The ubiquity of GitHub in information technology (IT) environments has made it a lucrative choice for threat actors to host and deliver malicious payloads and act as dead drop resolvers, command-and-control, and data exfiltration points.
“Using GitHub services for malicious infrastructure allows adversaries to blend in with legitimate network traffic, often bypassing traditional security
https://thehackernews.com/2024/01/threat-actors-increasingly-abusing.html?utm_source=dlvr.it&utm_medium=blogger
Friday, January 12, 2024
New PoC Exploit for Apache OfBiz Vulnerability Poses Risk to ERP Systems
Cybersecurity researchers have developed a proof-of-concept (PoC) code that exploits a recently disclosed critical flaw in the Apache OfBiz open-source Enterprise Resource Planning (ERP) system to execute a memory-resident payload.
The vulnerability in question is CVE-2023-51467 (CVSS score: 9.8), a bypass for another severe shortcoming in the same software (
https://thehackernews.com/2024/01/new-poc-exploit-for-apache-ofbiz.html?utm_source=dlvr.it&utm_medium=blogger
The vulnerability in question is CVE-2023-51467 (CVSS score: 9.8), a bypass for another severe shortcoming in the same software (
https://thehackernews.com/2024/01/new-poc-exploit-for-apache-ofbiz.html?utm_source=dlvr.it&utm_medium=blogger
New Python-based FBot Hacking Toolkit Aims at Cloud and SaaS Platforms
A new Python-based hacking tool called FBot has been uncovered targeting web servers, cloud services, content management systems (CMS), and SaaS platforms such as Amazon Web Services (AWS), Microsoft 365, PayPal, Sendgrid, and Twilio.
“Key features include credential harvesting for spamming attacks, AWS account hijacking tools, and functions to enable attacks against PayPal and various
https://thehackernews.com/2024/01/new-python-based-fbot-hacking-toolkit.html?utm_source=dlvr.it&utm_medium=blogger
“Key features include credential harvesting for spamming attacks, AWS account hijacking tools, and functions to enable attacks against PayPal and various
https://thehackernews.com/2024/01/new-python-based-fbot-hacking-toolkit.html?utm_source=dlvr.it&utm_medium=blogger
There is a Ransomware Armageddon Coming for Us All
Generative AI will enable anyone to launch sophisticated phishing attacks that only Next-generation MFA devices can stop
The least surprising headline from 2023 is that ransomware again set new records for a number of incidents and the damage inflicted. We saw new headlines every week, which included a who’s-who of big-name organizations. If MGM, Johnson Controls, Chlorox, Hanes Brands, Caesars
https://thehackernews.com/2024/01/there-is-ransomware-armageddon-coming.html?utm_source=dlvr.it&utm_medium=blogger
The least surprising headline from 2023 is that ransomware again set new records for a number of incidents and the damage inflicted. We saw new headlines every week, which included a who’s-who of big-name organizations. If MGM, Johnson Controls, Chlorox, Hanes Brands, Caesars
https://thehackernews.com/2024/01/there-is-ransomware-armageddon-coming.html?utm_source=dlvr.it&utm_medium=blogger
Atomic Stealer Gets an Upgrade - Targeting Mac Users with Encrypted Payload
Cybersecurity researchers have identified an updated version of a macOS information stealer called Atomic (or AMOS), indicating that the threat actors behind the malware are actively enhancing its capabilities.
"It looks like Atomic Stealer was updated around mid to late December 2023, where its developers introduced payload encryption in an effort to bypass detection rules,"
https://thehackernews.com/2024/01/atomic-stealer-gets-upgrade-targeting.html?utm_source=dlvr.it&utm_medium=blogger
"It looks like Atomic Stealer was updated around mid to late December 2023, where its developers introduced payload encryption in an effort to bypass detection rules,"
https://thehackernews.com/2024/01/atomic-stealer-gets-upgrade-targeting.html?utm_source=dlvr.it&utm_medium=blogger
Thursday, January 11, 2024
Free Decryptor Released for Black Basta and Babuk's Tortilla Ransomware Victims
A decryptor for the Tortilla variant of the Babuk ransomware has been released by Cisco Talos, allowing victims targeted by the malware to regain access to their files.
The cybersecurity firm said the threat intelligence it shared with Dutch law enforcement authorities made it possible to arrest the threat actor behind the operations.
The encryption key has also been shared with Avast,
https://thehackernews.com/2024/01/free-decryptor-released-for-black-basta.html?utm_source=dlvr.it&utm_medium=blogger
The cybersecurity firm said the threat intelligence it shared with Dutch law enforcement authorities made it possible to arrest the threat actor behind the operations.
The encryption key has also been shared with Avast,
https://thehackernews.com/2024/01/free-decryptor-released-for-black-basta.html?utm_source=dlvr.it&utm_medium=blogger
FTC Bans Outlogic (X-Mode) From Selling Sensitive Location Data
The U.S. Federal Trade Commission (FTC) on Tuesday prohibited data broker Outlogic, which was previously known as X-Mode Social, from sharing or selling any sensitive location data with third-parties.
The ban is part of a settlement over allegations that the company "sold precise location data that could be used to track people's visits to sensitive locations such as medical and
https://thehackernews.com/2024/01/ftc-bans-outlogic-x-mode-from-selling.html?utm_source=dlvr.it&utm_medium=blogger
The ban is part of a settlement over allegations that the company "sold precise location data that could be used to track people's visits to sensitive locations such as medical and
https://thehackernews.com/2024/01/ftc-bans-outlogic-x-mode-from-selling.html?utm_source=dlvr.it&utm_medium=blogger
Microsoft's January 2024 Windows Update Patches 48 New Vulnerabilities
Microsoft has addressed a total of 48 security flaws spanning its software as part of its Patch Tuesday updates for January 2024.
Of the 48 bugs, two are rated Critical and 46 are rated Important in severity. There is no evidence that any of the issues are publicly known or under active attack at the time of release, making it the second consecutive Patch Tuesday with no zero-days.
The
https://thehackernews.com/2024/01/microsofts-january-2024-windows-update.html?utm_source=dlvr.it&utm_medium=blogger
Of the 48 bugs, two are rated Critical and 46 are rated Important in severity. There is no evidence that any of the issues are publicly known or under active attack at the time of release, making it the second consecutive Patch Tuesday with no zero-days.
The
https://thehackernews.com/2024/01/microsofts-january-2024-windows-update.html?utm_source=dlvr.it&utm_medium=blogger
CISA Flags 6 Vulnerabilities - Apple, Apache, Adobe, D-Link, Joomla Under Attack
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added six security flaws to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation.
This includes CVE-2023-27524 (CVSS score: 8.9), a high-severity vulnerability impacting the Apache Superset open-source data visualization software that could enable remote code execution.
https://thehackernews.com/2024/01/cisa-flags-6-vulnerabilities-apple.html?utm_source=dlvr.it&utm_medium=blogger
This includes CVE-2023-27524 (CVSS score: 8.9), a high-severity vulnerability impacting the Apache Superset open-source data visualization software that could enable remote code execution.
https://thehackernews.com/2024/01/cisa-flags-6-vulnerabilities-apple.html?utm_source=dlvr.it&utm_medium=blogger
Alert: Water Curupira Hackers Actively Distributing PikaBot Loader Malware
A threat actor called Water Curupira has been observed actively distributing the PikaBot loader malware as part of spam campaigns in 2023.
“PikaBot’s operators ran phishing campaigns, targeting victims via its two components — a loader and a core module — which enabled unauthorized remote access and allowed the execution of arbitrary commands through an established connection with
https://thehackernews.com/2024/01/alert-water-curupira-hackers-actively.html?utm_source=dlvr.it&utm_medium=blogger
“PikaBot’s operators ran phishing campaigns, targeting victims via its two components — a loader and a core module — which enabled unauthorized remote access and allowed the execution of arbitrary commands through an established connection with
https://thehackernews.com/2024/01/alert-water-curupira-hackers-actively.html?utm_source=dlvr.it&utm_medium=blogger
Subscribe to:
Posts (Atom)









