Category: TheHackerNews

Popular Chrome Extensions Leak API Keys, User Data via HTTP and Hardcoded Credentials
05
Jun
2025

Popular Chrome Extensions Leak API Keys, User Data via HTTP and Hardcoded Credentials

Jun 05, 2025Ravie LakshmananBrowser Security / Online Safety Cybersecurity researchers have flagged several popular Google Chrome extensions that have been…

Bitter Hacker Group
05
Jun
2025

Researchers Detail Bitter APT’s Evolving Tactics as Its Geographic Scope Expands

Jun 05, 2025Ravie LakshmananThreat Intelligence / Network Security The threat actor known as Bitter has been assessed to be a…

Whisper and Spearal Malware
05
Jun
2025

Iran-Linked BladedFeline Hits Iraqi and Kurdish Targets with Whisper and Spearal Malware

An Iran-aligned hacking group has been attributed to a new set of cyber attacks targeting Kurdish and Iraqi government officials…

Why Business Impact Should Lead the Security Conversation
05
Jun
2025

Why Business Impact Should Lead the Security Conversation

Security teams face growing demands with more tools, more data, and higher expectations than ever. Boards approve large security budgets,…

DoJ Seizes 145 Domains Tied to BidenCash Carding Marketplace in Global Takedown
05
Jun
2025

DoJ Seizes 145 Domains Tied to BidenCash Carding Marketplace in Global Takedown

Jun 05, 2025Ravie LakshmananDark Web / Law Enforcement The U.S. Department of Justice (DoJ) on Wednesday announced the seizure of…

Cisco ISE Auth Bypass Flaw
05
Jun
2025

Critical Cisco ISE Auth Bypass Flaw Impacts Cloud Deployments on AWS, Azure, and OCI

Jun 05, 2025Ravie LakshmananNetwork Security / Vulnerability Cisco has released security patches to address a critical security flaw impacting the…

Google Exposes Vishing Group UNC6040 Targeting Salesforce with Fake Data Loader App
04
Jun
2025

Google Exposes Vishing Group UNC6040 Targeting Salesforce with Fake Data Loader App

Jun 04, 2025Ravie Lakshmanan Threat Intelligence / Data Breach Google has disclosed details of a financially motivated threat cluster that…

Chaos RAT Malware
04
Jun
2025

Chaos RAT Malware Targets Windows and Linux via Fake Network Tool Downloads

Jun 04, 2025Ravie LakshmananLinux / Malware Threat hunters are calling attention to a new variant of a remote access trojan…

Why Traditional DLP Solutions Fail in the Browser Era
04
Jun
2025

Why Traditional DLP Solutions Fail in the Browser Era

Jun 04, 2025The Hacker NewsBrowser Security / Enterprise Security Traditional data leakage prevention (DLP) tools aren’t keeping pace with the…

Malicious PyPI, npm, and Ruby Packages
04
Jun
2025

Malicious PyPI, npm, and Ruby Packages Exposed in Ongoing Open-Source Supply Chain Attacks

Several malicious packages have been uncovered across the npm, Python, and Ruby package repositories that drain funds from cryptocurrency wallets,…

HPE Issues Security Patch
04
Jun
2025

HPE Issues Security Patch for StoreOnce Bug Allowing Remote Authentication Bypass

Jun 04, 2025The Hacker NewsVulnerability / DevOps Hewlett Packard Enterprise (HPE) has released security updates to address as many as…

Multi-Stage PowerShell Attack
03
Jun
2025

Fake DocuSign, Gitcode Sites Spread NetSupport RAT via Multi-Stage PowerShell Attack

Jun 03, 2025Ravie LakshmananUnited States Threat hunters are alerting to a new campaign that employs deceptive websites to trick unsuspecting…