PROJET AUTOBLOG


The Hacker News

Site original : The Hacker News

⇐ retour index

Dridex Malware Deploying Entropy Ransomware on Hacked Computers

mercredi 23 février 2022 à 14:00
Similarities have been unearthed between the Dridex general-purpose malware and a little-known ransomware strain called Entropy, suggesting that the operators are continuing to rebrand their extortion operations under a different name. "The similarities are in the software packer used to conceal the ransomware code, in the malware subroutines designed to find and obfuscate commands (API calls),

Chinese Experts Uncover Details of Equation Group's Bvp47 Covert Hacking Tool

mercredi 23 février 2022 à 09:39
Researchers from China's Pangu Lab have disclosed details of a "top-tier" backdoor put to use by the Equation Group, an advanced persistent threat (APT) with alleged ties to the cyber-warfare intelligence-gathering unit of the U.S. National Security Agency (NSA). Dubbed "Bvp47" owing to numerous references to the string "Bvp" and the numerical value "0x47" used in the encryption algorithm, the

9-Year-Old Unpatched Email Hacking Bug Uncovered in Horde Webmail Software

mercredi 23 février 2022 à 08:06
Users of Horde Webmail are being urged to disable a feature to contain a nine-year-old unpatched security vulnerability in the software that could be abused to gain complete access to email accounts simply by previewing an attachment. "This gives the attacker access to all sensitive and perhaps secret information a victim has stored in their email account and could allow them to gain further

25 Malicious JavaScript Libraries Distributed via Official NPM Package Repository

mercredi 23 février 2022 à 07:30
Another batch of 25 malicious JavaScript libraries have made their way to the official NPM package registry with the goal of stealing Discord tokens and environment variables from compromised systems, more than two months after 17 similar packages were taken down. The libraries in question leveraged typosquatting techniques and masqueraded as other legitimate packages such as colors.js,

Hackers Stole $1.7 Million Worth of NFTs from Users of OpenSea Marketplace

mardi 22 février 2022 à 15:41
Malicious actors took advantage of a smart contract upgrade process in the OpenSea NFT marketplace to carry out a phishing attack against 17 of its users that resulted in the theft of virtual assets worth about $1.7 million. NFTs, short for non-fungible tokens, are digital tokens that act like certificates of authenticity for, and in some cases represent ownership of, assets that range from