Welcome, Guest
You have to register before you can post on our site.

Username/Email:
  

Password
  





Search Forums

(Advanced Search)

Online Users
There are currently 167 online users.
» 0 Member(s) | 166 Guest(s)
Bing

Latest Threads
Mysterious Kill Switch Di...
Forum: The Hacker News
Last Post: yazrozzarn
01-10-2026, 04:36 AM
» Replies: 1
» Views: 858
UAW drops unfair labor pr...
Forum: Other Automakers
Last Post: BillyMum
06-16-2025, 09:15 PM
» Replies: 2
» Views: 2,528
Uber's Ex-CISO Appeals Co...
Forum: Dark Reading.com
Last Post: BillyMum
06-15-2025, 05:26 AM
» Replies: 2
» Views: 3,790
2021 Hyundai Ioniq SEL
Forum: Kia USB Entry
Last Post: HackMaster
03-31-2025, 07:17 AM
» Replies: 0
» Views: 450
Vulnerability of Remote K...
Forum: Keyless entry
Last Post: HackMaster
03-31-2025, 07:14 AM
» Replies: 0
» Views: 349
The (In)Security of Autom...
Forum: Keyless entry
Last Post: HackMaster
03-31-2025, 07:12 AM
» Replies: 0
» Views: 327
Relay Attacks on Passive ...
Forum: Keyless entry
Last Post: HackMaster
03-31-2025, 07:07 AM
» Replies: 0
» Views: 321
Hacking Tesla from Wirele...
Forum: Tesla
Last Post: HackMaster
03-31-2025, 06:58 AM
» Replies: 0
» Views: 360
Hacking Tesla from Wirele...
Forum: Tesla
Last Post: HackMaster
03-31-2025, 06:22 AM
» Replies: 0
» Views: 346
Schematics and Datasheets
Forum: Schematics
Last Post: HackMaster
02-27-2025, 12:26 AM
» Replies: 0
» Views: 303

 
  Google Kubernetes Misconfig Lets Any Gmail Account Control Your Clusters
Posted by: The Hacker News - 01-28-2024, 11:02 AM - Forum: The Hacker News - No Replies

Google Kubernetes Misconfig Lets Any Gmail Account Control Your Clusters

Cybersecurity researchers have discovered a loophole impacting Google Kubernetes Engine (GKE) that could be potentially exploited by threat actors with a Google account to take control of a Kubernetes cluster.
The critical shortcoming has been codenamed Sys:All by cloud security firm Orca. As many as 250,000 active GKE clusters in the wild are estimated to be susceptible to the attack vector.
In

https://thehackernews.com/2024/01/google...s-any.html

Print this item

  Tech Giant HP Enterprise Hacked by Russian Hackers Linked to DNC Breach
Posted by: The Hacker News - 01-28-2024, 11:02 AM - Forum: The Hacker News - No Replies

Tech Giant HP Enterprise Hacked by Russian Hackers Linked to DNC Breach

Hackers with links to the Kremlin are suspected to have infiltrated information technology company Hewlett Packard Enterprise's (HPE) cloud email environment to exfiltrate mailbox data.
"The threat actor accessed and exfiltrated data beginning in May 2023 from a small percentage of HPE mailboxes belonging to individuals in our cybersecurity, go-to-market, business segments, and other functions,"

https://thehackernews.com/2024/01/tech-g...ed-by.html

Print this item

  New CherryLoader Malware Mimics CherryTree to Deploy PrivEsc Exploits
Posted by: The Hacker News - 01-28-2024, 11:02 AM - Forum: The Hacker News - No Replies

New CherryLoader Malware Mimics CherryTree to Deploy PrivEsc Exploits

A new Go-based malware loader called CherryLoader has been discovered by threat hunters in the wild to deliver additional payloads onto compromised hosts for follow-on exploitation.
Arctic Wolf Labs, which discovered the new attack tool in two recent intrusions, said the loader's icon and name masquerades as the legitimate CherryTree note-taking application to dupe potential victims

https://thehackernews.com/2024/01/new-ch...imics.html

Print this item

  China-backed Hackers Hijack Software Updates to Implant "NSPX30" Spyware
Posted by: The Hacker News - 01-28-2024, 11:02 AM - Forum: The Hacker News - No Replies

China-backed Hackers Hijack Software Updates to Implant "NSPX30" Spyware

A previously undocumented China-aligned threat actor has been linked to a set of adversary-in-the-middle (AitM) attacks that hijack update requests from legitimate software to deliver a sophisticated implant named NSPX30.
Slovak cybersecurity firm ESET is tracking the advanced persistent threat (APT) group under the name Blackwood. It's said to be active since at least 2018.
The NSPX30

https://thehackernews.com/2024/01/china-...tware.html

Print this item

  VexTrio: The Uber of Cybercrime - Brokering Malware for 60+ Affiliates
Posted by: The Hacker News - 01-28-2024, 11:02 AM - Forum: The Hacker News - No Replies

VexTrio: The Uber of Cybercrime - Brokering Malware for 60+ Affiliates

The threat actors behind ClearFake, SocGholish, and dozens of other actors have established partnerships with another entity known as VexTrio as part of a massive "criminal affiliate program," new findings from Infoblox reveal.
The latest development demonstrates the "breadth of their activities and depth of their connections within the cybercrime industry," the company said,

https://thehackernews.com/2024/01/vextri...ering.html

Print this item

  Patch Your GoAnywhere MFT Immediately - Critical Flaw Lets Anyone Be Admin
Posted by: The Hacker News - 01-28-2024, 11:02 AM - Forum: The Hacker News - No Replies

Patch Your GoAnywhere MFT Immediately - Critical Flaw Lets Anyone Be Admin

A critical security flaw has been disclosed in Fortra's GoAnywhere Managed File Transfer (MFT) software that could be abused to create a new administrator user.
Tracked as CVE-2024-0204, the issue carries a CVSS score of 9.8 out of 10.
"Authentication bypass in Fortra's GoAnywhere MFT prior to 7.4.1 allows an unauthorized user to create an admin user via the administration portal," Fortra&

https://thehackernews.com/2024/01/patch-...ately.html

Print this item

  U.S., U.K., Australia Sanction Russian REvil Hacker Behind Medibank Breach
Posted by: The Hacker News - 01-28-2024, 11:02 AM - Forum: The Hacker News - No Replies

U.S., U.K., Australia Sanction Russian REvil Hacker Behind Medibank Breach

Governments from Australia, the U.K., and the U.S. have imposed financial sanctions on a Russian national for his alleged role in the 2022 ransomware attack against health insurance provider Medibank.
Alexander Ermakov (aka blade_runner, GistaveDore, GustaveDore, or JimJones), 33, has been tied to the breach of the Medibank network as well as the theft and release of Personally Identifiable

https://thehackernews.com/2024/01/us-uk-...revil.html

Print this item

  The Unknown Risks of The Software Supply Chain: A Deep-Dive
Posted by: The Hacker News - 01-28-2024, 11:02 AM - Forum: The Hacker News - No Replies

The Unknown Risks of The Software Supply Chain: A Deep-Dive

In a world where more & more organizations are adopting open-source components as foundational blocks in their application's infrastructure, it's difficult to consider traditional SCAs as complete protection mechanisms against open-source threats.
Using open-source libraries saves tons of coding and debugging time, and by that - shortens the time to deliver our applications. But, as

https://thehackernews.com/2024/01/the-un...upply.html

Print this item

  Kasseika Ransomware Using BYOVD Trick to Disarm Security Pre-Encryption
Posted by: The Hacker News - 01-28-2024, 11:02 AM - Forum: The Hacker News - No Replies

Kasseika Ransomware Using BYOVD Trick to Disarm Security Pre-Encryption

The ransomware group known as Kasseika has become the latest to leverage the Bring Your Own Vulnerable Driver (BYOVD) attack to disarm security-related processes on compromised Windows hosts, joining the likes of other groups like Akira, AvosLocker, BlackByte, and RobbinHood.
The tactic allows "threat actors to terminate antivirus processes and services for the deployment of ransomware," Trend

https://thehackernews.com/2024/01/kassei...trick.html

Print this item

  What is Nudge Security and How Does it Work?
Posted by: The Hacker News - 01-28-2024, 11:02 AM - Forum: The Hacker News - No Replies

What is Nudge Security and How Does it Work?

In today’s highly distributed workplace, every employee has the ability to act as their own CIO, adopting new cloud and SaaS technologies whenever and wherever they need. While this has been a critical boon to productivity and innovation in the digital enterprise, it has upended traditional approaches to IT security and governance.
Nudge Security is the world’s first and only solution to address

https://thehackernews.com/2024/01/what-i...es-it.html

Print this item