PROJET AUTOBLOG


The Hacker News

Site original : The Hacker News

⇐ retour index

Chinese Hackers Target Taiwanese Financial Institutions with a new Stealthy Backdoor

lundi 7 février 2022 à 08:15
A Chinese advanced persistent threat (APT) group has been targeting Taiwanese financial institutions as part of a "persistent campaign" that lasted for at least 18 months. The intrusions, whose primary intent was espionage, resulted in the deployment of a backdoor called xPack, granting the adversary extensive control over compromised machines, Broadcom-owned Symantec said in a report published

CISA Orders Federal Agencies to Patch Actively Exploited Windows Vulnerability

lundi 7 février 2022 à 06:03
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) is urging federal agencies to secure their systems against an actively exploited security vulnerability in Windows that could be abused to gain elevated permissions on affected hosts. To that end, the agency has added CVE-2022-21882 (CVSS score: 7.0) to the Known Exploited Vulnerabilities Catalog, necessitating that Federal

New Argo CD Bug Could Let Hackers Steal Secret Info from Kubernetes Apps

dimanche 6 février 2022 à 06:48
Users of the Argo continuous deployment (CD) tool for Kubernetes are being urged to push through updates after a zero-day vulnerability was found that could allow an attacker to extract sensitive information such as passwords and API keys. The flaw, tagged as CVE-2022-24348 (CVSS score: 7.7), affects all versions and has been addressed in versions 2.3.0, 2.2.4, and 2.1.9. Cloud security firm

Microsoft Uncovers New Details of Russian Hacking Campaign Targeting Ukraine

samedi 5 février 2022 à 08:15
Microsoft on Friday shared more of the tactics, techniques, and procedures (TTPs) adopted by the Russia-based Gamaredon hacking group to facilitate a barrage of cyber espionage attacks aimed at several entities in Ukraine over the past six months. The attacks are said to have singled out government, military, non-government organizations (NGO), judiciary, law enforcement, and non-profit

Another Israeli Firm, QuaDream, Caught Weaponizing iPhone Bug for Spyware

vendredi 4 février 2022 à 12:52
A now-patched security vulnerability in Apple iOS that was previously found to be exploited by Israeli company NSO Group was also separately weaponized by a different surveillance vendor named QuaDream to hack into the company's devices. The development was reported by Reuters, citing unnamed sources, noting that "the two rival businesses gained the same ability last year to remotely break into