Category: TheHackerNews

Windows Zero-Day
27
Mar
2025

EncryptHub Exploits Windows Zero-Day to Deploy Rhadamanthys and StealC Malware

Mar 26, 2025Ravie LakshmananWindows Security / Vulnerability The threat actor known as EncryptHub exploited a recently-patched security vulnerability in Microsoft…

SparrowDoor Backdoor
27
Mar
2025

New SparrowDoor Backdoor Variants Found in Attacks on U.S. and Mexican Organizations

Mar 26, 2025Ravie LakshmananMalware / Vulnerability The Chinese threat actor known as FamousSparrow has been linked to a cyber attack…

RansomHub's EDRKillShifter
27
Mar
2025

Hackers Repurpose RansomHub’s EDRKillShifter in Medusa, BianLian, and Play Attacks

Mar 27, 2025Ravie LakshmananEndpoint Security / Ransomware A new analysis has uncovered connections between affiliates of RansomHub and other ransomware…

NetApp SnapCenter
27
Mar
2025

NetApp SnapCenter Flaw Could Let Users Gain Remote Admin Access on Plug-In Systems

Mar 27, 2025Ravie LakshmananVulnerability / Enterprise Security A critical security flaw has been disclosed in NetApp SnapCenter that, if successfully…

CISA Warns of Sitecore RCE Flaws; Active Exploits Hit Next.js and DrayTek Devices
27
Mar
2025

CISA Warns of Sitecore RCE Flaws; Active Exploits Hit Next.js and DrayTek Devices

Mar 27, 2025Ravie LakshmananVulnerability / Threat Intelligence The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added two six-year-old security…

India Post Website
27
Mar
2025

APT36 Spoofs India Post Website to Infect Windows and Android Users with Malware

Mar 27, 2025Ravie LakshmananMobile Security / Malware An advanced persistent threat (APT) group with ties to Pakistan has been attributed…

Chinese Gambling Platforms
27
Mar
2025

150,000 Sites Compromised by JavaScript Injection Promoting Chinese Gambling Platforms

Mar 27, 2025Ravie LakshmananMalware / Website Security An ongoing campaign that infiltrates legitimate websites with malicious JavaScript injects to promote…

Why CASB Solutions Fail to Address Shadow SaaS
27
Mar
2025

New Report Explains Why CASB Solutions Fail to Address Shadow SaaS and How to Fix It

Mar 27, 2025The Hacker NewsBrowser Security / Data Protection Whether it’s CRMs, project management tools, payment processors, or lead management…

MS Office Exploits
27
Mar
2025

Top 3 MS Office Exploits Hackers Use in 2025 – Stay Alert!

Hackers have long used Word and Excel documents as delivery vehicles for malware, and in 2025, these tricks are far…

3 Victims, $5K Entry Fee, Multi-OS, and Double Extortion Tactics
24
Mar
2025

3 Victims, $5K Entry Fee, Multi-OS, and Double Extortion Tactics

Mar 24, 2025Ravie LakshmananMalware / Ransomware A ransomware-as-a-service (RaaS) operation called VanHelsing has already claimed three victims since it launched…

Password Security
24
Mar
2025

How to Balance Password Security Against User Experience

Mar 24, 2025Ravie LakshmananPassword Security / Compliance If given the choice, most users are likely to favor a seamless experience…

VSCode Marketplace
24
Mar
2025

VSCode Marketplace Removes Two Extensions Deploying Early-Stage Ransomware

Mar 24, 2025Ravie LakshmananMalware / Encryption Cybersecurity researchers have uncovered two malicious extensions in the Visual Studio Code (VSCode) Marketplace…