Category: TheHackerNews

Hackers Use TikTok Videos to Distribute Vidar and StealC Malware via ClickFix Technique
23
May
2025

Hackers Use TikTok Videos to Distribute Vidar and StealC Malware via ClickFix Technique

The malware known as Latrodectus has become the latest to embrace the widely-used social engineering technique called ClickFix as a…

ViciousTrap Uses Cisco Flaw to Build Global Honeypot from 5,300 Compromised Devices
23
May
2025

ViciousTrap Uses Cisco Flaw to Build Global Honeypot from 5,300 Compromised Devices

May 23, 2025Ravie LakshmananThreat Intelligence / Network Security Cybersecurity researchers have disclosed that a threat actor codenamed ViciousTrap has compromised…

Ransomware Networks Worldwide
23
May
2025

300 Servers and €3.5M Seized as Europol Strikes Ransomware Networks Worldwide

May 23, 2025Ravie LakshmananRansomware / Dark Web As part of the latest “season” of Operation Endgame, a coalition of law…

Open Source Web Application Firewall
23
May
2025

Open Source Web Application Firewall with Zero-Day Detection and Bot Protection

From zero-day exploits to large-scale bot attacks — the demand for a powerful, self-hosted, and user-friendly web application security solution…

U.S. Dismantles DanaBot Malware Network, Charges 16 in $50M Global Cybercrime Operation
23
May
2025

U.S. Dismantles DanaBot Malware Network, Charges 16 in $50M Global Cybercrime Operation

The U.S. Department of Justice (DoJ) on Thursday announced the disruption of the online infrastructure associated with DanaBot (aka DanaTools)…

GitLab Duo Vulnerability
23
May
2025

GitLab Duo Vulnerability Enabled Attackers to Hijack AI Responses with Hidden Prompts

Cybersecurity researchers have discovered an indirect prompt injection flaw in GitLab’s artificial intelligence (AI) assistant Duo that could have allowed…

Broader SaaS Attacks
23
May
2025

CISA Warns of Suspected Broader SaaS Attacks Exploiting App Secrets and Cloud Misconfigs

May 23, 2025Ravie LakshmananCloud Security / Vulnerability The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Thursday revealed that Commvault…

Chinese Hackers Exploit Trimble Cityworks Flaw
22
May
2025

Chinese Hackers Exploit Trimble Cityworks Flaw to Infiltrate U.S. Government Networks

May 22, 2025Ravie LakshmananVulnerability / Threat Intelligence A Chinese-speaking threat actor tracked as UAT-6382 has been linked to the exploitation…

Unpatched Versa Concerto Flaws Let Attackers Escape Docker and Compromise Host
22
May
2025

Unpatched Versa Concerto Flaws Let Attackers Escape Docker and Compromise Host

May 22, 2025Ravie LakshmananVulnerability / Software Security Cybersecurity researchers have uncovered multiple critical security vulnerabilities impacting the Versa Concerto network…

Critical Windows Server 2025 dMSA Vulnerability Enables Active Directory Compromise
22
May
2025

Critical Windows Server 2025 dMSA Vulnerability Enables Active Directory Compromise

May 22, 2025Ravie LakshmananCybersecurity / Vulnerability A privilege escalation flaw has been demonstrated in Windows Server 2025 that makes it…

Learn How to Build a Reasonable and Legally Defensible Cybersecurity Program
22
May
2025

Learn How to Build a Reasonable and Legally Defensible Cybersecurity Program

May 22, 2025The Hacker NewsSecurity Framework / Cyber Defense It’s not enough to be secure. In today’s legal climate, you…

Chinese Hackers Exploit Ivanti EPMM Bugs in Global Enterprise Network Attacks
22
May
2025

Chinese Hackers Exploit Ivanti EPMM Bugs in Global Enterprise Network Attacks

May 22, 2025Ravie LakshmananEnterprise Security / Malware A recently patched pair of security flaws affecting Ivanti Endpoint Manager Mobile (EPMM)…