PROJET AUTOBLOG


The Hacker News

Site original : The Hacker News

⇐ retour index

AvosLocker Ransomware Variant Using New Trick to Disable Antivirus Protection

mardi 3 mai 2022 à 07:50
Cybersecurity researchers have disclosed a new variant of the AvosLocker ransomware that disables antivirus solutions to evade detection after breaching target networks by taking advantage of unpatched security flaws.  "This is the first sample we observed from the U.S. with the capability to disable a defense solution using a legitimate Avast Anti-Rootkit Driver file (asWarPot.sys)," Trend

Chinese Hackers Caught Exploiting Popular Antivirus Products to Target Telecom Sector

mardi 3 mai 2022 à 07:32
A Chinese-aligned cyberespionage group has been observed striking the telecommunication sector in Central Asia with versions of malware such as ShadowPad and PlugX. Cybersecurity firm SentinelOne tied the intrusions to an actor it tracks under the name "Moshen Dragon," with tactical overlaps between the collective and another threat group referred to as Nomad Panda (aka RedFoxtrot). "PlugX and

Unpatched DNS Related Vulnerability Affects a Wide Range of IoT Devices

mardi 3 mai 2022 à 06:58
Cybersecurity researchers have disclosed an unpatched security vulnerability that could pose a serious risk to IoT products. The issue, which was originally reported in September 2021, affects the Domain Name System (DNS) implementation of two popular C libraries called uClibc and uClibc-ng that are used for developing embedded Linux systems. <!--adsense--> uClibc is known to be used by major

New Hacker Group Pursuing Corporate Employees Focused on Mergers and Acquisitions

mardi 3 mai 2022 à 06:17
A newly discovered suspected espionage threat actor has been targeting employees focusing on mergers and acquisitions as well as large corporate transactions to facilitate bulk email collection from victim environments. Mandiant is tracking the activity cluster under the uncategorized moniker UNC3524, citing a lack of evidence linking it to an existing group. However, some of the intrusions are

GitHub Says Recent Attack Involving Stolen OAuth Tokens Was "Highly Targeted"

mardi 3 mai 2022 à 05:49
Cloud-based code hosting platform GitHub described the recent attack campaign involving the abuse of OAuth access tokens issued to Heroku and Travis-CI as "highly targeted" in nature. "This pattern of behavior suggests the attacker was only listing organizations in order to identify accounts to selectively target for listing and downloading private repositories," GitHub's Mike Hanley said in an