Category: TheHackerNews

CISA Warns of Sitecore RCE Flaws; Active Exploits Hit Next.js and DrayTek Devices
27
Mar
2025

CISA Warns of Sitecore RCE Flaws; Active Exploits Hit Next.js and DrayTek Devices

Mar 27, 2025Ravie LakshmananVulnerability / Threat Intelligence The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added two six-year-old security…

India Post Website
27
Mar
2025

APT36 Spoofs India Post Website to Infect Windows and Android Users with Malware

Mar 27, 2025Ravie LakshmananMobile Security / Malware An advanced persistent threat (APT) group with ties to Pakistan has been attributed…

Chinese Gambling Platforms
27
Mar
2025

150,000 Sites Compromised by JavaScript Injection Promoting Chinese Gambling Platforms

Mar 27, 2025Ravie LakshmananMalware / Website Security An ongoing campaign that infiltrates legitimate websites with malicious JavaScript injects to promote…

Why CASB Solutions Fail to Address Shadow SaaS
27
Mar
2025

New Report Explains Why CASB Solutions Fail to Address Shadow SaaS and How to Fix It

Mar 27, 2025The Hacker NewsBrowser Security / Data Protection Whether it’s CRMs, project management tools, payment processors, or lead management…

MS Office Exploits
27
Mar
2025

Top 3 MS Office Exploits Hackers Use in 2025 – Stay Alert!

Hackers have long used Word and Excel documents as delivery vehicles for malware, and in 2025, these tricks are far…

3 Victims, $5K Entry Fee, Multi-OS, and Double Extortion Tactics
24
Mar
2025

3 Victims, $5K Entry Fee, Multi-OS, and Double Extortion Tactics

Mar 24, 2025Ravie LakshmananMalware / Ransomware A ransomware-as-a-service (RaaS) operation called VanHelsing has already claimed three victims since it launched…

Password Security
24
Mar
2025

How to Balance Password Security Against User Experience

Mar 24, 2025Ravie LakshmananPassword Security / Compliance If given the choice, most users are likely to favor a seamless experience…

VSCode Marketplace
24
Mar
2025

VSCode Marketplace Removes Two Extensions Deploying Early-Stage Ransomware

Mar 24, 2025Ravie LakshmananMalware / Encryption Cybersecurity researchers have uncovered two malicious extensions in the Visual Studio Code (VSCode) Marketplace…

Critical Next.js Vulnerability Allows Attackers to Bypass Middleware Authorization Checks
24
Mar
2025

Critical Next.js Vulnerability Allows Attackers to Bypass Middleware Authorization Checks

Mar 24, 2025Ravie LakshmananVulnerability / Web Security A critical security flaw has been disclosed in the Next.js React framework that…

Coinbase Attack Exposes 218 Repositories, Leaks CI/CD Secrets
23
Mar
2025

Coinbase Attack Exposes 218 Repositories, Leaks CI/CD Secrets

The supply chain attack involving the GitHub Action “tj-actions/changed-files” started as a highly-targeted attack against one of Coinbase’s open-source projects,…

Tornado Cash Sanctions
22
Mar
2025

U.S. Treasury Lifts Tornado Cash Sanctions Amid North Korea Money Laundering Probe

Mar 22, 2025Ravie LakshmananFinancial Security / Cryptocurrency The U.S. Treasury Department has announced that it’s removing sanctions against Tornado Cash,…

UAT-5918 Targets Taiwan's Critical Infrastructure Using Web Shells and Open-Source Tools
21
Mar
2025

UAT-5918 Targets Taiwan’s Critical Infrastructure Using Web Shells and Open-Source Tools

Mar 21, 2025Ravie LakshmananThreat Hunting / Vulnerability Threat hunters have uncovered a new threat actor named UAT-5918 that has been…