Category: TheHackerNews

Vulnerability Management
25
Apr
2023

The Move Toward Exposure Management

Apr 25, 2023The Hacker NewsVulnerability Management Managing vulnerabilities in the constantly evolving technological landscape is a difficult task. Although vulnerabilities…

RustBucket macOS Malware
25
Apr
2023

Lazarus Subgroup Targeting Apple Devices with New RustBucket macOS Malware

A financially-motivated North Korean threat actor is suspected to be behind a new Apple macOS malware strain called RustBucket. “[RustBucket]…

Google Authenticator
25
Apr
2023

Google Authenticator App Gets Cloud Backup Feature for TOTP Codes

Apr 25, 2023Ravie LakshmananPassword Security / Authentication Search giant Google on Monday unveiled a major update to its 12-year-old Authenticator…

Ransomware Hackers
24
Apr
2023

Ransomware Hackers Using AuKill Tool to Disable EDR Software Using BYOVD Attack

Apr 24, 2023Ravie LakshmananEndpoint Security / BYOVD Threat actors are employing a previously undocumented “defense evasion tool” dubbed AuKill that’s…

Russian Hackers
24
Apr
2023

Russian Hackers Tomiris Targeting Central Asia for Intelligence Gathering

Apr 24, 2023Ravie LakshmananCyber Espionage The Russian-speaking threat actor behind a backdoor known as Tomiris is primarily focused on gathering…

WordPress Sites
24
Apr
2023

Hackers Exploit Outdated WordPress Plugin to Backdoor Thousands of WordPress Sites

Apr 24, 2023Ravie LakshmananServer Security / WordPress Threat actors have been observed leveraging a legitimate but outdated WordPress plugin to…

SaaS Security
24
Apr
2023

Study: 84% of Companies Use Breached SaaS Applications

Apr 24, 2023The Hacker NewsSaaS Security A recent review by Wing Security, a SaaS security company that analyzed the data…

Stealer for Windows
24
Apr
2023

New All-in-One “EvilExtractor” Stealer for Windows Systems Surfaces on the Dark Web

Apr 24, 2023Ravie LakshmananCyber Risk / Dark Web A new “all-in-one” stealer malware named EvilExtractor (also spelled Evil Extractor) is…

PaperCut Servers
24
Apr
2023

Russian Hackers Suspected in Ongoing Exploitation of Unpatched PaperCut Servers

Apr 24, 2023Ravie LakshmananThreat Intel / Cyber Attack Print management software provider PaperCut said that it has “evidence to suggest…

KEV Catalog
22
Apr
2023

CISA Adds 3 Actively Exploited Flaws to KEV Catalog, including Critical PaperCut Bug

Apr 22, 2023Ravie LakshmananPatch Management / Vulnerability The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Friday added three security…

Critical Infra Hacking
22
Apr
2023

Lazarus X_TRADER Hack Impacts Critical Infrastructure Beyond 3CX Breach

Apr 22, 2023Ravie LakshmananSupply Chain / Cyber Threat Lazarus, the prolific North Korean hacking group behind the cascading supply chain…

Kubernetes RBAC
21
Apr
2023

Kubernetes RBAC Exploited in Large-Scale Campaign for Cryptocurrency Mining

Apr 21, 2023Ravie LakshmananKubernetes / Cryptocurrency A large-scale attack campaign discovered in the wild has been exploiting Kubernetes (K8s) Role-Based…