There are new articles available, click to refresh the page.
Before yesterdayThe Hacker News

Product Overview: Cynet SaaS Security Posture Management (SSPM)

21 October 2021 at 13:07
Software-as-a-service (SaaS) applications have gone from novelty to business necessity in a few short years, and its positive impact on organizations is clear. It’s safe to say that most industries today run on SaaS applications, which is undoubtedly positive, but it does introduce some critical new challenges to organizations.Β  As SaaS application use expands, as well as the number of

Malicious NPM Packages Caught Running Cryptominer On Windows, Linux, macOS Devices

21 October 2021 at 11:00
Three JavaScript libraries uploaded to the official NPM package repository have been unmasked as crypto-mining malware, once again demonstrating how open-source software package repositories are becoming a lucrative target for executing an array of attacks on Windows, macOS, and Linux systems. The malicious packages in question β€” namedΒ okhsa,Β klow, andΒ klownΒ β€” were published by the same

U.S. Government Bans Sale of Hacking Tools to Authoritarian Regimes

21 October 2021 at 07:43
The U.S. Commerce Department on Wednesday announced new rules barring the sales of hacking software and equipment to authoritarian regimes and potentially facilitate human rights abuse for national security (NS) and anti-terrorism (AT) reasons. TheΒ mandate, which is set to go into effect in 90 days, will forbid the export, reexport and transfer of "cybersecurity items" to countries of "national

Hackers Stealing Browser Cookies to Hijack High-Profile YouTube Accounts

21 October 2021 at 07:03
Since at least late 2019, a network of hackers-for-hire have been hijacking the channels of YouTube creators, luring them with bogus collaboration opportunities to broadcast cryptocurrency scams or sell the accounts to the highest bidder. That's according to a new report published by Google's Threat Analysis Group (TAG), which said it disrupted financially motivated phishing campaigns targeting

Two Eastern Europeans Sentenced for Providing Bulletproof Hosting to Cyber Criminals

21 October 2021 at 03:42
Two Eastern European nationals have been sentenced in the U.S. for offering "bulletproof hosting" services to cybercriminals, who used the technical infrastructure to distribute malware and attack financial institutions across the country between 2009 to 2015. Pavel Stassi, 30, of Estonia, and Aleksandr Shorodumov, 33, of Lithuania, have been each sentenced to 24 months and 48 months in prison,

Researchers Break Intel SGX With New 'SmashEx' CPU Attack Technique

20 October 2021 at 13:27
A newly disclosed vulnerability affecting Intel processors could be abused by an adversary to gain access to sensitive information stored within enclaves and even run arbitrary code on vulnerable systems. The vulnerability (CVE-2021-0186, CVSS score: 8.2) was discovered by a group of academics from ETH Zurich, the National University of Singapore, and the Chinese National University of Defense

OWASP's 2021 List Shuffle: A New Battle Plan and Primary Foe

20 October 2021 at 08:16
Code injection attacks, the infamous king of vulnerabilities, have lost the top spot to broken access control as the worst of the worst, and developers need to take notice. In this increasingly chaotic world, there have always been a few constants that people could reliably count on: The sun will rise in the morning and set again at night, Mario will always be cooler than Sonic the Hedgehog, and

LightBasin Hackers Breach at Least 13 Telecom Service Providers Since 2019

20 October 2021 at 08:01
A highly sophisticated adversary named LightBasin has been identified as behind a string of attacks targeting the telecom sector with the goal of collecting "highly specific information" from mobile communication infrastructure, such as subscriber information and call metadata.Β  "The nature of the data targeted by the actor aligns with information likely to be of significant interest to signals

Microsoft Warns of New Security Flaw Affecting Surface Pro 3 Devices

20 October 2021 at 07:20
Microsoft has published a new advisory warning of a security bypass vulnerability affecting Surface Pro 3 convertible laptops that could be exploited by an adversary to introduce malicious devices within enterprise networks and defeat the device attestation mechanism. Tracked asΒ CVE-2021-42299Β (CVSS score: 5.6), the issue has been codenamed "TPM Carte Blanche" by Google software engineer Chris

Squirrel Engine Bug Could Let Attackers Hack Games and Cloud Services

19 October 2021 at 15:07
Researchers have disclosed an out-of-bounds read vulnerability in the Squirrel programming language that can be abused by attackers to break out of the sandbox restrictions and execute arbitrary code within a SquirrelVM, thus giving a malicious actor complete access to the underlying machine.Β  Tracked as CVE-2021-41556, the issue occurs when a game library referred to as Squirrel Engine is used

A New Variant of FlawedGrace Spreading Through Mass Email Campaigns

19 October 2021 at 12:03
Cybersecurity researchers on Tuesday took the wraps off a mass volume email attack staged by a prolific cybercriminal gang affecting a wide range of industries, with one of its region-specific operations notably targeting Germany and Austria. Enterprise security firm Proofpoint tied the malware campaign with high confidence toΒ TA505, which is the name assigned to the financially motivated threat

Cybersecurity Experts Warn of a Rise in Lyceum Hacker Group Activities in Tunisia

19 October 2021 at 06:11
A threat actor, previously known for striking organizations in the energy and telecommunications sectors across the Middle East as early as April 2018, has evolved its malware arsenal to strike two entities in Tunisia. Security researchers at Kaspersky, who presented their findings at the VirusBulletin VB2021 conference earlier this month, attributed the attacks to a group tracked asΒ LyceumΒ (aka

Why Database Patching Best Practice Just Doesn't Work and How to Fix It

18 October 2021 at 16:00
Patching really, really matters – patching is what keeps technology solutions from becoming like big blocks of Swiss cheese, with endless security vulnerabilities punching hole after hole into critical solutions. But anyone who's spent any amount of time maintaining systems will know that patching is often easier said than done. Yes, in some instances, you can just run a command line to install

Over 30 Countries Pledge to Fight Ransomware Attacks in US-led Global Meeting

18 October 2021 at 08:21
Representatives from the U.S., the European Union, and 30 other countries pledged to mitigate the risk of ransomware and harden the financial system from exploitation with the goal of disrupting the ecosystem, calling it an "escalating global security threat with serious economic and security consequences."Β  "From malign operations against local health providers that endanger patient care, to

Is Your Data Safe? Check Out Some Cybersecurity Master Classes

18 October 2021 at 06:30
Since cybersecurity is definitely an issue that’s here to stay, I’ve just checked out the recently released first episodes of Cato NetworksΒ Cybersecurity Master Class Series.Β  According to Cato, the series aims to teach and demonstrate cybersecurity tools and best practices; provide research and real-world case studies on cybersecurity; and bring the voices and opinions of top cybersecurity

REvil Ransomware Gang Goes Underground After Tor Sites Were Compromised

18 October 2021 at 06:49
REvil, the notorious ransomware gang behind a string of cyberattacks in recent years, appears to have gone off the radar once again, a little over a month after the cybercrime group staged a surprise return following a two-month-long hiatus. The development, firstΒ spottedΒ by Recorded Future'sΒ Dmitry Smilyanets, comes after a member affiliated with the REvil operation posted on the XSS hacking

Windows 10, Linux, iOS, Chrome and Many Others at Hacked Tianfu Cup 2021

18 October 2021 at 05:53
Windows 10, iOS 15, Google Chrome, Apple Safari, Microsoft Exchange Server, and Ubuntu 20 were successfully broken into using original, never-before-seen exploits at the Tianfu Cup 2021, the fourth edition of the international cybersecurity contest held in the city of Chengdu, China. Targets this yearΒ includedΒ Google Chrome running on Windows 10 21H1, Apple Safari running on Macbook Pro, Adobe

Attackers Behind Trickbot Expanding Malware Distribution Channels

15 October 2021 at 14:40
The operators behind the pernicious TrickBot malware have resurfaced with new tricks that aim to increase its foothold by expanding its distribution channels, ultimately leading to the deployment of ransomware such as Conti. The threat actor, tracked under the monikers ITG23 and Wizard Spider, has been found to partner with other cybercrime gangs known Hive0105, Hive0106 (aka TA551 or Shathak),

Ad-Blocking Chrome Extension Caught Injecting Ads in Google Search Pages

15 October 2021 at 14:23
A new deceptive ad injection campaign has been found leveraging an ad blocker extension for Google Chrome and Opera web browsers to sneakily insert ads and affiliate codes on websites, according to new research from cybersecurity firm Imperva. The findings come following the discovery of rogue domains distributing an ad injection script in late August 2021 that the researchers connected to an