been the victim of a hack orchestrated by Russian-state hackers Midnight Blizzard (sometimes known as Nobelium). The concerning detail about this case is how easy it was to breach the software giant. It wasn't a highly technical hack that exploited a zero-day vulnerability – the hackers used a simple password spray attack to take control of an old, inactive account. This serves as a stark reminder of the importance of password security and why organizations need to protect every user account.

thehackernews EN 2024 Microsoft MidnightBlizzard lesson-learned password-spray
U.S. Sanctions 3 Cryptocurrency Exchanges for Helping Russia Evade Sanctions https://thehackernews.com/2024/03/us-sanctions-3-cryptocurrency-exchanges.html
26/03/2024 10:14:15
QRCode
archive.org

The U.S. Department of the Treasury's Office of Foreign Assets Control (OFAC) sanctioned three cryptocurrency exchanges for offering services used to evade economic restrictions imposed on Russia following its invasion of Ukraine in early 2022.

This includes Bitpapa IC FZC LLC, Crypto Explorer DMCC (AWEX), and Obshchestvo S Ogranichennoy Otvetstvennostyu Tsentr Obrabotki Elektronnykh Platezhey (TOEP).

thehackernews EN 2024 sanctions US cryptocurrency Russia exchanges Bitpapa
APT28 Hacker Group Targeting Europe, Americas, Asia in Widespread Phishing Scheme https://thehackernews.com/2024/03/apt28-hacker-group-targeting-europe.html?m=1
18/03/2024 07:24:03
QRCode
archive.org

The Russia-linked threat actor known as APT28 has been linked to multiple ongoing phishing campaigns that employ lure documents imitating government and non-governmental organizations (NGOs) in Europe, the South Caucasus, Central Asia, and North and South America.

"The uncovered lures include a mixture of internal and publicly available documents, as well as possible actor-generated documents associated with finance, critical infrastructure, executive engagements, cyber security, maritime security, healthcare, business, and defense industrial production," IBM X-Force said in a report published last week.

thehackernews EN 2024 APT28 Russia-linked Widespread Phishing Scheme
Phobos Ransomware Aggressively Targeting U.S. Critical Infrastructure https://thehackernews.com/2024/03/phobos-ransomware-aggressively.html
06/03/2024 10:15:25
QRCode
archive.org

U.S. cybersecurity and intelligence agencies have warned of Phobos ransomware attacks targeting government and critical infrastructure entities, outlining the various tactics and techniques the threat actors have adopted to deploy the file-encrypting malware.

"Structured as a ransomware-as-a-service (RaaS) model, Phobos ransomware actors have targeted entities including municipal and county governments, emergency services, education, public healthcare, and critical infrastructure to successfully ransom several million in U.S. dollars," the government said.

thehackernews EN 2024 Phobos Ransomware CISA US Critical-infrastructure
8,000+ Domains of Trusted Brands Hijacked for Massive Spam Operation https://thehackernews.com/2024/02/8000-subdomains-of-trusted-brands.html?m=1
03/03/2024 20:21:17
QRCode
archive.org

Over 8,000 subdomains belonging to recognized brands and organizations are being exploited for malicious email distribution.

thehackernews malware attacks subdomains brands Guardio Labs
Malicious NPM Packages Exfiltrate Hundreds of Developer SSH Keys via GitHub https://thehackernews.com/2024/01/malicious-npm-packages-exfiltrate-1600.html
28/01/2024 16:53:25
QRCode
archive.org
thumbnail

Did you download Warbeast2000 or Kodiak2k from npm? If so, your SSH keys might be compromised! These packages steal keys & upload them to GitHub.

thehackernews EN 2024 NPM Packages Malicious SSH Keys warbeast2000 kodiak2k
Balada Injector Infects Over 7,100 WordPress Sites Using Plugin Vulnerability https://thehackernews.com/2024/01/balada-injector-infects-over-7100.html
20/01/2024 21:19:56
QRCode
archive.org
thumbnail

Over 7,100 WordPress sites have been hit by the 'Balada Injector' malware, which exploits sites using a vulnerable version of the Popup Builder plugin

thehackernews 2024 EN Balada WP plugin WordPress malware Injector infected
Microsoft's Top Execs' Emails Breached in Sophisticated Russia-Linked APT Attack https://thehackernews.com/2024/01/microsofts-top-execs-emails-breached-in.html
20/01/2024 09:54:39
QRCode
archive.org
thumbnail

Microsoft on Friday revealed that it was the target of a nation-state attack on its corporate systems that resulted in the theft of emails and attachments from senior executives and other individuals in the company's cybersecurity and legal departments.

The Windows maker attributed the attack to a Russian advanced persistent threat (APT) group it tracks as Midnight Blizzard (formerly Nobelium), which is also known as APT29, BlueBravo, Cloaked Ursa, Cozy Bear, and The Dukes.

thehackernews en 2024 Microsoft APT29 Russia theft mail executives attack MidnightBlizzard
Opera MyFlaw Bug Could Let Hackers Run ANY File on Your Mac or Windows https://thehackernews.com/2024/01/opera-myflaw-bug-could-let-hackers-run.html?m=1
15/01/2024 15:42:55
QRCode
archive.org
thumbnail

Critical security flaw found in Opera Browsers. MyFlow sync feature lets attackers take over your Windows and macOS systems.

thehackernews 2024 EN Critical Opera Browsers MyFlow vulnerability
Beware! YouTube Videos Promoting Cracked Software Distribute Lumma Stealer https://thehackernews.com/2024/01/beware-youtube-videos-promoting-cracked.html?m=1
15/01/2024 07:19:53
QRCode
archive.org
thumbnail

Beware of YouTube videos offering cracked software! They might be a gateway to the Lumma malware, stealing your sensitive information

thehackernews EN 2024 Lumma Stealer vulnerability
page 2 / 4
4259 links
Shaarli - The personal, minimalist, super-fast, database free, bookmarking service par la communauté Shaarli - Theme by kalvn - Curated by Decio