Tag: malicious
-
Millions of Pixel devices can be hacked due to a pre-installed vulnerable app
Many Google Pixel devices shipped since September 2017 have included a vulnerable app that could be exploited for malicious purposes. Many Google Pixe… First seen on securityaffairs.com Jump to article: securityaffairs.com/167130/security/pixel-devices-pre-installed-vulnerable-app.html
-
Roundcube Webmail Flaws Allow Hackers to Steal Emails and Passwords
Cybersecurity researchers have disclosed details of security flaws in the Roundcube webmail software that could be exploited to execute malicious Java… First seen on thehackernews.com Jump to article: thehackernews.com/2024/08/roundcube-webmail-flaws-allow-hackers.html
-
North Korean Hackers Moonstone Sleet Push Malicious JS Packages to npm Registry
The North Korea-linked threat actor known as Moonstone Sleet has continued to push malicious npm packages to the JavaScript package registry with the … First seen on thehackernews.com Jump to article: thehackernews.com/2024/08/north-korean-hackers-moonstone-sleet.html
-
0.0.0.0 Day Browser Flaw Enables Malicious Requests To Local Networks
First seen on packetstormsecurity.com Jump to article: packetstormsecurity.com/news/view/36198/0.0.0.0-Day-Browser-Flaw-Enables-Malicious-Requests-To-Local-Networks.html
-
Malicious browser extensions leveraged in widespread malware compromise
First seen on scmagazine.com Jump to article: www.scmagazine.com/brief/malicious-browser-extensions-leveraged-in-widespread-malware-compromise
-
AWS unveils Mithra to identify and mitigate malicious domains across its massive system
When a company is the size of Amazon, a lot of bad actors will come after it and its customers, which makes defending the network a monster job. Over … First seen on techcrunch.com Jump to article: techcrunch.com/2024/08/05/aws-launches-mithra-to-identify-and-mitigate-malicious-domains/
-
China-Linked Hackers Compromise ISP to Deploy Malicious Software Updates
The China-linked threat actor known as Evasive Panda compromised an unnamed internet service provider (ISP) to push malicious software updates to targ… First seen on thehackernews.com Jump to article: thehackernews.com/2024/08/china-linked-hackers-compromise-isp-to.html
-
Chrome, Edge users beset by malicious extensions that can’t be easily removed
A widespread campaign featuring a malicious installer that saddles users with difficult-to-remove malicious Chrome and Edge browser extensions has bee… First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2024/08/12/chrome-edge-malicious-browser-extensions/
-
Hackers posing as Ukraine’s Security Service infect 100 govt PCs
Attackers impersonating the Security Service of Ukraine (SSU) have used malicious spam emails to target and compromise systems belonging to the countr… First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/hackers-posing-as-ukraines-security-service-infect-100-govt-pcs/
-
Malware-asService and Ransomware-asService lower barriers for cybercriminals
The sophistication of cyber threats has escalated dramatically, with malicious actors’ deploying advanced tactics, techniques, and procedures (TTPs) t… First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2024/08/09/maas-threat-landscape/
-
Bumble and Hinge allowed stalkers to pinpoint users’ locations down to 2 meters, researchers say
Badoo, Bumble, Grindr, happn, Hinge and Hily all had the same vulnerability that could have helped a malicious user to identify the near-exact locatio… First seen on techcrunch.com Jump to article: techcrunch.com/2024/07/31/bumble-and-hinge-allowed-stalkers-to-pinpoint-users-locations-down-to-2-meters-researchers-say/
-
QuickShell: Sharing Is Caring about an RCE Attack Chain on Quick Share
See how a SafeBreach Labs researcher bypassed the anti-tampering mechanism of a leading EDR to execute malicious code within one of the EDR’s own proc… First seen on securityboulevard.com Jump to article: securityboulevard.com/2024/08/quickshell-sharing-is-caring-about-an-rce-attack-chain-on-quick-share/
-
Hackers Distributing Malicious Python Packages via Popular Developer Q&A Platform
In yet another sign that threat actors are always looking out for new ways to trick users into downloading malware, it has come to light that the ques… First seen on thehackernews.com Jump to article: thehackernews.com/2024/08/hackers-distributing-malicious-python.html
-
Over 1 Million Domains at Risk of ‘Sitting Ducks’ Domain Hijacking Technique
Over a million domains are susceptible to takeover by malicious actors by means of what has been called a Sitting Ducks attack.The powerful attack vec… First seen on thehackernews.com Jump to article: thehackernews.com/2024/08/over-1-million-domains-at-risk-of.html
-
CISA Warns of Cisco Smart Install Feature Actively Exploited by Hackers
The Cybersecurity and Infrastructure Security Agency (CISA) has raised alarms over malicious cyber actors’ active exploitation of the Cisco Smart Inst… First seen on gbhackers.com Jump to article: gbhackers.com/cisco-smart-install-feature/
-
Federal watchdog urges EPA to develop comprehensive cyber strategy to protect water systems
The report comes amid a rise in malicious cyberthreats from state-linked and criminal hackers targeting U.S. drinking water and water treatment facili… First seen on cybersecuritydive.com Jump to article: www.cybersecuritydive.com/news/federal-watchdog-epa-cyber-strategy/723427/
-
‘0.0.0.0 Day’ browser flaw enables malicious requests to local networks
First seen on scmagazine.com Jump to article: www.scmagazine.com/news/0-0-0-0-day-browser-flaw-enables-malicious-requests-to-local-networks
-
Government Hit by Multi-Malware Cyberattack via Cloudflare Service
A sophisticated cyberattack targeting the government sector has been uncovered, utilizing a quartet of malicious software XWorm, AsyncRAT, VenomRAT, a… First seen on securityonline.info Jump to article: securityonline.info/government-hit-by-multi-malware-cyberattack-via-cloudflare-service/
-
18-year-old security flaw in Firefox and Chrome exploited in attacks
A vulnerability disclosed 18 years ago, dubbed 0.0.0.0 Day, allows malicious websites to bypass security in Google Chrome, Mozilla Firefox, and Apple … First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/18-year-old-security-flaw-in-firefox-and-chrome-exploited-in-attacks/
-
New Flaws in Sonos Smart Speakers Allow Hackers to Eavesdrop on Users
Cybersecurity researchers have uncovered weaknesses in Sonos smart speakers that could be exploited by malicious actors to clandestinely eavesdrop on … First seen on thehackernews.com Jump to article: thehackernews.com/2024/08/new-flaws-in-sonos-smart-speakers-allow.html
-
Malicious npm packages leveraged by North Korean hackers for Windows compromise
First seen on scmagazine.com Jump to article: www.scmagazine.com/brief/malicious-npm-packages-leveraged-by-north-korean-hackers-for-windows-compromise
-
Cybercriminals Deploy 100K+ Malware Android Apps to Steal OTP Codes
A new malicious campaign has been observed making use of malicious Android apps to steal users’ SMS messages since at least February 2022 as part of a… First seen on thehackernews.com Jump to article: thehackernews.com/2024/07/cybercriminals-deploy-100k-malware.html
-
Attacks on Bytecode Interpreters Conceal Malicious Injection Activity
First seen on darkreading.com Jump to article: www.darkreading.com/vulnerabilities-threats/attacks-on-bytecode-interpreters-conceal-malicious-injection-activity
-
Exim vulnerability affecting 1.5M servers lets attackers attach malicious files
First seen on arstechnica.com Jump to article: arstechnica.com/
-
Attackers Hijack Facebook Pages, Promote Malicious AI Photo Editor
First seen on darkreading.com Jump to article: www.darkreading.com/cyberattacks-data-breaches/attackers-hijack-facebook-pages-promote-malicious-ai-photo-editor
-
Record Breaking DDoS Attack 419 TB of Malicious Traffic Within 24-Hours
A record-breaking Distributed Denial of Service (DDoS) attack unleashed 419 terabytes of malicious traffic over 24 hours. This unprecedented event, wh… First seen on gbhackers.com Jump to article: gbhackers.com/breaking-ddos-attack-419/
-
AWS Launches Mithra To Detect Malicious Domains Across Systems
Amazon’s e-commerce platforms and cloud services form a digital ecosystem requiring a strong cybersecurity framework. Amazon, which has a vast online … First seen on gbhackers.com Jump to article: gbhackers.com/aws-mithra-malicious-domains/

