Category: Uncategorized
-

Warning: 3 Critical Vulnerabilities Expose ownCloud Users to Data Breaches [email protected] (The Hacker News)
The maintainers of the open-source file-sharing software ownCloud have warned of three critical security flaws that could be exploited to disclose sensitive information and modify files. A brief description of the vulnerabilities is as follows – Disclosure of sensitive credentials and configuration in containerized deployments impacting graphapi versions from 0.2.0 to 0.3.0. (CVSS score: 10.0)Read…
-

Cybercriminals Using Telekopye Telegram Bot to Craft Phishing Scams on a Grand Scale [email protected] (The Hacker News)
More details have emerged about a malicious Telegram bot called Telekopye that’s used by threat actors to pull off large-scale phishing scams. “Telekopye can craft phishing websites, emails, SMS messages, and more,” ESET security researcher Radek Jizba said in a new analysis. The threat actors behind the operation – codenamed Neanderthals – are known to run the criminal enterprise as aRead…
-
North Korean Software Supply Chain Attack Hits North America, Asia Eduard Kovacs
North Korean hackers breached a Taiwanese company and used its systems to deliver malware to the US, Canada, Japan and Taiwan in a supply chain attack. The post North Korean Software Supply Chain Attack Hits North America, Asia appeared first on SecurityWeek. Read More
-
In Other News: National Laboratory Breach, Airplane GPS Attacks, Russia Accuses Allies of Hacking SecurityWeek News
Noteworthy stories that might have slipped under the radar: Idaho National Laboratory breach, GPS attacks target airplanes, Russian accuses China and North Korea of hacking. The post In Other News: National Laboratory Breach, Airplane GPS Attacks, Russia Accuses Allies of Hacking appeared first on SecurityWeek. Read More
-

Tell Me Your Secrets Without Telling Me Your Secrets [email protected] (The Hacker News)
The title of this article probably sounds like the caption to a meme. Instead, this is an actual problem GitGuardian’s engineers had to solve in implementing the mechanisms for their new HasMySecretLeaked service. They wanted to help developers find out if their secrets (passwords, API keys, private keys, cryptographic certificates, etc.) had found their way into…
-

Hamas-Linked Cyberattacks Using Rust-Powered SysJoker Backdoor Against Israel [email protected] (The Hacker News)
Cybersecurity researchers have shed light on a Rust version of a cross-platform backdoor called SysJoker, which is assessed to have been used by a Hamas-affiliated threat actor to target Israel amid the ongoing war in the region. “Among the most prominent changes is the shift to Rust language, which indicates the malware code was entirely rewritten,…
-

Kubernetes Secrets of Fortune 500 Companies Exposed in Public Repositories [email protected] (The Hacker News)
Cybersecurity researchers are warning of publicly exposed Kubernetes configuration secrets that could put organizations at risk of supply chain attacks. “These encoded Kubernetes configuration secrets were uploaded to public repositories,” Aqua security researchers Yakir Kadkoda and Assaf Morag said in a new research published earlier this week. Some of those impacted include two top blockchainRead More
-

Konni Group Using Russian-Language Malicious Word Docs in Latest Attacks [email protected] (The Hacker News)
A new phishing attack has been observed leveraging a Russian-language Microsoft Word document to deliver malware capable of harvesting sensitive information from compromised Windows hosts. The activity has been attributed to a threat actor called Konni, which is assessed to share overlaps with a North Korean cluster tracked as Kimsuky (aka APT43). “This campaign relies…
-

Alert: New WailingCrab Malware Loader Spreading via Shipping-Themed Emails [email protected] (The Hacker News)
Delivery- and shipping-themed email messages are being used to deliver a sophisticated malware loader known as WailingCrab. “The malware itself is split into multiple components, including a loader, injector, downloader and backdoor, and successful requests to C2-controlled servers are often necessary to retrieve the next stage,” IBM X-Force researchers Charlotte Hammond, Ole Villadsen, and KatRead More
-

6 Steps to Accelerate Cybersecurity Incident Response [email protected] (The Hacker News)
Modern security tools continue to improve in their ability to defend organizations’ networks and endpoints against cybercriminals. But the bad actors still occasionally find a way in. Security teams must be able to stop threats and restore normal operations as quickly as possible. That’s why it’s essential that these teams not only have the right…
