Category: Uncategorized
-
Top Python Developers Hacked in Sophisticated Supply Chain Attack Ionut Arghire
Multiple Python developers get infected after downloading malware-packed clone of the popular tool Colorama. The post Top Python Developers Hacked in Sophisticated Supply Chain Attack appeared first on SecurityWeek. Read More
-

Key Lesson from Microsoft’s Password Spray Hack: Secure Every Account [email protected] (The Hacker News)
In January 2024, Microsoft discovered they’d been the victim of a hack orchestrated by Russian-state hackers Midnight Blizzard (sometimes known as Nobelium). The concerning detail about this case is how easy it was to breach the software giant. It wasn’t a highly technical hack that exploited a zero-day vulnerability – the hackers used a simple password spray…
-
Mozilla Patches Firefox Zero-Days Exploited at Pwn2Own Ionut Arghire
Firefox browser updates address two zero-day vulnerabilities exploited at the Pwn2Own hacking contest. The post Mozilla Patches Firefox Zero-Days Exploited at Pwn2Own appeared first on SecurityWeek. Read More
-
White House Nominates First Assistant Secretary of Defense for Cyber Policy Eduard Kovacs
Michael Sulmeyer has been nominated by the White House as the first assistant secretary of defense for cyber policy at the Pentagon. The post White House Nominates First Assistant Secretary of Defense for Cyber Policy appeared first on SecurityWeek. Read More
-

New “GoFetch” Vulnerability in Apple M-Series Chips Leaks Secret Encryption Keys [email protected] (The Hacker News)
A new security shortcoming discovered in Apple M-series chips could be exploited to extract secret keys used during cryptographic operations. Dubbed GoFetch, the vulnerability relates to a microarchitectural side-channel attack that takes advantage of a feature known as data memory-dependent prefetcher (DMP) to target constant-time cryptographic implementations and capture sensitive dataRead More
-

Iran-Linked MuddyWater Deploys Atera for Surveillance in Phishing Attacks [email protected] (The Hacker News)
The Iran-affiliated threat actor tracked as MuddyWater (aka Mango Sandstorm or TA450) has been linked to a new phishing campaign in March 2024 that aims to deliver a legitimate Remote Monitoring and Management (RMM) solution called Atera. The activity, which took place from March 7 through the week of March 11, targeted Israeli entities spanning global manufacturing,…
-

N. Korea-linked Kimsuky Shifts to Compiled HTML Help Files in Ongoing Cyberattacks [email protected] (The Hacker News)
The North Korea-linked threat actor known as Kimsuky (aka Black Banshee, Emerald Sleet, or Springtail) has been observed shifting its tactics, leveraging Compiled HTML Help (CHM) files as vectors to deliver malware for harvesting sensitive data. Kimsuky, active since at least 2012, is known to target entities located in South Korea as well as North America, Asia,…
-

German Police Seize ‘Nemesis Market’ in Major International Darknet Raid [email protected] (The Hacker News)
German authorities have announced the takedown of an illicit underground marketplace called Nemesis Market that peddled narcotics, stolen data, and various cybercrime services. The Federal Criminal Police Office (aka Bundeskriminalamt or BKA) said it seized the digital infrastructure associated with the darknet service located in Germany and Lithuania and confiscated €94,000 ($102,107)Read More
-

Russian Hackers Use ‘WINELOADER’ Malware to Target German Political Parties [email protected] (The Hacker News)
The WINELOADER backdoor used in recent cyber attacks targeting diplomatic entities with wine-tasting phishing lures has been attributed as the handiwork of a hacking group with links to Russia’s Foreign Intelligence Service (SVR), which was responsible for breaching SolarWinds and Microsoft. The findings come from Mandiant, which said Midnight Blizzard (aka APT29, BlueBravo, orRead More
-
Finite State Raises $20 Million to Grow Software Supply Chain Security Business SecurityWeek News
Software risk management firm Finite State has raised a $20 million growth round led by Energy Impact Partners (EIP). The post Finite State Raises $20 Million to Grow Software Supply Chain Security Business appeared first on SecurityWeek. Read More
