Category: TheHackerNews

Malicious Excel Add-ins
28
Dec
2022

APT Hackers Turn to Malicious Excel Add-ins as Initial Intrusion Vector

Dec 28, 2022Ravie LakshmananMalware / Windows Security Microsoft’s decision to block Visual Basic for Applications (VBA) macros by default for…

Hacking Using SVG Files to Smuggle QBot Malware onto Windows Systems
28
Dec
2022

Hacking Using SVG Files to Smuggle QBot Malware onto Windows Systems

Dec 15, 2022Ravie LakshmananEmail Security / Endpoint Security Phishing campaigns involving the Qakbot malware are using Scalable Vector Graphics (SVG)…

denial-of-service
28
Dec
2022

FBI Charges 6, Seizes 48 Domains Linked to DDoS-for-Hire Service Platforms

Dec 15, 2022Ravie LakshmananCyber Attack / DDoS-for-Hire The U.S. Department of Justice (DoJ) on Wednesday announced the seizure of 48…

Open Source Repositories
28
Dec
2022

Hackers Bombard Open Source Repositories with Over 144,000 Malicious Packages

Dec 15, 2022Ravie Lakshmanan NuGet, PyPi, and npm ecosystems are the target of a new campaign that has resulted in…

Top 5 Web App Vulnerabilities and How to Find Them
28
Dec
2022

Top 5 Web App Vulnerabilities and How to Find Them

Web applications, often in the form of Software as a Service (SaaS), are now the cornerstone for businesses all over…

Money-Lending Apps
27
Dec
2022

Android Malware Campaign Leverages Money-Lending Apps to Blackmail Victims

A previously undocumented Android malware campaign has been observed leveraging money-lending apps to blackmail victims into paying up with personal…

SPNEGO Extended Negotiation Security Vulnerability
27
Dec
2022

Microsoft Reclassifies SPNEGO Extended Negotiation Security Vulnerability as ‘Critical’

Dec 15, 2022Ravie LakshmananWindows Security / Network Security Microsoft has revised the severity of a security vulnerability it originally patched…

Cyber attack targeting Japanese Political Entities
27
Dec
2022

Researchers Uncover MirrorFace Cyber Attacks Targeting Japanese Political Entities

Dec 15, 2022Ravie LakshmananAdvanced Persistent Threat A Chinese-speaking advanced persistent threat (APT) actor codenamed MirrorFace has been attributed to a…

Veeam Backup and Replication
27
Dec
2022

Veeam Backup and Replication Vulnerabilities Being Exploited in Attacks

Dec 16, 2022Ravie LakshmananBackup & Recovery / Zero-Day The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added two vulnerabilities…

Cross-Platform DDoS Botnet
27
Dec
2022

Microsoft Warns About Cross-Platform DDoS Botnet

Dec 16, 2022Ravie LakshmananServer Security / Botnet Microsoft on Thursday flagged a cross-platform botnet that’s primarily designed to launch distributed…

SHA-1 Cryptographic Algorithm
27
Dec
2022

NIST Retires 27-Year-Old Widely Used Cryptographic Algorithm

Dec 16, 2022Ravie LakshmananEncryption / Data Security The U.S. National Institute of Standards and Technology (NIST), an agency within the…

GitHub Secret Scanning
27
Dec
2022

GitHub Announces Free Secret Scanning for All Public Repositories

Dec 16, 2022Ravie LakshmananSecure Coding / Code Hosting GitHub on Thursday said it is making available its secret scanning service…