Category: TheHackerNews

Google Releases Android Update
08
Apr
2025

Google Releases Android Update to Patch Two Actively Exploited Vulnerabilities

Apr 08, 2025Ravie LakshmananMobile Security / Vulnerability Google has shipped patches for 62 vulnerabilities, two of which it said have…

Fast Flux is Powering Resilient Malware
07
Apr
2025

CISA and FBI Warn Fast Flux is Powering Resilient Malware, C2, and Phishing Networks

Apr 07, 2025Ravie LakshmananMalware / Network Security Cybersecurity agencies from Australia, Canada, New Zealand, and the United States have published…

Security Theater: Vanity Metrics Keep You Busy
07
Apr
2025

Security Theater: Vanity Metrics Keep You Busy

Apr 07, 2025The Hacker NewsAttack Surface Management After more than 25 years of mitigating risks, ensuring compliance, and building robust…

PoisonSeed Exploits CRM Accounts to Launch Cryptocurrency Seed Phrase Poisoning Attacks
07
Apr
2025

PoisonSeed Exploits CRM Accounts to Launch Cryptocurrency Seed Phrase Poisoning Attacks

Apr 07, 2025Ravie LakshmananCloud Security / Cryptocurrency A malicious campaign dubbed PoisonSeed is leveraging compromised credentials associated with customer relationship…

Microsoft Credits EncryptHub
05
Apr
2025

Microsoft Credits EncryptHub, Hacker Behind 618+ Breaches, for Disclosing Windows Flaws

A likely lone wolf actor behind the EncryptHub persona was acknowledged by Microsoft for discovering and reporting two security flaws…

Malicious npm Packages
05
Apr
2025

North Korean Hackers Deploy BeaverTail Malware via 11 Malicious npm Packages

Apr 05, 2025Ravie LakshmananMalware / Supply Chain Attack The North Korean threat actors behind the ongoing Contagious Interview campaign are…

Malicious Python Packages on PyPI
05
Apr
2025

Malicious Python Packages on PyPI Downloaded 39,000+ Times, Steal Sensitive Data

Apr 05, 2025Ravie LakshmananMalware / Supply Chain Attack Cybersecurity researchers have uncovered malicious libraries in the Python Package Index (PyPI)…

OPSEC Failure Exposes Coquettte's Malware Campaigns on Bulletproof Hosting Servers
04
Apr
2025

OPSEC Failure Exposes Coquettte’s Malware Campaigns on Bulletproof Hosting Servers

Apr 04, 2025Ravie LakshmananThreat Intelligence / Malware A novice cybercrime actor has been observed leveraging the services of a Russian…

Have We Reached a Distroless Tipping Point?
04
Apr
2025

Have We Reached a Distroless Tipping Point?

There’s a virtuous cycle in technology that pushes the boundaries of what’s being built and how it’s being used. A…

SpotBugs Access Token Theft Identified as Root Cause of GitHub Supply Chain Attack
04
Apr
2025

SpotBugs Access Token Theft Identified as Root Cause of GitHub Supply Chain Attack

Apr 04, 2025Ravie LakshmananVulnerability / Open Source, The cascading supply chain attack that initially targeted Coinbase before becoming more widespread…

04
Apr
2025

Have We Reached a Distroless Tipping Point?

There’s a virtuous cycle in technology that pushes the boundaries of what’s being built and how it’s being used. A…

04
Apr
2025

Have We Reached a Distroless Tipping Point?

There’s a virtuous cycle in technology that pushes the boundaries of what’s being built and how it’s being used. A…