PROJET AUTOBLOG


The Hacker News

Site original : The Hacker News

⇐ retour index

New Golang-based Linux Malware Targeting eCommerce Websites

lundi 22 novembre 2021 à 13:10
Weaknesses in e-commerce portals are being exploited to deploy a Linux backdoor as well as a credit card skimmer that's capable of stealing payment information from compromised websites. "The attacker started with automated e-commerce attack probes, testing for dozens of weaknesses in common online store platforms," researchers from Sansec Threat Research said in an analysis. "After a day and a

Hackers Exploiting ProxyLogon and ProxyShell Flaws in Spam Campaigns

lundi 22 novembre 2021 à 12:47
Threat actors are exploiting ProxyLogon and ProxyShell exploits in unpatched Microsoft Exchange Servers as part of an ongoing spam campaign that leverages stolen email chains to bypass security software and deploy malware on vulnerable systems. The findings come from Trend Micro following an investigation into a number of intrusions in the Middle East that culminated in the distribution of a

Facebook Postpones Plans for E2E Encryption in Messenger, Instagram Until 2023

lundi 22 novembre 2021 à 08:30
Meta, the parent company of Facebook, Instagram, and WhatsApp, disclosed that it doesn't intend to roll out default end-to-end encryption (E2EE) across all its messaging services until 2023, pushing its original plans by at least a year. "We're taking our time to get this right and we don't plan to finish the global rollout of end-to-end encryption by default across all our messaging services

RedCurl Corporate Espionage Hackers Return With Updated Hacking Tools

samedi 20 novembre 2021 à 16:54
A corporate cyber-espionage hacker group has resurfaced after a seven-month hiatus with new intrusions targeting four companies this year, including one of the largest wholesale stores in Russia, while simultaneously making tactical improvements to its toolset in an attempt to thwart analysis. "In every attack, the threat actor demonstrates extensive red teaming skills and the ability to bypass

North Korean Hackers Found Behind a Range of Credential Theft Campaigns

samedi 20 novembre 2021 à 16:26
A threat actor with ties to North Korea has been linked to a prolific wave of credential theft campaigns targeting research, education, government, media and other organizations, with two of the attacks also attempting to distribute malware that could be used for intelligence gathering. Enterprise security firm Proofpoint attributed the infiltrations to a group it tracks as TA406, and by the