Category: TheHackerNews

AI Jailbreak
03
Jan
2025

New AI Jailbreak Method ‘Bad Likert Judge’ Boosts Attack Success Rates by Over 60%

Jan 03, 2025Ravie LakshmananMachine Learning / Vulnerability Cybersecurity researchers have shed light on a new jailbreak technique that could be…

LDAPNightmare PoC Exploit
03
Jan
2025

LDAPNightmare PoC Exploit Crashes LSASS and Reboots Windows Domain Controllers

Jan 03, 2025Ravie LakshmananWindows Server / Threat Mitigation A proof-of-concept (PoC) exploit has been released for a now-patched security flaw…

.NET Domains
03
Jan
2025

Update Old .NET Domains Before January 7, 2025 to Avoid Service Disruption

Jan 03, 2025Ravie LakshmananDevOps / Software Development Microsoft has announced that it’s making an “unexpected change” to the way .NET…

Siri Privacy Violations
03
Jan
2025

Apple to Pay Siri Users $20 Per Device in Settlement Over Accidental Siri Privacy Violations

Jan 03, 2025Ravie LakshmananTechnology / Data Privacy Apple has agreed to pay $95 million to settle a proposed class action…

Microsoft Dynamics 365 and Power Apps Web API
02
Jan
2025

Severe Security Flaws Patched in Microsoft Dynamics 365 and Power Apps Web API

Jan 02, 2025Ravie LakshmananVulnerability / Data Protection Details have emerged about three now-patched security vulnerabilities in Dynamics 365 and Power…

Espionage for Russian Secret Service
02
Jan
2025

Three Russian-German Nationals Charged with Espionage for Russian Secret Service

Jan 02, 2025Ravie LakshmananCyber Espionage / Hacking German prosecutors have charged three Russian-German nationals for acting as secret service agents…

Cross-Domain Attacks
02
Jan
2025

A Growing Threat to Modern Security and How to Combat Them

Jan 02, 2025The Hacker NewsCloud Security / Threat Intelligence In the past year, cross-domain attacks have gained prominence as an…

Malicious Obfuscated NPM Package Disguised as an Ethereum Tool Deploys Quasar RAT
02
Jan
2025

Malicious Obfuscated NPM Package Disguised as an Ethereum Tool Deploys Quasar RAT

Cybersecurity researchers have discovered a malicious package on the npm package registry that masquerades as a library for detecting vulnerabilities…

DoubleClickjacking
01
Jan
2025

New “DoubleClickjacking” Exploit Bypasses Clickjacking Protections on Major Websites

Jan 01, 2025Ravie LakshmananWeb Security / Vulnerability Threat hunters have disclosed a new “widespread timing-based vulnerability class” that leverages a…

Election Interference Using AI and Cyber Tactics
01
Jan
2025

Iranian and Russian Entities Sanctioned for Election Interference Using AI and Cyber Tactics

Jan 01, 2025Ravie LakshmananGenerative AI / Election Interference The U.S. Treasury Department’s Office of Foreign Assets Control (OFAC) on Tuesday…

Bulk Data Transfers
31
Dec
2024

New U.S. DoJ Rule Halts Bulk Data Transfers to Adversarial Nations to Protect Privacy

Dec 31, 2024Ravie LakshmananData Security / Privacy The U.S. Department of Justice (DoJ) has issued a final rule carrying out…

U.S. Treasury Systems
31
Dec
2024

Chinese APT Exploits BeyondTrust API Key to Access U.S. Treasury Systems and Documents

Dec 31, 2025Ravie LakshmananVulnerability / Incident Response The United States Treasury Department said it suffered a “major cybersecurity incident” that…