PROJET AUTOBLOG


The Hacker News

Site original : The Hacker News

⇐ retour index

Chinese "Override Panda" Hackers Resurface With New Espionage Attacks

lundi 2 mai 2022 à 15:39
A Chinese state-sponsored espionage group known as Override Panda has resurfaced in recent weeks with a new phishing attack with the goal of stealing sensitive information. "The Chinese APT used a spear-phishing email to deliver a beacon of a Red Team framework known as 'Viper,'" Cluster25 said in a report published last week. "The target of this attack is currently unknown but with high

Which Hole to Plug First? Solving Chronic Vulnerability Patching Overload

lundi 2 mai 2022 à 15:30
According to folklore, witches were able to sail in a sieve, a strainer with holes in the bottom. Unfortunately, witches don’t work in cybersecurity – where networks generally have so many vulnerabilities that they resemble sieves.  For most of us, keeping the sieve of our networks afloat requires nightmarishly hard work and frequent compromises on which holes to plug first. The reason? In 2010,

Russian Hackers Targeting Diplomatic Entities in Europe, Americas, and Asia

lundi 2 mai 2022 à 13:40
A Russian state-sponsored threat actor has been observed targeting diplomatic and government entities as part of a series of phishing campaigns commencing on January 17, 2022. Threat intelligence and incident response firm Mandiant attributed the attacks to a hacking group tracked as APT29 (aka Cozy Bear), with some set of the activities associated with the crew assigned the moniker Nobelium (

Google Releases First Developer Preview of Privacy Sandbox on Android 13

lundi 2 mai 2022 à 08:06
Google has officially released the first developer preview for the Privacy Sandbox on Android 13, offering an "early look" at the SDK Runtime and Topics API to boost users' privacy online. "The Privacy Sandbox on Android Developer Preview program will run over the course of 2022, with a beta release planned by the end of the year," the search giant said in an overview. A "multi-year effort," 

Here's a New Tool That Scans Open-Source Repositories for Malicious Packages

lundi 2 mai 2022 à 06:50
The Open Source Security Foundation (OpenSSF) has announced the initial prototype release of a new tool that's capable of carrying out dynamic analysis of all packages uploaded to popular open source repositories. Called the Package Analysis project, the initiative aims to secure open-source packages by detecting and alerting users to any malicious behavior with the goal of bolstering the