Category: Uncategorized
-

Lazarus Hackers Exploited Windows Kernel Flaw as Zero-Day in Recent Attacks [email protected] (The Hacker News)
The notorious Lazarus Group actors exploited a recently patched privilege escalation flaw in the Windows Kernel as a zero-day to obtain kernel-level access and disable security software on compromised hosts. The vulnerability in question is CVE-2024-21338 (CVSS score: 7.8), which can permit an attacker to gain SYSTEM privileges. It was resolved by Microsoft earlier this month as…
-
Windows Zero-Day Exploited by North Korean Hackers in Rootkit Attack Eduard Kovacs
North Korean group Lazarus exploited AppLocker driver zero-day CVE-2024-21338 for privilege escalation in attacks involving FudModule rootkit. The post Windows Zero-Day Exploited by North Korean Hackers in Rootkit Attack appeared first on SecurityWeek. Read More
-

New Backdoor Targeting European Officials Linked to Indian Diplomatic Events [email protected] (The Hacker News)
A previously undocumented threat actor dubbed SPIKEDWINE has been observed targeting officials in European countries with Indian diplomatic missions using a new backdoor called WINELOADER. The adversary, according to a report from Zscaler ThreatLabz, used a PDF file in emails that purported to come from the Ambassador of India, inviting diplomatic staff to a wine-tastingRead More
-

Lazarus Exploits Typos to Sneak PyPI Malware into Dev Systems [email protected] (The Hacker News)
The notorious North Korean state-backed hacking group Lazarus uploaded four packages to the Python Package Index (PyPI) repository with the goal of infecting developer systems with malware. The packages, now taken down, are pycryptoenv, pycryptoconf, quasarlib, and swapmempool. They have been collectively downloaded 3,269 times, with pycryptoconf accounting for the mostRead More
-

Chinese Hackers Exploiting Ivanti VPN Flaws to Deploy New Malware [email protected] (The Hacker News)
At least two different suspected China-linked cyber espionage clusters, tracked as UNC5325 and UNC3886, have been attributed to the exploitation of security flaws in Ivanti Connect Secure VPN appliances. UNC5325 abused CVE-2024-21893 to deliver a wide range of new malware called LITTLELAMB.WOOLTEA, PITSTOP, PITDOG, PITJET, and PITHOOK, as well as maintain persistentRead More
-

President Biden Blocks Mass Transfer of Personal Data to High-Risk Nations [email protected] (The Hacker News)
U.S. President Joe Biden has issued an Executive Order that prohibits the mass transfer of citizens’ personal data to countries of concern. The Executive Order also “provides safeguards around other activities that can give those countries access to Americans’ sensitive data,” the White House said in a statement. This includes sensitive information such as genomic data, biometric…
-
ConnectWise ScreenConnect Attack
Threat actors including ransomware gangs are seen exploiting newly discovered critical flaws in remote monitoring and management software called ScreenConnect.Read More
-
White House to Issue Executive Order on Personal Information Protection Ionut Arghire
A coming White House Executive Order seeks to protect personal information by preventing the mass transfer of Americans’ sensitive data to countries of concern. The post White House to Issue Executive Order on Personal Information Protection appeared first on SecurityWeek. Read More
-
Cyber Insights 2024: APIs – A Clear, Present, and Future Danger Kevin Townsend
The API attack surface is expanding and API vulnerabilities are growing. AI will help attackers find and exploit API vulnerabilities at scale. The post Cyber Insights 2024: APIs – A Clear, Present, and Future Danger appeared first on SecurityWeek. Read More
-

Iran-Linked UNC1549 Hackers Target Middle East Aerospace & Defense Sectors [email protected] (The Hacker News)
An Iran-nexus threat actor known as UNC1549 has been attributed with medium confidence to a new set of attacks targeting aerospace, aviation, and defense industries in the Middle East, including Israel and the U.A.E. Other targets of the cyber espionage activity likely include Turkey, India, and Albania, Google-owned Mandiant said in a new analysis. UNC1549 is said…
