Source: www.bleepingcomputer.com – Author: Bill Toulas Millions of GitHub repositories may be vulnerable to dependency repository hijacking, also known as “RepoJacking,” which could help attackers deploy...
Author:
DuckDuckGo browser for Windows available for everyone as public beta – Source: www.bleepingcomputer.com
Source: www.bleepingcomputer.com – Author: Bill Toulas DuckDuckGo has released its privacy-centric browser for Windows to the general public. It is a beta version available for download...
Chinese APT15 hackers resurface with new Graphican malware – Source: www.bleepingcomputer.com
Source: www.bleepingcomputer.com – Author: Bill Toulas The Chinese state-sponsored hacking group tracked as APT15 has been observed using a novel backdoor named ‘Graphican’ in a new...
New Condi malware builds DDoS botnet out of TP-Link AX21 routers – Source: www.bleepingcomputer.com
Source: www.bleepingcomputer.com – Author: Bill Toulas A new DDoS-as-a-Service botnet called “Condi” emerged in May 2023, exploiting a vulnerability in TP-Link Archer AX21 (AX1800) Wi-Fi routers...
Hackers infect Linux SSH servers with Tsunami botnet malware – Source: www.bleepingcomputer.com
Source: www.bleepingcomputer.com – Author: Bill Toulas An unknown threat actor is brute-forcing Linux SSH servers to install a wide range of malware, including the Tsunami DDoS...
Zyxel warns of critical command injection flaw in NAS devices – Source: www.bleepingcomputer.com
Source: www.bleepingcomputer.com – Author: Bill Toulas Zyxel is warning its NAS (Network Attached Storage) devices users to update their firmware to fix a critical severity command...
New RDStealer malware steals from drives shared over Remote Desktop – Source: www.bleepingcomputer.com
Source: www.bleepingcomputer.com – Author: Bill Toulas A cyberespionage and hacking campaign tracked as ‘RedClouds’ uses the custom ‘RDStealer’ malware to automatically steal data from drives shared...
Hackers use fake OnlyFans pics to drop info-stealing malware – Source: www.bleepingcomputer.com
Source: www.bleepingcomputer.com – Author: Bill Toulas A malware campaign is using fake OnlyFans content and adult lures to install a remote access trojan known as ‘DcRAT,’...
Android spyware camouflaged as VPN, chat apps on Google Play – Source: www.bleepingcomputer.com
Source: www.bleepingcomputer.com – Author: Bill Toulas Three Android apps on Google Play were used by state-sponsored threat actors to collect intelligence from targeted devices, such as...
New Mystic Stealer malware increasingly used in attacks – Source: www.bleepingcomputer.com
Source: www.bleepingcomputer.com – Author: Bill Toulas A new information-stealing malware named ‘Mystic Stealer,’ has been promoted on hacking forums and darknet markets since April 2023, quickly...
SMS delivery reports can be used to infer recipient’s location – Source: www.bleepingcomputer.com
Source: www.bleepingcomputer.com – Author: Bill Toulas A team of university researchers has devised a new side-channel attack named ‘Freaky Leaky SMS,’ which relies on the timing...
Google targets fake business reviews network in new lawsuit – Source: www.bleepingcomputer.com
Source: www.bleepingcomputer.com – Author: Bill Toulas Google has filed a consumer protection lawsuit against Ethan QiQi Hu and his company, Rafadigital, accusing him of creating 350...
Western Digital boots outdated NAS devices off of My Cloud – Source: www.bleepingcomputer.com
Source: www.bleepingcomputer.com – Author: Bill Toulas Western Digital is warning owners of My Cloud series devices that can no longer connect to cloud services starting on...
Millions of Oregon, Louisiana state IDs stolen in MOVEit breach – Source: www.bleepingcomputer.com
Source: www.bleepingcomputer.com – Author: Bill Toulas Louisiana and Oregon warn that millions of driver’s licenses were exposed in a data breach after a ransomware gang hacked...
Android GravityRAT malware now steals your WhatsApp backups – Source: www.bleepingcomputer.com
Source: www.bleepingcomputer.com – Author: Bill Toulas A new Android malware campaign spreading the latest version of GravityRAT has been underway since August 2022, infecting mobile devices...
Barracuda ESG zero-day attacks linked to suspected Chinese hackers – Source: www.bleepingcomputer.com
Source: www.bleepingcomputer.com – Author: Bill Toulas A suspected pro-China hacker group tracked by Mandiant as UNC4841 has been linked to data-theft attacks on Barracuda ESG (Email...
Russian hackers use PowerShell USB malware to drop backdoors – Source: www.bleepingcomputer.com
Source: www.bleepingcomputer.com – Author: Bill Toulas The Russian state-sponsored hacking group Gamaredon (aka Armageddon or Shuckworm) continues to target critical organizations in Ukraine’s military and security intelligence...
WannaCry ransomware impersonator targets Russian “Enlisted” FPS players – Source: www.bleepingcomputer.com
Source: www.bleepingcomputer.com – Author: Bill Toulas A ransomware operation targets Russian players of the Enlisted multiplayer first-person shooter, using a fake website to spread trojanized versions...
Fake WannaCry ransomware targets Russian “Enlisted” FPS players – Source: www.bleepingcomputer.com
Source: www.bleepingcomputer.com – Author: Bill Toulas A ransomware operation targets Russian players of the Enlisted multiplayer first-person shooter, using a fake website to spread trojanized versions...
New ‘Shampoo’ Chromeloader malware pushed via fake warez sites – Source: www.bleepingcomputer.com
Source: www.bleepingcomputer.com – Author: Bill Toulas A new ChromeLoader campaign is underway, infecting visitors of warez and pirated movie sites with a new variant of the...
Chinese hackers use DNS-over-HTTPS for Linux malware communication – Source: www.bleepingcomputer.com
Source: www.bleepingcomputer.com – Author: Bill Toulas The Chinese threat group ‘ChamelGang’ infects Linux devices with a previously unknown implant named ‘ChamelDoH,’ allowing DNS-over-HTTPS communications with attackers’...
Fake zero-day PoC exploits on GitHub push Windows, Linux malware – Source: www.bleepingcomputer.com
Source: www.bleepingcomputer.com – Author: Bill Toulas Hackers are impersonating cybersecurity researchers on Twitter and GitHub to publish fake proof-of-concept exploits for zero-day vulnerabilities that infect Windows...
Pirated Windows 10 ISOs install clipper malware via EFI partitions – Source: www.bleepingcomputer.com
Source: www.bleepingcomputer.com – Author: Bill Toulas Hackers are distributing Windows 10 using torrents that hide cryptocurrency hijackers in the EFI (Extensible Firmware Interface) partition to evade...
WordPress Stripe payment plugin bug leaks customer order details – Source: www.bleepingcomputer.com
Source: www.bleepingcomputer.com – Author: Bill Toulas The WooCommerce Stripe Gateway plugin for WordPress was found to be vulnerable to a bug that allows any unauthenticated user...
Bulletproof hoster gets 3 years for pushing Urfsnif, Zeus malware – Source: www.bleepingcomputer.com
Source: www.bleepingcomputer.com – Author: Bill Toulas Romanian national Mihai Ionut Paunescu, aka “Virus,” was sentenced to three years in prison by a Manhattan federal court for...
Have I Been Pwned warns of new Zacks data breach impacting 8 million – Source: www.bleepingcomputer.com
Source: www.bleepingcomputer.com – Author: Bill Toulas Zacks Investment Research (Zacks) has reportedly suffered an older, previously undisclosed data breach impacting 8.8 million customers, with the database...
Swiss government warns of ongoing DDoS attacks, data leak – Source: www.bleepingcomputer.com
Source: www.bleepingcomputer.com – Author: Bill Toulas The Swiss government has disclosed that a recent ransomware attack on an IT supplier might have impacted its data, while...
Strava heatmap feature can be abused to find home addresses – Source: www.bleepingcomputer.com
Source: www.bleepingcomputer.com – Author: Bill Toulas Researchers at the North Carolina State University Raleigh have discovered a privacy risk in the Strava app’s heatmap feature that could...
Hackers steal $3 million by impersonating crypto news journalists – Source: www.bleepingcomputer.com
Source: www.bleepingcomputer.com – Author: Bill Toulas A hacking group tracked as ‘Pink Drainer’ is impersonating journalists in phishing attacks to compromise Discord and Twitter accounts for...
University of Manchester says hackers ‘likely’ stole data in cyberattack – Source: www.bleepingcomputer.com
Source: www.bleepingcomputer.com – Author: Bill Toulas The University of Manchester warns staff and students that they suffered a cyberattack where threat actors likely stole data from...