PROJET AUTOBLOG


The Hacker News

Site original : The Hacker News

⇐ retour index

Iranian Hackers Exploiting VMware RCE Bug to Deploy 'Code Impact' Backdoor

mardi 26 avril 2022 à 08:18
An Iranian-linked threat actor known as Rocket Kitten has been observed actively exploiting a recently patched VMware vulnerability to gain initial access and deploy the Core Impact penetration testing tool on vulnerable systems. Tracked as CVE-2022-22954 (CVSS score: 9.8), the critical issue concerns a case of remote code execution (RCE) vulnerability affecting VMware Workspace ONE Access and

Researchers Report Critical RCE Vulnerability in Google's VirusTotal Platform

lundi 25 avril 2022 à 22:00
Security researchers have disclosed a security vulnerability in the VirusTotal platform that could have been potentially weaponized to achieve remote code execution (RCE). The flaw, now patched, made it possible to "execute commands remotely within VirusTotal platform and gain access to its various scans capabilities," Cysource researchers Shai Alfasi and Marlon Fabiano da Silva said in a report

Critical Bug in Everscale Wallet Could've Let Attackers Steal Cryptocurrencies

lundi 25 avril 2022 à 12:51
A security vulnerability has been disclosed in the web version of the Ever Surf wallet that, if successfully weaponized, could allow an attacker to gain full control over a victim's wallet. "By exploiting the vulnerability, it's possible to decrypt the private keys and seed phrases that are stored in the browser's local storage," Israeli cybersecurity company Check Point said in a report shared

New BotenaGo Malware Variant Targeting Lilin Security Camera DVR Devices

lundi 25 avril 2022 à 11:41
A new variant of an IoT botnet called BotenaGo has emerged in the wild, specifically singling out Lilin security camera DVR devices to infect them with Mirai malware. Dubbed "Lilin Scanner" by Nozomi Networks, the latest version is designed to exploit a two-year-old critical command injection vulnerability in the DVR firmware that was patched by the Taiwanese company in February 2020. <!-

FBI Warns of BlackCat Ransomware That Breached Over 60 Organisations Worldwide

lundi 25 avril 2022 à 06:51
The U.S. Federal Bureau of Investigation (FBI) is sounding the alarm on the BlackCat ransomware-as-a-service (RaaS), which it said victimized at least 60 entities worldwide between as of March 2022 since its emergence last November. Also called ALPHV and Noberus, the ransomware is notable for being the first-ever malware written in the Rust programming language that's known to be memory safe and