Category: Uncategorized
-

Analysis and Config Extraction of Lu0Bot, a Node.js Malware with Considerable Capabilities [email protected] (The Hacker News)
Nowadays, more malware developers are using unconventional programming languages to bypass advanced detection systems. The Node.js malware Lu0Bot is a testament to this trend. By targeting a platform-agnostic runtime environment common in modern web apps and employing multi-layer obfuscation, Lu0Bot is a serious threat to organizations and individuals. Although currently, the malware has lowRead More
-

Guyana Governmental Entity Hit by DinodasRAT in Cyber Espionage Attack [email protected] (The Hacker News)
A governmental entity in Guyana has been targeted as part of a cyber espionage campaign dubbed Operation Jacana. The activity, which was detected by ESET in February 2023, entailed a spear-phishing attack that led to the deployment of a hitherto undocumented implant written in C++ called DinodasRAT. The Slovak cybersecurity firm said it could link the intrusion…
-
Hundreds Download Malicious NPM Package Capable of Delivering Rootkit Ionut Arghire
Threat actor uses typosquatting to trick hundreds of users into downloading a malicious NPM package that delivers the r77 rootkit. The post Hundreds Download Malicious NPM Package Capable of Delivering Rootkit appeared first on SecurityWeek. Read More
-
Sony Confirms Data Stolen in Two Recent Hacker Attacks Eduard Kovacs
Sony shares information on the impact of two recent unrelated hacker attacks carried out by known ransomware groups. The post Sony Confirms Data Stolen in Two Recent Hacker Attacks appeared first on SecurityWeek. Read More
-

GoldDigger Android Trojan Targets Banking Apps in Asia Pacific Countries [email protected] (The Hacker News)
A new Android banking trojan named GoldDigger has been found targeting several financial applications with an aim to siphon victims’ funds and backdoor infected devices. “The malware targets more than 50 Vietnamese banking, e-wallet and crypto wallet applications,” Group-IB said. “There are indications that this threat might be poised to extend its reach across the wider…
-

CISA Warns of Active Exploitation of JetBrains and Windows Vulnerabilities [email protected] (The Hacker News)
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added two security flaws to its Known Exploited Vulnerabilities (KEV) catalog due to active exploitation, while removing five bugs from the list due to lack of adequate evidence. The vulnerabilities newly added are below – CVE-2023-42793 (CVSS score: 9.8) – JetBrains TeamCity Authentication Bypass VulnerabilityRead More
-

Apple Rolls Out Security Patches for Actively Exploited iOS Zero-Day Flaw [email protected] (The Hacker News)
Apple on Wednesday rolled out security patches to address a new zero-day flaw in iOS and iPadOS that it said has come under active exploitation in the wild. Tracked as CVE-2023-42824, the kernel vulnerability could be abused by a local attacker to elevate their privileges. The iPhone maker said it addressed the problem with improved checks.…
-

Atlassian Confluence Hit by Newly Actively Exploited Zero-Day – Patch Now [email protected] (The Hacker News)
Atlassian has released fixes to contain an actively exploited critical zero-day flaw impacting publicly accessible Confluence Data Center and Server instances. The vulnerability, tracked as CVE-2023-22515, is remotely exploitable and allows external attackers to create unauthorized Confluence administrator accounts and access Confluence servers. It does not impact Confluence versions prior toRead More
-
CVE-2023-40044: Progress Software WS_FTP Server Insecure Deserialization Vulnerability
What is Progress Software WS_FTP? WS_FTP is a secure file transfer client and server software package from Ipswitch, which is now a part of Progress Software. What is the Attack? CVE-2023-40044 is a .NET deserialization vulnerability that affects WS_FTP Server versions prior to 8.7.4 and 8.8.2 with the Ad Hoc Transfer module installed. Successful exploitation…
-
Apple Warns of Newly Exploited iOS 17 Kernel Zero-Day Ryan Naraine
Apple’s cat-and-mouse struggles with zero-day exploits on its flagship iOS platform is showing no signs of slowing down. The post Apple Warns of Newly Exploited iOS 17 Kernel Zero-Day appeared first on SecurityWeek. Read More
