PROJET AUTOBLOG


The Hacker News

Site original : The Hacker News

⇐ retour index

Hackers Exploiting Recently Reported Windows Print Spooler Vulnerability in the Wild

mercredi 20 avril 2022 à 04:54
A security flaw in the Windows Print Spooler component that was patched by Microsoft in February is being actively exploited in the wild, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) has warned. To that end, the agency has added the shortcoming to its Known Exploited Vulnerabilities Catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to address the issues by

New Lenovo UEFI Firmware Vulnerabilities Affect Millions of Laptops

mardi 19 avril 2022 à 14:30
Three high-impact Unified Extensible Firmware Interface (UEFI) security vulnerabilities have been discovered impacting various Lenovo consumer laptop models, enabling malicious actors to deploy and execute firmware implants on the affected devices. Tracked as CVE-2021-3970, CVE-2021-3971, and CVE-2021-3972, the latter two "affect firmware drivers originally meant to be used only during the

Experts Uncover Spyware Attacks Against Catalan Politicians and Activists

mardi 19 avril 2022 à 12:26
A previously unknown zero-click exploit in Apple's iMessage was used to install mercenary spyware from NSO Group and Candiru against at least 65 individuals as part of a "multi-year clandestine operation." "Victims included Members of the European Parliament, Catalan Presidents, legislators, jurists, and members of civil society organizations," the University of Toronto's Citizen Lab said in a

FBI, U.S. Treasury and CISA Warn of North Korean Hackers Targeting Blockchain Companies

mardi 19 avril 2022 à 08:23
The U.S. Cybersecurity and Infrastructure Security Agency (CISA), along with the Federal Bureau of Investigation (FBI) and the Treasury Department, warned of a new set of ongoing cyber attacks carried out by the Lazarus Group targeting blockchain companies. Calling the activity cluster TraderTraitor, the infiltrations involve the North Korean state-sponsored advanced persistent threat (APT)

Github Notifies Victims Whose Private Data Was Accessed Using OAuth Tokens

mardi 19 avril 2022 à 07:12
GitHub on Monday noted that it had notified all victims of an attack campaign, which involved an unauthorized party downloading private repository contents by taking advantage of third-party OAuth user tokens maintained by Heroku and Travis CI. "Customers should also continue to monitor Heroku and Travis CI for updates on their own investigations into the affected OAuth applications," the