❌

Normal view

There are new articles available, click to refresh the page.
Today β€” 14 June 2024The Hacker News

Google's Privacy Sandbox Accused of User Tracking by Austrian Non-Profit

By: Newsroom
14 June 2024 at 13:21
Google's plans to deprecate third-party tracking cookies in its Chrome web browser with Privacy Sandbox has run into fresh trouble after Austrian privacy non-profit noyb (none of your business) said the feature can still be used to track users. "While the so-called 'Privacy Sandbox' is advertised as an improvement over extremely invasive third-party tracking, the tracking is now simply done

ZKTeco Biometric System Found Vulnerable to 24 Critical Security Flaws

By: Newsroom
14 June 2024 at 08:09
An analysis of a hybrid biometric access system from Chinese manufacturer ZKTeco has uncovered two dozen security flaws that could be used by attackers to defeat authentication, steal biometric data, and even deploy malicious backdoors. "By adding random user data to the database or using a fake QR code, a nefarious actor can easily bypass the verification process and gain unauthorized access,"

North Korean Hackers Target Brazilian Fintech with Sophisticated Phishing Tactics

By: Newsroom
14 June 2024 at 06:45
Threat actors linked to North Korea have accounted for one-third of all the phishing activity targeting Brazil since 2020, as the country's emergence as an influential power has drawn the attention of cyber espionage groups. "North Korean government-backed actors have targeted the Brazilian government and Brazil's aerospace, technology, and financial services sectors," Google's Mandiant and

Microsoft Delays AI-Powered Recall Feature for Copilot+ PCs Amid Security Concerns

By: Newsroom
14 June 2024 at 04:30
Microsoft on Thursday revealed that it's delaying the rollout of the controversial artificial intelligence (AI)-powered Recall feature for Copilot+ PCs. To that end, the company said it intends to shift from general availability to a preview available first in the Windows Insider Program (WIP) in the coming weeks. "We are adjusting the release model for Recall to leverage the expertise of the

Yesterday β€” 13 June 2024The Hacker News

New Attack Technique 'Sleepy Pickle' Targets Machine Learning Models

By: Newsroom
13 June 2024 at 14:08
The security risks posed by the Pickle format have once again come to the fore with the discovery of a new "hybrid machine learning (ML) model exploitation technique" dubbed Sleepy Pickle. The attack method, per Trail of Bits, weaponizes the ubiquitous format used to package and distribute machine learning (ML) models to corrupt the model itself, posing a severe supply chain risk to an

Arid Viper Launches Mobile Espionage Campaign with AridSpy Malware

By: Newsroom
13 June 2024 at 13:55
The threat actor known as Arid Viper has been attributed to a mobile espionage campaign that leverages trojanized Android apps to deliver a spyware strain dubbed AridSpy. "The malware is distributed through dedicated websites impersonating various messaging apps, a job opportunity app, and a Palestinian Civil Registry app," ESET researcher LukΓ‘Ε‘ Ε tefanko said in a report published today. "Often

Why SaaS Security is Suddenly Hot: Racing to Defend and Comply

By: Newsroom
13 June 2024 at 11:30
Recent supply chain cyber-attacks are prompting cyber security regulations in the financial sector to tighten compliance requirements, and other industries are expected to follow. Many companies still don’t have efficient methods to manage related time-sensitive SaaS security and compliance tasks. Free SaaS risk assessment tools are an easy and practical way to bring visibility and initial

Pakistan-linked Malware Campaign Evolves to Target Windows, Android, and macOS

By: Newsroom
13 June 2024 at 10:26
Threat actors with ties to Pakistan have been linked to a long-running malware campaign dubbed Operation Celestial Force since at least 2018. The activity, still ongoing, entails the use of an Android malware called GravityRAT and a Windows-based malware loader codenamed HeavyLift, according to Cisco Talos, which are administered using another standalone tool referred to as GravityAdmin. The

Cybercriminals Employ PhantomLoader to Distribute SSLoad Malware

By: Newsroom
13 June 2024 at 10:19
The nascent malware known as SSLoad is being delivered by means of a previously undocumented loader called PhantomLoader, according to findings from cybersecurity firm Intezer. "The loader is added to a legitimate DLL, usually EDR or AV products, by binary patching the file and employing self-modifying techniques to evade detection," security researchers Nicole Fishbein and Ryan Robinson said in

Ukraine Police Arrest Suspect Linked to LockBit and Conti Ransomware Groups

By: Newsroom
13 June 2024 at 08:05
The Cyber Police of Ukraine has announced the arrest of a local man who is suspected to have offered their services to LockBit and Conti ransomware groups. The unnamed 28-year-old native of the Kharkiv region allegedly specialized in the development of crypters to encrypt and obfuscate malicious payloads in order to evade detection by security programs. The product is believed to have been

Google Warns of Pixel Firmware Security Flaw Exploited as Zero-Day

By: Newsroom
13 June 2024 at 07:08
Google has warned that a security flaw impacting Pixel Firmware has been exploited in the wild as a zero-day. The high-severity vulnerability, tagged as CVE-2024-32896, has been described as an elevation of privilege issue in Pixel Firmware. The company did not share any additional details related to the nature of attacks exploiting it, but noted "there are indications that CVE-2024-32896 may be

New Cross-Platform Malware 'Noodle RAT' Targets Windows and Linux Systems

By: Newsroom
13 June 2024 at 06:25
A previously undocumented cross-platform malware codenamed Noodle RAT has been put to use by Chinese-speaking threat actors either for espionage or cybercrime for years. While this backdoor was previously categorized as a variant of Gh0st RAT and Rekoobe, Trend Micro security researcher Hara Hiroaki said "this backdoor is not merely a variant of existing malware, but is a new type altogether."

❌
❌