Category: Uncategorized
-

Inside the Code of a New XWorm Variant [email protected] (The Hacker News)
XWorm is a relatively new representative of the remote access trojan cohort that has already earned its spot among the most persistent threats across the globe. Since 2022, when it was first observed by researchers, it has undergone a number of major updates that have significantly enhanced its functionality and solidified its staying power. The…
-

Earth Lusca’s New SprySOCKS Linux Backdoor Targets Government Entities [email protected] (The Hacker News)
The China-linked threat actor known as Earth Lusca has been observed targeting government entities using a never-before-seen Linux backdoor called SprySOCKS. Earth Lusca was first documented by Trend Micro in January 2022, detailing the adversary’s attacks against public and private sector entities across Asia, Australia, Europe, North America. Active since 2021, the group has relied onRead More
-
Hacker Conversations: Casey Ellis, Hacker and Ringmaster at Bugcrowd Kevin Townsend
SecurityWeek interviews Casey Ellis, founder, chairman and CTO at Bugcrowd, best known for operating bug bounty programs for organizations. The post Hacker Conversations: Casey Ellis, Hacker and Ringmaster at Bugcrowd appeared first on SecurityWeek. Read More
-
Chinese Hackers Target North American, APAC Firms in Web Skimmer Campaign Ionut Arghire
A Chinese threat actor has been observed targeting organizations in multiple industries to deploy web skimmers on online payment pages. The post Chinese Hackers Target North American, APAC Firms in Web Skimmer Campaign appeared first on SecurityWeek. Read More
-

Live Webinar: Overcoming Generative AI Data Leakage Risks [email protected] (The Hacker News)
As the adoption of generative AI tools, like ChatGPT, continues to surge, so does the risk of data exposure. According to Gartner’s “Emerging Tech: Top 4 Security Risks of GenAI” report, privacy and data security is one of the four major emerging risks within generative AI. A new webinar featuring a multi-time Fortune 100 CISO and the…
-
CISA Says Owl Labs Vulnerabilities Requiring Close Physical Range Exploited in Attacks Eduard Kovacs
CISA says Owl Labs video conferencing device vulnerabilities that require the attacker to be in close range exploited in attacks The post CISA Says Owl Labs Vulnerabilities Requiring Close Physical Range Exploited in Attacks appeared first on SecurityWeek. Read More
-

Over 12,000 Juniper Firewalls Found Vulnerable to Recently Disclosed RCE Vulnerability [email protected] (The Hacker News)
New research has found that close to 12,000 internet-exposed Juniper firewall devices are vulnerable to a recently disclosed remote code execution flaw. VulnCheck, which discovered a new exploit for CVE-2023-36845, said it could be exploited by an “unauthenticated and remote attacker to execute arbitrary code on Juniper firewalls without creating a file on the system.” CVE-2023-36845 refers to aRead…
-
Cybersecurity M&A Roundup for First Half of September 2023 Eduard Kovacs
A dozen cybersecurity-related M&A deals were announced in the first half of September 2023. The post Cybersecurity M&A Roundup for First Half of September 2023 appeared first on SecurityWeek. Read More
-
What is extortionware? How does it differ from ransomware?
Post ContentRead More
-

Transparent Tribe Uses Fake YouTube Android Apps to Spread CapraRAT Malware [email protected] (The Hacker News)
The suspected Pakistan-linked threat actor known as Transparent Tribe is using malicious Android apps mimicking YouTube to distribute the CapraRAT mobile remote access trojan (RAT), demonstrating the continued evolution of the activity. “CapraRAT is a highly invasive tool that gives the attacker control over much of the data on the Android devices that it infects,” SentinelOne securityRead…
