Category: TheHackerNews

Malicious Visual Studio Extensions
10
Jan
2023

Hackers Can Abuse Visual Studio Marketplace to Target Developers with Malicious Extensions

Jan 09, 2023Ravie LakshmananSupply Chain / CodeSec A new attack vector targeting the Visual Studio Code extensions marketplace could be…

SaaS Cybersecurity Threats
09
Jan
2023

Top SaaS Cybersecurity Threats in 2023: Are You Ready?

Jan 09, 2023The Hacker NewsWeb Security / SaaS Security Cybercriminals will be as busy as ever this year. Stay safe…

PyPI Packages Using Cloudflare Tunnels
09
Jan
2023

Malicious PyPI Packages Using Cloudflare Tunnels to Sneak Through Firewalls

Jan 09, 2023Ravie LakshmananNetwork Security / Supply Chain In yet another campaign targeting the Python Package Index (PyPI) repository, six…

Car Hacking
09
Jan
2023

API Vulnerabilities Uncovered in 16 Major Car Brands

Jan 09, 2023Ravie LakshmananAutomotive Security Multiple bugs affecting millions of vehicles from 16 different manufacturers could be abused to unlock,…

Kinsing Cryptojacking
09
Jan
2023

Kinsing Cryptojacking Hits Kubernetes Clusters via Misconfigured PostgreSQL

Jan 09, 2023Ravie LakshmananKubernetes / Cryptojacking The threat actors behind the Kinsing cryptojacking operation have been spotted exploiting misconfigured and…

Text-to-SQL Model Vulnerabilities
09
Jan
2023

New Study Uncovers Text-to-SQL Model Vulnerabilities Allowing Data Theft and DoS Attacks

Jan 09, 2023Ravie LakshmananDatabase Security / PLM Framework A group of academics has demonstrated novel attacks that leverage Text-to-SQL models…

SaaS Security
09
Jan
2023

Why Do User Permissions Matter for SaaS Security?

Jan 09, 2023The Hacker NewsSaaS Security / SSPM Solution Earlier this year, threat actors infiltrated Mailchimp, the popular SaaS email…

Russian Turla Hackers Hijack Decade-Old Malware Infrastructure to Deploy New Backdoors
08
Jan
2023

Russian Turla Hackers Hijack Decade-Old Malware Infrastructure to Deploy New Backdoors

Jan 08, 2023Ravie LakshmananCyberespionage / Threat Analysis The Russian cyberespionage group known as Turla has been observed piggybacking on attack…

Freejacking Campaign
06
Jan
2023

Hackers Using CAPTCHA Bypass Tactics in Freejacking Campaign on GitHub

Jan 06, 2023Ravie LakshmananCryptocurrency / GitHub A South Africa-based threat actor known as Automated Libra has been observed employing CAPTCHA…

Dridex Malware Now Attacking macOS Systems with Novel Infection Method
06
Jan
2023

Dridex Malware Now Attacking macOS Systems with Novel Infection Method

Jan 06, 2023Ravie LakshmananUnited States A variant of the infamous Dridex banking malware has set its sights on Apple’s macOS…

Ransomware Families Targeting macOS
06
Jan
2023

Microsoft Reveals Tactics Used by 4 Ransomware Families Targeting macOS

Jan 06, 2023Ravie LakshmananEndpoint Security / Cyber Threat Microsoft has shed light on four different ransomware families – KeRanger, FileCoder,…

WhatsApp Introduces Proxy Support to Help Users Bypass Internet Censorship
06
Jan
2023

WhatsApp Introduces Proxy Support to Help Users Bypass Internet Censorship

Jan 06, 2023Ravie LakshmananOnline Safety / Privacy Popular instant messaging service WhatsApp has launched support for proxy servers in the…