PROJET AUTOBLOG


The Hacker News

Site original : The Hacker News

⇐ retour index

UBEL is the New Oscorp — Android Credential Stealing Malware Active in the Wild

mercredi 28 juillet 2021 à 14:53
An Android malware that was observed abusing accessibility services in the device to hijack user credentials from European banking applications has morphed into an entirely new botnet as part of a renewed campaign that began in May 2021. Italy's CERT-AGID, in late January, disclosed details about Oscorp, a mobile malware developed to attack multiple financial targets with the goal of stealing

Chinese Hackers Implant PlugX Variant on Compromised MS Exchange Servers

mercredi 28 juillet 2021 à 12:58
A Chinese cyberespionage group known for targeting Southeast Asia leveraged flaws in the Microsoft Exchange Server that came to light earlier this March to deploy a previously undocumented variant of a remote access trojan (RAT) on compromised systems. Attributing the intrusions to a threat actor named PKPLUG (aka Mustang Panda and HoneyMyte), Palo Alto Networks' Unit 42 threat intelligence team

Hackers Posed as Aerobics Instructors for Years to Target Aerospace Employees

mercredi 28 juillet 2021 à 12:06
An Iranian cyberespionage group masqueraded as an aerobics instructor on Facebook in an attempt to infect the machine of an employee of an aerospace defense contractor with malware as part of years-long social engineering and targeted malware campaign. Enterprise security firm Proofpoint attributed the covert operation to a state-aligned threat actor it tracks as TA456, and by the wider

New Bug Could Let Attackers Hijack Zimbra Server by Sending Malicious Email

mardi 27 juillet 2021 à 17:46
Cybersecurity researchers have discovered multiple security vulnerabilities in Zimbra email collaboration software that could be potentially exploited to compromise email accounts by sending a malicious message and even achieve a full takeover of the mail server when hosted on a cloud infrastructure. The flaws — tracked as CVE-2021-35208 and CVE-2021-35208 — were discovered and reported in

Several Bugs Found in 3 Open-Source Software Used by Several Businesses

mardi 27 juillet 2021 à 15:01
Cybersecurity researchers on Tuesday disclosed nine security vulnerabilities affecting three open-source projects — EspoCRM, Pimcore, and Akaunting — that are widely used by several small to medium businesses and, if successfully exploited, could provide a pathway to more sophisticated attacks. All the security flaws in question, which impact EspoCRM v6.1.6, Pimcore Customer Data Framework