PROJET AUTOBLOG


The Hacker News

Site original : The Hacker News

⇐ retour index

Kaseya Rules Out Supply-Chain Attack; Says VSA 0-Day Hit Its Customers Directly

mardi 6 juillet 2021 à 09:03
U.S. technology firm Kaseya, which is firefighting the largest ever supply-chain ransomware strike on its VSA on-premises product, ruled out the possibility that its codebase was unauthorizedly tampered with to distribute malware. While initial reports raised speculations that the ransomware gang might have gained access to Kaseya's backend infrastructure and abused it to deploy a malicious

Getting Started with Security Testing: A Practical Guide for Startups

lundi 5 juillet 2021 à 14:44
A common misconception among startup founders is that cybercriminals won't waste time on them, because they're not big or well known enough yet. But just because you are small doesn't mean you're not in the firing line. The size of a startup does not exempt it from cyber-attacks – that's because hackers constantly scan the internet looking for flaws that they can exploit; one slip up, and your

TrickBot Botnet Found Deploying A New Ransomware Called Diavol

lundi 5 juillet 2021 à 11:48
Threat actors behind the infamous TrickBot malware have been linked to a new ransomware strain named "Diavol," according to the latest research. Diavol and Conti ransomware payloads were deployed on different systems in a case of an unsuccessful attack targeting one of its customers earlier this month, researchers from Fortinet's FortiGuard Labs said last week. TrickBot, a banking Trojan first

Microsoft Urges Azure Users to Update PowerShell to Patch RCE Flaw

lundi 5 juillet 2021 à 08:42
Microsoft is urging Azure users to update the PowerShell command-line tool as soon as possible to protect against a critical remote code execution vulnerability impacting .NET Core. The issue, tracked as CVE-2021-26701 (CVSS score: 8.1), affects PowerShell versions 7.0 and 7.1 and have been remediated in versions 7.0.6 and 7.1.3, respectively. Windows PowerShell 5.1 isn't impacted by the flaw.

REvil Used 0-Day in Kaseya Ransomware Attack, Demands $70 Million Ransom

lundi 5 juillet 2021 à 07:22
Amidst the massive supply-chain ransomware attack that triggered an infection chain compromising thousands of businesses on Friday, new details have emerged about how the notorious Russia-linked REvil cybercrime gang may have pulled off the unprecedented hack. The Dutch Institute for Vulnerability Disclosure (DIVD) on Sunday revealed it had alerted Kaseya to a number of zero-day vulnerabilities