Posts

Showing posts from October, 2020

Alibaba's Online Store Redmart Suffers Data Breach of More Than Million Accounts, Experts say Company's Fault

Image
  Lazada, a Singapore firm owned by e-commerce company Alibaba, suffered a hacking attack that cost more than one million accounts. On Friday, the e-commerce company said it lost user accounts containing personal information like credit card credentials and addresses. In what is considered one of the most significant data breach incidents, Singapore suffered a data breach of 5.7 million accounts.  According to ZDNet, "once beloved for its streamlined and clean users interface, the integrated RedMart experience was described by customers as cluttered, difficult navigate, and missing several popular features such as the ability to update a scheduled order and access to the favorite items list." In its email, the firm confirmed that the hackers took the information from the database of its online grocery platform, RedMart. RedMart had been inactive for more than eighteen months. Experts say that the attack on RedMart was bound to happen as the company didn't take cybersec...

Maze Ransomware Announces Departure – Replacements Already Available

After disrupting lots of businesses and making money, Maze ransomware has now announced its departure. However, there won’t be a Maze Ransomware Announces Departure – Replacements Already Available on Latest Hacking News . from Latest Hacking News https://ift.tt/3oGMUYZ

Link Previews Make Chat Apps Vulnerable To Data Leak And RCE Attacks

Reportedly, the faulty implementation of link previews has made numerous chat apps vulnerable to cyber attacks. These apps include Facebook Link Previews Make Chat Apps Vulnerable To Data Leak And RCE Attacks on Latest Hacking News . from Latest Hacking News https://ift.tt/3oDZatr

Smart Irrigation Systems Left Wide Open to Abuse

A small Israel-based security firm, Security Joes, recently spotted a vulnerability in smart irrigation systems. These included around 100 systems Smart Irrigation Systems Left Wide Open to Abuse on Latest Hacking News . from Latest Hacking News https://ift.tt/3mJrvg9

US President’s Twitter Account Hacked; The Ethical Hacker ‘Guessed’ The Password

Image
  According to reports by a Dutch media, US President Donald Trump's Twitter account was purportedly hacked, after a Dutch researcher accurately speculated the president's password: "maga2020!" De Volkskrant, a Dutch daily morning newspaper revealed, the ethical hacker and security researcher Victor Gevers had been able to access Trump's direct messages, post tweets in his name and even change his profile.  A Twitter spokesperson however has denied this hack, in a statement, they stated, "We’ve seen no evidence to corroborate this claim, including from the article published in the Netherlands today. We proactively implemented account security measures for a designated group of high-profile, election-related Twitter accounts in the United States, including federal branches of government."  Jack Mannino, CEO at nVisium, a Falls Church, Virginia-based application security provider, explains, “A security-savvy team would assume that these controls we...

Russian Cyber Criminals started using bots to deceive victims

Image
Fraudulent call centers started using bots to filtering distrustful victims in order to force them to call back and assist them on their own According to experts, this approach makes it possible to reduce the cost of attacks on victims and increase conversion. "The robot says: "Your card in this bank is blocked, call us back at this number”. When the victim calls back, allegedly the bank's security officers answer, ” explained Artem Gavrichenkov, technical director of Qrator Labs. He added that scammers make up to hundreds of calls a day using such robots. Fraudsters also use fake IP telephony service numbers, bulk SMS sending services and messages in Messengers on behalf of the Bank, said Sergei Nikitin, deputy head of the Group-IB computer forensics laboratory. The fraudsters in this case used "reverse social engineering", said Alexey Drozd, head of the information security department at SerchInform. In such cases, the victim calls the attackers. Andrey Z...

10 Best Practices for Data Encryption

Online data privacy is a prominent topic in the digital space. The increased transfer of data from analog to digital 10 Best Practices for Data Encryption on Latest Hacking News . from Latest Hacking News https://ift.tt/3jJOCVU

Why Do You Need Continuous Data Protection

Introduction Not only is data protection essential to those needing regulatory compliance across multiple laws and standards but it is Why Do You Need Continuous Data Protection on Latest Hacking News . from Latest Hacking News https://ift.tt/3jJut2f

Performance Testing vs. Load Testing vs. Stress Testing

In app development, there is a necessary phase called performance test. What you do in this phase is try to Performance Testing vs. Load Testing vs. Stress Testing on Latest Hacking News . from Latest Hacking News https://ift.tt/3mDpcej

How to Design a Website? 3 Important Tips

Before you just outsource your web design to a front-end development agency, it would not hurt to have some basic How to Design a Website? 3 Important Tips on Latest Hacking News . from Latest Hacking News https://ift.tt/35KQXLg

21 More Android Apps Part Of HiddenAds Campaign – 3 Still Available On Play Store

Once again, malicious apps barraging users with ads have flooded the Android Play Store. This time, the researchers spotted 21 21 More Android Apps Part Of HiddenAds Campaign – 3 Still Available On Play Store on Latest Hacking News . from Latest Hacking News https://ift.tt/2HHEiAW

Hackers Stole $2.3M, Wisconsin Republicans Claims

Image
  Wisconsin: Republican officials said that hackers stole $2.3m from the party's account being used to support Donald Trump's re-election.  Following the discovery of the suspicious activity on 22nd October, the FBI has been contacted to investigate the matter, as per the statements given by the state party chairman Andrew Hitt. He also that the state was warned regarding such cyberattacks in August during the party's national convention.    The campaign invoices from four vendors were manipulated by hackers to steal the funds, as per the reports by the Associated Press. These vendors were being paid to send out direct mail and handing out pro-Trump material like hats to support the Trump campaign.    Seemingly, the attackers began from a phishing scam and proceeded with altering the invoices to direct payments from vendors to themselves, Mr. Hitt said. A party spokesman added that no data seemed to be stolen. However, millions were stolen from the W...

U.S Suffers A Massive Wave Of Cyberattacks In Healthcare Industry, FBI Issues Alert

Image
  Cybercriminals are attacking the U.S. healthcare systems, destroying the network infrastructures, and stealing critical data. The U.S. federal agencies have issued an alarm that healthcare is in great danger of cyberattacks and intrusions. Hackers have become more active in attacking healthcare networks. The rise in hacking attempts had led to a risk of breach of patient privacy, which is a critical issue during the Covid-19 pandemic, as the cases are at an all-time high.  The FBI and other agencies in a joint report mentioned that they had verified information about cyberattacks on U.S. healthcare providers and hospitals. The warning also emphasized that few criminal groups are now targetting the healthcare industry to steal critical data and disrupt health care services. The ransomware attacks can scramble data into jargon. Only the security keys that the hacker has can reassemble data. The hacker demands payment in turn for providing the security keys. According to cyb...

US Security Department Issue Potential Trickbot and Malware Attack Warning to Health Department

Image
  The United States Healthcare providers have been alerted to vary of Trickbot and ransomware attacks by their Homeland Security department. The Department of Homeland Security's Cybersecurity and Infrastructure Security Agency (CISA), the Federal Bureau of Investigation (FBI), and the Department of Health and Human Services of US-issued out a warning of "imminent cybercrime threat to US hospitals and healthcare providers" regarding an infection from Trickbot and ransomware.  Already heavy with the burden of coronavirus, the US health department now faces another cybersecurity threat from Trickbot, one of the largest botnets worldwide, and Ryuk Ransomware, a lethal and savage malware on its own. Even Microsoft recently took legal action against Trickbots earlier this month. Earlier, Trickbot was a banking trojan attacking users via Webfakes (where it redirects the user to a fake webpage made by the attackers instead of the original banking webpage; accessing the user...

Russian Hackers Infiltrate U.S Government Networks and Steal Data

Image
  In a recent cybersecurity incident, the U.S. government issued a statement claiming that state-sponsored Russian hackers attacked the U.S. agencies and successfully breached the government networks. CISA (Cybersecurity and Infrastructure Security Agency) and FBI (Federal Bureau of Investigation) issued a joint report regarding the issue, confirm the U.S. government officials.  "The Russian-sponsored APT actor is obtaining user and administrator credentials to establish initial access, enable lateral movement once inside the network, and locate high-value assets to exfiltrate data. To date, the FBI and CISA have no information to indicate this APT actor has intentionally disrupted any aviation, education, elections, or government operations. However, the actor may be seeking access to obtain future disruption options, to influence U.S. policies and actions, or to delegitimize SLTT government entities," reports FBI and CISA.  According to the U.S. agencies, the hacki...

Federal Agencies Warned the US Healthcare System on Facing An “Increased and Imminent” Threat of Cybercrime

Image
  A couple of days back the FBI and two federal agencies, the Department of Homeland Security and the Department of Health and Human Services issued a caution that they had “credible information of an increased and imminent cybercrime threat to US hospitals and healthcare providers”.  This news comes after federal agencies cautioned that the US healthcare systems are confronting an “increased and imminent” danger of cybercrime, and that cybercriminals are releasing an influx of coercion endeavors intended to lock up hospital information systems, which could hurt patient care similarly to cases of Coronavirus are on a steady rise.  The cyberattacks include ransomware, which scrambles information into the hogwash that must be opened with software keys given once targets pay up. Independent security specialists state it has 'already hobbled at least five US hospitals' this week, and might affect hundreds more.  Charles Carmakal, chief technical officer of the cy...

The best free VPN for unblocking Netflix 2020

Are you trying to find a way for unblocking Netflix from everywhere and accessing more movie titles and Tv shows? The best free VPN for unblocking Netflix 2020 on Latest Hacking News . from Latest Hacking News https://ift.tt/3jEWl7s

Is Roku Worth It? How Can I Link My Roku With My Cable Internet?

When it comes to TV entertainment, people have different preferences. Some people want to just sit back and relax while Is Roku Worth It? How Can I Link My Roku With My Cable Internet? on Latest Hacking News . from Latest Hacking News https://ift.tt/2TAPHVu

10 Reasons to Switch to Ruby

Some programmers are wondering why others have switched to Ruby. Perhaps, you are also curious about this sudden trend in 10 Reasons to Switch to Ruby on Latest Hacking News . from Latest Hacking News https://ift.tt/3jyJdkh

Hackers stole the personal data of patients in Finland

Image
Finland: Hackers have stolen data from the Vastaamo Psychotherapy Center. Folders with personal information of tens of thousands of Suomi citizens, who in different years applied to this medical organization, were freely available The Сenter's archive includes people not only with serious mental illnesses but also those who have experienced temporary psychological difficulties. Journalists note that the organization's lists include politicians, businessmen, public figures, as well as ordinary citizens, even minors. The attackers made public the names of patients, addresses, phone numbers, identification numbers, as well as the contents of psychotherapy sessions. And they declare that they will not remove this information from public access until they receive the money. It is not surprising that the leak of personal data excited the entire Finnish society.  Finnish President Sauli Niinistö, in an interview with journalists, urged citizens to refuse further dissemination of ...

Enel Group attacked by Netwalker, demanding a whooping $14 million

Image
  Energy Company Enel Group has yet again been hit by malware, making it a second this year. The energy group has been demanded a ransom of 14 million dollars for the decryption key and to not reveal the stolen data by Netwalker ransomware. Enel Group is an Italian multinational Power company, operating in 30 countries working in electricity generation and distribution, as well as in the distribution of natural gas. With a revenue of $90 billion, it ranks 87th in Fortune Global 500.  Earlier this year in June, Enel Group was attacked by Snake ransomware also known as EKANS but then the attack was caught beforehand and was not successful. Contrary to now, when Netwalker not only successfully encrypted the power company's system but also leaked their data on its website.  Enel Group has still not confirmed if the attack was true but bleepingcomputer confirms the attack as data given by Netwalker reveals info of Enel employees.  The attackers connected to Enel Gr...

Nitro PDF Suffered A Data Breach Impacting Google, Apple, Amazon, And More

Popular PDF service provider Nitro PDF has recently suffered a massive data breach. While, they apparently strive to downplay the Nitro PDF Suffered A Data Breach Impacting Google, Apple, Amazon, And More on Latest Hacking News . from Latest Hacking News https://ift.tt/3oy0b68

Internet of Things (IoT): Greater Threat for Businesses Reopening Amid COVID-19 Pandemic

Image
  Businesses have increasingly adopted IoT devices, especially amid the COVID-19 pandemic to keep their operations safe. Over the past year, the number of IoT devices employed by various organizations in their network has risen by a remarkable margin, as per research conducted by Palo Alto Networks' threat intelligence arm, Unit 42.    While looking into the current IoT supply ecosystem, Unit 42 explained the multi exploits and vulnerabilities affecting IoT supply chains. The research also examined potential kinds of motivation for exploiting the IoT supply chain, illustrating how no layer is completely immune to the threat.   The analysis of the same has been reported during this year's National Cybersecurity Awareness Month (NCSAM), which is encouraging the individual's role in protecting their part of cyberspace and stressing personal accountability and the significance of taking proactive measures to strengthen cybersecurity.    The analysis...

Impact of Covid-19 Web Threats on Cybersecurity, A Report from Beginning to End

Image
  Cyberattacks during the Covid-19 pandemic exposed the flawed systems of cybersecurity. We should glance at these attacks and learn new ways to strengthen cybersecurity infrastructure from experience. Impact of cyberattacks during the pandemic-   Until the first quarter of 2020, the FBI's cyber division reported a 3-4 times surge in cyberattacks complaints since the start of Covid-19. According to Interpol and FBI data, there has been a massive increase in ransomware, phishing, DDoS and malware attacks; since the coronavirus pandemic. Hackers used email platforms to carry out their web threats.  Interpol reports, "Cybercriminals are taking advantage of the widespread global communications on the coronavirus to mask their activities. Hospitals, medical centers, and public institutions are being targeted by cybercriminals for ransomware attacks – since they are overwhelmed with the health crisis and cannot afford to be locked out of their systems, the criminals belie...

Numerous fraudulent sites disguised as well-known brands have appeared on the Runet

Image
In autumn, experts recorded mass registration of domain names with the names of well-known brands in the .RU zone Specialists at Infosecurity, a Softline company, recorded mass domain registration in Runet with the name of well-known brands and the ending –off, which can be used for sales. As an example, the company cited the domain names familiya-off.ru, detskiy-mir-off.ru, tele2-off.ru, rosneft-off.ru and citilink-off.ru. According to the head of the Infosecurity special server Sergey Trukhachev, on October 20, the Ethic threat detection service detected the registration of 192 such domains. All of them are registered through the same Russian structure with servers at ISPIRIA Networks Ltd, located in Belize (Central America). As Trukhachev noted, the company is often used for hosting malicious sites. At the end of September, the appearance of hundreds of similar domains in Runet was noticed by SearchInform. According to Alexey Drodd, head of the company's information securit...

Easy Ways to Ensure Your New Business is Protected

Starting a new business is an exciting time. But it can also be a busy and stressful time. Of course, Easy Ways to Ensure Your New Business is Protected on Latest Hacking News . from Latest Hacking News https://ift.tt/2HFw249

Few Easy Tips to Improve Your Website Design

If you’re wondering what tips to improve your website design would be best for you, keep reading. As you know Few Easy Tips to Improve Your Website Design on Latest Hacking News . from Latest Hacking News https://ift.tt/3dXcGDx

Malicious Apps Repeatedly Bypassed Apple App Notarization

Researchers found repeated successful attempts by criminals to bypass Apple’s app notarization – security check for apps outside Mac App Malicious Apps Repeatedly Bypassed Apple App Notarization on Latest Hacking News . from Latest Hacking News https://ift.tt/2HCVM0V

French IT Firm Sopra Steria Suffered Ransomware Attack

One more time, a devastating cyberattack has hit a corporate giant. This time, the victim is a French IT firm French IT Firm Sopra Steria Suffered Ransomware Attack on Latest Hacking News . from Latest Hacking News https://ift.tt/2JcXx5P

Georgia County Voting System Suffered Ransomware Attack

Weeks before the US election 2020, Georgia Hall County suffered a ransomware attack on its voting system. Their IT systems Georgia County Voting System Suffered Ransomware Attack on Latest Hacking News . from Latest Hacking News https://ift.tt/3jrl7rT

Google Removed Three Kids Android Apps For Data Collection Violations

Google has recently removed three different Android apps for kids for violating the data collection policy. The apps had millions Google Removed Three Kids Android Apps For Data Collection Violations on Latest Hacking News . from Latest Hacking News https://ift.tt/2HCmh6m

Firefox Brings Site Isolation Feature For Testing In Nightly Builds

Mozilla Firefox now plans to roll out the much-awaited site isolation feature for user testing. Users can presently experience this Firefox Brings Site Isolation Feature For Testing In Nightly Builds on Latest Hacking News . from Latest Hacking News https://ift.tt/3dUpytS

Latest Google Chrome Update Addressed Actively Exploited Zero-Day

With the latest Chrome release, Google has addressed a serious zero-day vulnerability alongside other bugs. Update your browser at the Latest Google Chrome Update Addressed Actively Exploited Zero-Day on Latest Hacking News . from Latest Hacking News https://ift.tt/2TqfzDa

Waze App Vulnerability Could Allow Tracking Users’ Location

A serious vulnerability has been discovered in the Waze app that could allow tracking other users’ locations in real-time. The Waze App Vulnerability Could Allow Tracking Users’ Location on Latest Hacking News . from Latest Hacking News https://ift.tt/3mg7n4M

Twitter and Facebook CEOs asked to testify on election and content moderation before the US Senate

Image
  The US Senate Judiciary Committee has asked the CEO of Twitter and Facebook to evaluate their role in “platforms’ censorship and suppression of New York Post articles” and their role in the election. After voting to move forward with a pair of subpoenas, the Senate Judiciary Committee agreed that the two CEO Twitter's Jack Dorsey and Facebook’s Mark Zuckerberg will be answerable to the Senate set on November 17, two weeks after the US elections. The committee lead by Republican South Carolina Senator Lindsey Graham set the agenda of the day as “platforms’ censorship and suppression of New York Post articles.”  The aforementioned New York Post article was labeled false as it published a story about Hunter Biden, the son of Democratic presidential nominee and former Vice President Joe Biden. The article claimed that Hunter Biden organized a meeting between Joe Biden and an executive at a Ukrainian energy company Burisma in April 2015. Many are calling it a typical "Right-Wi...

Multiple Mobile Browsers Suffer Address Bar Spoofing Vulnerabilities

Mobile users are exposed to a serious security problem due to vulnerable browsers on their devices. Security researchers have disclosed Multiple Mobile Browsers Suffer Address Bar Spoofing Vulnerabilities on Latest Hacking News . from Latest Hacking News https://ift.tt/3knZry1

Deepfake Bots on Telegram, Italian Authorities Investigating

Image
  Cybercriminals are using a newly created Artificial Intelligence bot to generate and share deepfake nude images of women on the messaging platform Telegram. The Italian Data Protection Authority has begun to investigate the matter following the news by a visual threat intelligence firm Sensity, which exposed the 'deepfake ecosystem' — estimating that almost 104,852 fake images have been created and shared with a large audience via public Telegram channels as of July 2020.    The bots are programmed to create fake nudes having watermarks or displaying nudity partially. Users upon accessing the partially nude image, pay for the whole photo to be revealed to them. They can do so by simply submitting a picture of any woman to the bot and get back a full version wherein clothes are digitally removed using the software called "DeepNude", which uses neural networks to make images appear "realistically nude". Sometimes, it's done for free of cost as well.  ...

U.S Elections: Spammers Use Fake Voter Registration Forms To Steal User Data and Banking Credentials

Image
  As the U.S. presidential elections are approaching, the hacking and spamming attacks related to it are rising. In a similar incident, hackers use fake voter registration forms to steal data of the users who access the fake government sites. The voter registration links work as bait, and if the user clicks it, he is redirected to a fake government website. The hacker then steals personal user data, along with banking credentials sometimes.  "Whatever the intent behind this particular phishing attack, it should serve as a reminder that human beings -- users, employees, citizens, and voters -- are "soft targets" for malicious actors. This is especially true in turbulent times such as the present -- when fear, confusion, and doubt are surging in the run-up to a historic election that happens to fall in the middle of a catastrophic pandemic," says KnowBe4. These phishing campaigns started in September and are still active.  Cybersecurity firms KnowBe4 and Proofpoi...

Russian experts says the number of cyber threats increased during COVID-19

Image
Cyber attack prevention experts recorded a sharp increase in the number of cyber threats and outlined the main trends in computer crimes during the COVID-19. The report was presented at the international forum of the Academy of Management of the Ministry of Internal Affairs of the Russian Federation "Strategic development of the system of the Ministry of Internal Affairs of Russia: state, trends, prospects". The main conclusion of the study is the rapid growth of computer crime, primarily financial fraud using social engineering, as well as the exploitation of the COVID-19 theme in malicious mailings, switching operators of encryption viruses to large targets, as well as active recruitment of new participants to criminal communities. According to the Ministry of Internal Affairs, one of the main trends of digital transformation is the development of remote methods of committing crimes, crimes have gone from offline to online. Almost 70% of registered crimes related to ill...

Google Remove Malicious Adblockers From Web Store For Collecting User Data

Google has recently removed two malicious adblockers from the web store after they were found collecting user data. Uninstall them Google Remove Malicious Adblockers From Web Store For Collecting User Data on Latest Hacking News . from Latest Hacking News https://ift.tt/35sKggF

What are typical payment terms? What are alternative payment methods?

Since the time gold coins were used until the present time when eWallets and eBanking prevail, lots of processes and What are typical payment terms? What are alternative payment methods? on Latest Hacking News . from Latest Hacking News https://ift.tt/35sqVMJ

Why You Can’t Use Avast SecureLine VPN With Netflix

Because of the various licensing agreements that Netflix has in place with the owners of the content that they show Why You Can’t Use Avast SecureLine VPN With Netflix on Latest Hacking News . from Latest Hacking News https://ift.tt/35u2Mp1

 6 Security Tips to Protect Your Website from Hackers

In today’s digital age, a secure website for your businesses is more than necessary. You may think that your portal  6 Security Tips to Protect Your Website from Hackers on Latest Hacking News . from Latest Hacking News https://ift.tt/2Htg7G0

Qualities to Look For When Buying a Laptop

Technology is becoming more portable each day, and most people can’t imagine themselves a day without gadgets or modern devices Qualities to Look For When Buying a Laptop on Latest Hacking News . from Latest Hacking News https://ift.tt/3ogMWXk

Universities Back on Iranian Hackers’ Radar as the School Year Begins

In addition to stressful exams, long lectures, and COVID-19 fears, university students must also be on the lookout for potential Universities Back on Iranian Hackers’ Radar as the School Year Begins on Latest Hacking News . from Latest Hacking News https://ift.tt/3ksKr1J

Top 7 Types of software development

Software application has now become a discipline of professional work based on the rather high demand of market overview around Top 7 Types of software development on Latest Hacking News . from Latest Hacking News https://ift.tt/2TnccwY

United States Charged Six Russian Intelligence Officers with Involvement in An Unrestricted Huge Hacking Campaign

Image
  With involvement in an 'unrestricted huge hacking campaign', which incorporates the famous Petya ransomware attacks which have focused mainly on Ukraine in 2015, as of late, the Justice Department has charged six Russian intelligence officers.  Residents and nationals of the Russian Federation (Russia)the six officials were also in Unit 74455 of the Russian Main Intelligence Directorate (GRU), a military intelligence agency of the General Staff of the Armed Forces.   The government claimed that the group that had attacked Ukraine has likewise hacked different computers promoting the 2018 Winter Olympics in South Korea. It likewise hacked and leaked emails of people related to Emmanuel Macron's 2017 campaign for president of France.  Besides this, they additionally focused on the companies exploring the poisoning of former Russian operative Sergei Skripal two years ago in Britain.  All the six hackers are GRU officers; the government said that for o...

Expert opinion: how the digital currency of the Bank of Russia will change the future of the country

Image
Announcing the possible appearance of the digital ruble, the Russian Central Bank joined dozens of world Central banks that have begun research and experiments in the field of creating national digital currencies. Yevgeny Marchenko, Director of E. M. FINANCE, was one of the first to share his opinion on the issue. The expert is sure that the introduction of the digital ruble is necessary to increase the convenience of payments for citizens. Also, among other advantages for citizens and banks, the introduction of the electronic ruble will allow the Bank of Russia to better regulate the country's economy. The official representative of the Garantex cryptocurrency exchange, Tatyana Maksimenko, noted that it will be increasingly difficult to conduct gray and black schemes since cash flows will be under control — both foreign and domestic. According to independent expert Leonid Khazanov, the digital ruble is primarily beneficial to the Bank of Russia and the Federal Tax Service. Ac...

Phantom Attack Bluffs Self Driving Cars By Displaying Simulated Objects

Recent research has demonstrated a phantom attack that fools self-driving cars by displaying virtual objects. Such attacks can trigger sudden Phantom Attack Bluffs Self Driving Cars By Displaying Simulated Objects on Latest Hacking News . from Latest Hacking News https://ift.tt/2HoY5Vt

TI WooCommerce Wishlist WP Plugin Flaw Could Allow Site Takeovers

One more vulnerable WordPress plugin requires immediate attention from the users. This time, the flaw appeared in the TI WooCommerce TI WooCommerce Wishlist WP Plugin Flaw Could Allow Site Takeovers on Latest Hacking News . from Latest Hacking News https://ift.tt/3dOkDdX

Iranian Hacker Group Using New Tools to Target Government Agencies of Broader Middle East Region

Image
  In the part of their attacks on companies and government agencies in the broader Middle East region, an Iranian cyberattack group has begun utilizing new tools, including a custom download utility and commodity ransomware, as per Broadcom's Symantec division.  Dubbed as Seedworm, the group gives off an impression of being deploying a few variations of a new downloader, known as PowGoop, to the recent targets. The utilization of the noxious program doesn't demonstrate a shift to ransomware-based cybercrime for the group, yet rather a reception of a more extensive variety of strategies for countering defensive measures.  The software downloads and decrypts 'obfuscated' PowerShell scripts to run on compromised frameworks, utilizing the basic utility as an approach to execute code.  The researchers additionally state that the group is sending ransomware, known as Thanos, which previously appeared available to be purchased not long ago and gives off an impress...

TikTok Launches Bug Bounty Program As It Partners With HackerOne

Amidst the US-China-TikTok tussle and security snafus, the Chinese video-sharing app has taken an important step. Specifically, TikTok has launched TikTok Launches Bug Bounty Program As It Partners With HackerOne on Latest Hacking News . from Latest Hacking News https://ift.tt/31sv8i3

United States rejected Putin's offer to cooperate on cybersecurity

Image
The US authorities for the first time publicly responded to the proposal of Russian President Vladimir Putin to resume cooperation in the field of international information security. US Assistant Attorney General for National Security John Demers called the Kremlin's initiative "nothing more than false rhetoric, cynical and cheap propaganda.” And Secretary of State Mike Pompeo said that Russia is dismissive of public security and international stability in cyberspace. On September 25, Vladimir Putin invited the US authorities to resume cooperation in the field of international information security, which began in 2013 but was frozen due to disagreements over Ukraine and Russia's alleged interference in the 2016 US presidential election. The President of the Russian Federation then stated that the dialogue in the cyber sphere should not be a "hostage" of political disputes, and proposed a four-point program for restoring cooperation. In a statement, the Russian...

Mobile Versions of Several Browsers Found Vulnerable to Address Bar Spoofing Flaws

Image
  Several mobile browsers including Firefox, Chrome, and Safari were found vulnerable to an ‘address bar spoofing’ flaw which when exploited could allow a threat actor to disguise a URL and make his phishing page appear like a legitimate website, according to a report published by cybersecurity company Rapid7 which reportedly worked in collaboration with Rafay Baloch - an independent security researcher who disclosed ten new URL spoofing vulnerabilities in seven browsers.    The browsers were informed about the issues in August as the vulnerabilities surfaced earlier this year; some of the vendors took preventive measures - patching the issues beforehand while others left their browsers vulnerable to the threat.    Notably, the Firefox browser for Android has already been fixed by Mozilla, and for those who haven’t updated it yet make sure you do it now. While Google’s Chrome Browser on both Android and iOS is still vulnerable to the threat and is unli...

Microsoft Released Out-of-Band Fixes For Two Remote Code Execution Bugs

With monthly scheduled updates for October, Microsoft rolled out fixes for 87 different vulnerabilities, including some publicly known exploits. Days Microsoft Released Out-of-Band Fixes For Two Remote Code Execution Bugs on Latest Hacking News . from Latest Hacking News https://ift.tt/3dJojxE

Multiple Vulnerabilities In Discord Desktop App Could Allow RCE Attacks

Japanese bug bounty hunter Masato Kinugawa has found multiple vulnerabilities affecting the Discord Desktop app. Elaborating on his findings in Multiple Vulnerabilities In Discord Desktop App Could Allow RCE Attacks on Latest Hacking News . from Latest Hacking News https://ift.tt/2HbFAUA

The Russian Embassy denies the US charge of six Russians in hacking

Image
The Russian Embassy in Washington denies US accusations against Russian citizens of hacking and destabilizing activities around the world Russia has not been and is not engaged in carrying out cyberattacks in the world, said the Russian Embassy in Washington. The Department believes that the accusation of Russians in hacking is aimed at warming up Russophobic sentiments. Earlier, the US Department of Justice and the FBI brought charges against six Russians of involvement in a series of hacker attacks and the spread of malware in order to attack the infrastructure of other countries. In particular, they are charged with spreading the NotPetya virus in 2017. It is alleged that these individuals are GRU employees.  The Russian Embassy said that Russia "has no intention of engaging in any destabilizing operations around the world", as this does not correspond to foreign policy and national interests. "It is quite obvious that such information occasions have nothing to d...

Russian military companies were reportedly attacked by hackers from North Korea

Image
North Korean hacker group Kimsuky has reportedly conducted several attacks on the Russian military-industrial complex in order to obtain military and technological secrets of Russia According to the cybersecurity company Group-IB, attacks by hackers from the Democratic People's Republic of Korea on the Russian defense industry took place in the spring of 2020. North Korean cyber criminals sought to obtain data from aerospace and defense companies, as well as from enterprises that produce artillery equipment. Telegram-channel SecAtor reported that Rostec was among the companies that were attacked. RT-Inform, a subsidiary of Rostec that deals with information security, did not confirm or deny these data, but noted that the number of cyber attacks on the resources of the state corporation increased from April to September. "Most of the attacks were poorly prepared and did not pose a significant threat when they were exposed, but this could only be preparation," said RT-I...

UK National Cyber Security Centre Reveals Russia’s Plan to Disrupt Tokyo Olympics

Image
  The UK National Cyber Security Centre recently revealed that in an attempt to completely disrupt the 'world's premier sporting event' the Russian military intelligence services were coming up with a cyber-attack on the Japanese-facilitated Olympics and Paralympics in Tokyo.  The Russian cyber-reconnaissance work covered the Games organizers, logistics services, and sponsors and was in progress before the Olympics was delayed due to Covid-19.  The proof is the first indication that Russia was set up to venture as far as to disrupt the summer Games, from which all Russian competitors had been prohibited on account of diligent state-sponsored doping offenses.  The Kyodo news agency said a senior Japanese government official had specified that Tokyo would think about housing a protest with Moscow if cyber-attacks were affirmed to have been carried out by Russia.  Japan's chief government spokesman, Katsunobu Kato, said the country would do all that is con...

Review Of KeepSolid Passwarden – Your Ultimate Password Manager

Given the incidences of data breaches that expose users’ login credentials, password security has become the need of our time. Review Of KeepSolid Passwarden – Your Ultimate Password Manager on Latest Hacking News . from Latest Hacking News https://ift.tt/31G1Ug7