PROJET AUTOBLOG


The Hacker News

Site original : The Hacker News

⇐ retour index

Extortion Gang Breaches Cybersecurity Firm Qualys Using Accellion Exploit

jeudi 4 mars 2021 à 10:49
Enterprise cloud security firm Qualys has become the latest victim to join a long list of entities to have suffered a data breach after zero-day vulnerabilities in its Accellion File Transfer Appliance (FTA) server were exploited to steal sensitive business documents. As proof of access to the data, the cybercriminals behind the recent hacks targeting Accellion FTA servers have shared

CISA Issues Emergency Directive on In-the-Wild Microsoft Exchange Flaws

jeudi 4 mars 2021 à 09:26
Following Microsoft's release of out-of-band patches to address multiple zero-day flaws in on-premises versions of Microsoft Exchange Server, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued an emergency directive warning of "active exploitation" of the vulnerabilities. <!--adsense--> The alert comes on the heels of Microsoft's disclosure that China-based hackers were

Hackers Now Hiding ObliqueRAT Payload in Images to Evade Detection

mercredi 3 mars 2021 à 13:56
Cybercriminals are now deploying remote access Trojans (RATs) under the guise of seemingly innocuous images hosted on infected websites, once again highlighting how threat actors quickly change tactics when their attack methods are discovered and exposed publicly. New research released by Cisco Talos reveals a new malware campaign targeting organizations in South Asia that utilize malicious

Replacing EDR/NGAV with Autonomous XDR Makes a Big Difference for Small Security Teams

mercredi 3 mars 2021 à 11:34
The attack surface is virtually expanding before our eyes. Protecting assets across multiple locations, with multiple solutions from different vendors, has become a daily concern for CISOs globally.  In a new e-book recently published (download here), CISOs with small security teams talk about the drivers for replacing their EDR/NGAV solutions with an Autonomous XDR solution and why they believe

A $50,000 Bug Could've Allowed Hackers Access Any Microsoft Account

mercredi 3 mars 2021 à 11:12
Microsoft has awarded an independent security researcher $50,000 as part of its bug bounty program for reporting a flaw that could have allowed a malicious actor to hijack users' accounts without their knowledge. Reported by Laxman Muthiyah, the vulnerability aims to brute-force the seven-digit security code that's sent to a user's email address or mobile number to corroborate his (or her)