Goodbye SHA-1: NIST Retires 27-Year-Old Widely Used Cryptographic Algorithm

December 17, 2022 The U.S. National Institute of Standards and Technology (NIST), an agency within the Department of Commerce, announced Thursday that it’s formally retiring the SHA-1 cryptographic algorithm. SHA-1, short for Secure Hash Algorithm 1, is a 27-year-old hash function used in cryptography and has since been deemed broken owing to the risk of collision attacks. While hashes are designed to be …

Goodbye SHA-1: NIST Retires 27-Year-Old Widely Used Cryptographic Algorithm Read More »

Minecraft Servers Under Attack: Microsoft Warns About Cross-Platform DDoS Botnet

December 17, 2022 Microsoft on Thursday flagged a cross-platform botnet that’s primarily designed to launch distributed denial-of-service (DDoS) attacks against private Minecraft servers. Called MCCrash, the botnet is characterized by a unique spreading mechanism that allows it to propagate to Linux-based devices despite originating from malicious software downloads on Windows hosts. “The botnet spreads by Article …

Minecraft Servers Under Attack: Microsoft Warns About Cross-Platform DDoS Botnet Read More »

CISA Alert: Veeam Backup and Replication Vulnerabilities Being Exploited in Attacks

December 17, 2022 The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added two vulnerabilities impacting Veeam Backup & Replication software to its Known Exploited Vulnerabilities (KEV) Catalog, citing evidence of active exploitation in the wild. The now-patched critical flaws, tracked as CVE-2022-26500 and CVE-2022-26501, are both rated 9.8 on the CVSS scoring system, and could be leveraged …

CISA Alert: Veeam Backup and Replication Vulnerabilities Being Exploited in Attacks Read More »

Researchers Uncover MirrorFace Cyber Attacks Targeting Japanese Political Entities

December 16, 2022 A Chinese-speaking advanced persistent threat (APT) actor codenamed MirrorFace has been attributed to a spear-phishing campaign targeting Japanese political establishments. The activity, dubbed Operation LiberalFace by ESET, specifically focused on members of an unnamed political party in the nation with the goal of delivering an implant called LODEINFO and a hitherto unseen credential stealer Article posted …

Researchers Uncover MirrorFace Cyber Attacks Targeting Japanese Political Entities Read More »

Microsoft Reclassifies SPNEGO Extended Negotiation Security Vulnerability as ‘Critical’

December 16, 2022 Microsoft has revised the severity of a security vulnerability it originally patched in September 2022, upgrading it to “Critical” after it emerged that it could be exploited to achieve remote code execution. Tracked as CVE-2022-37958 (CVSS score: 8.1), the flaw was previously described as an information disclosure vulnerability in SPNEGO Extended Negotiation (NEGOEX) Security Mechanism. SPNEGO, Article …

Microsoft Reclassifies SPNEGO Extended Negotiation Security Vulnerability as ‘Critical’ Read More »

Android Malware Campaign Leverages Money-Lending Apps to Blackmail Victims

December 16, 2022 A previously undocumented Android malware campaign has been observed leveraging money-lending apps to blackmail victims into paying up with personal information stolen from their devices. Mobile security company Zimperium dubbed the activity MoneyMonger, pointing out the use of the cross-platform Flutter framework to develop the apps. MoneyMonger “takes advantage of Flutter’s framework to Article posted …

Android Malware Campaign Leverages Money-Lending Apps to Blackmail Victims Read More »

Hackers Bombard Open Source Repositories with Over 144,000 Malicious Packages

December 16, 2022 NuGet, PyPi, and npm ecosystems are the target of a new campaign that has resulted in over 144,000 packages being published by unknown threat actors. “The packages were part of a new attack vector, with attackers spamming the open-source ecosystem with packages containing links to phishing campaigns,” researchers from Checkmarx and Illustria said in …

Hackers Bombard Open Source Repositories with Over 144,000 Malicious Packages Read More »

FBI Charges 6, Seizes 48 Domains Linked to DDoS-for-Hire Service Platforms

December 16, 2022 The U.S. Department of Justice (DoJ) on Wednesday announced the seizure of 48 domains that offered services to conduct distributed denial-of-service (DDoS) attacks on behalf of other threat actors, effectively lowering the barrier to entry for malicious activity. It also charged six suspects – Jeremiah Sam Evans Miller (23), Angel Manuel Colon …

FBI Charges 6, Seizes 48 Domains Linked to DDoS-for-Hire Service Platforms Read More »

Hacking Using SVG Files to Smuggle QBot Malware onto Windows Systems

December 16, 2022 Phishing campaigns involving the Qakbot malware are using Scalable Vector Graphics (SVG) images embedded in HTML email attachments. The new distribution method was spotted by Cisco Talos, which said it identified fraudulent email messages featuring HTML attachments with encoded SVG images that incorporate HTML script tags. HTML smuggling is a technique that relies on using legitimate features of Article …

Hacking Using SVG Files to Smuggle QBot Malware onto Windows Systems Read More »

Open Whatsapp chat
Whatsapp Us
Chat with us for faster replies.