TheHackerNews

Category Added in a WPeMatico Campaign

U.S. DoJ Dismantles Warzone RAT Infrastructure, Arrests Key Operators

February 12, 2024 The U.S. Justice Department (DoJ) on Friday announced the seizure of online infrastructure that was used to sell a remote access trojan (RAT) called Warzone RAT. The domains – www.warzone[.]ws and three others – were “used to sell computer malware used by cybercriminals to secretly access and steal data from victims’ computers,” the DoJ said. Alongside …

U.S. DoJ Dismantles Warzone RAT Infrastructure, Arrests Key Operators Read More »

Alert: New Stealthy “RustDoor” Backdoor Targeting Apple macOS Devices

February 11, 2024 Apple macOS users are the target of a new Rust-based backdoor that has been operating under the radar since November 2023. The backdoor, codenamed RustDoor by Bitdefender, has been found to impersonate an update for Microsoft Visual Studio and target both Intel and Arm architectures. The exact initial access pathway used to propagate the implant …

Alert: New Stealthy “RustDoor” Backdoor Targeting Apple macOS Devices Read More »

Hands-on Review: Myrror Security Code-Aware and Attack-Aware SCA

February 10, 2024 Introduction The modern software supply chain represents an ever-evolving threat landscape, with each package added to the manifest introducing new attack vectors. To meet industry requirements, organizations must maintain a fast-paced development process while staying up-to-date with the latest security patches. However, in practice, developers often face a large amount of security …

Hands-on Review: Myrror Security Code-Aware and Attack-Aware SCA Read More »

MoqHao Android Malware Evolves with Auto-Execution Capability

February 10, 2024 Threat hunters have identified a new variant of Android malware called MoqHao that automatically executes on infected devices without requiring any user interaction. “Typical MoqHao requires users to install and launch the app to get their desired purpose, but this new variant requires no execution,” McAfee Labs said in a report published this week. “While the …

MoqHao Android Malware Evolves with Auto-Execution Capability Read More »

Raspberry Robin Malware Upgrades with Discord Spread and New Exploits

February 10, 2024 The operators of Raspberry Robin are now using two new one-day exploits to achieve local privilege escalation, even as the malware continues to be refined and improved to make it stealthier than before. This means that “Raspberry Robin has access to an exploit seller or its authors develop the exploits themselves in a short …

Raspberry Robin Malware Upgrades with Discord Spread and New Exploits Read More »

New Coyote Trojan Targets 61 Brazilian Banks with Nim-Powered Attack

February 10, 2024 Sixty-one banking institutions, all of them originating from Brazil, are the target of a new banking trojan called Coyote. “This malware utilizes the Squirrel installer for distribution, leveraging Node.js and a relatively new multi-platform programming language called Nim as a loader to complete its infection,” Russian cybersecurity firm Kaspersky said in a Thursday report. What …

New Coyote Trojan Targets 61 Brazilian Banks with Nim-Powered Attack Read More »

Fortinet Warns of Critical FortiOS SSL VPN Flaw Likely Under Active Exploitation

February 10, 2024 Fortinet has disclosed a new critical security flaw in FortiOS SSL VPN that it said is likely being exploited in the wild. The vulnerability, CVE-2024-21762 (CVSS score: 9.6), allows for the execution of arbitrary code and commands. “A out-of-bounds write vulnerability [CWE-787] in FortiOS may allow a remote unauthenticated attacker to execute arbitrary code …

Fortinet Warns of Critical FortiOS SSL VPN Flaw Likely Under Active Exploitation Read More »

Wazuh in the Cloud Era: Navigating the Challenges of Cybersecurity

February 10, 2024 Cloud computing has innovated how organizations operate and manage IT operations, such as data storage, application deployment, networking, and overall resource management. The cloud offers scalability, adaptability, and accessibility, enabling businesses to achieve sustainable growth. However, adopting cloud technologies into your infrastructure presents various cybersecurity risks and Article posted by: https://thehackernews.com/2024/02/wazuh-in-cloud-era-navigating.html ——————————————————————————————————————– …

Wazuh in the Cloud Era: Navigating the Challenges of Cybersecurity Read More »

Stealthy Zardoor Backdoor Targets Saudi Islamic Charity Organization

February 10, 2024 An unnamed Islamic non-profit organization in Saudi Arabia has been targeted as part of a stealthy cyber espionage campaign designed to drop a previously undocumented backdoor called Zardoor. Cisco Talos, which discovered the activity in May 2023, said the campaign has likely persisted since at least March 2021, adding it has identified only …

Stealthy Zardoor Backdoor Targets Saudi Islamic Charity Organization Read More »

Warning: New Ivanti Auth Bypass Flaw Affects Connect Secure and ZTA Gateways

February 10, 2024 Ivanti has alerted customers of yet another high-severity security flaw in its Connect Secure, Policy Secure, and ZTA gateway devices that could allow attackers to bypass authentication. The issue, tracked as CVE-2024-22024, is rated 8.3 out of 10 on the CVSS scoring system. “An XML external entity or XXE vulnerability in the SAML …

Warning: New Ivanti Auth Bypass Flaw Affects Connect Secure and ZTA Gateways Read More »

Open Whatsapp chat
Whatsapp Us
Chat with us for faster replies.