Welcome, Guest
You have to register before you can post on our site.

Username/Email:
  

Password
  





Search Forums

(Advanced Search)

Online Users
There are currently 311 online users.
» 0 Member(s) | 310 Guest(s)
Google

Latest Threads
Mysterious Kill Switch Di...
Forum: The Hacker News
Last Post: yazrozzarn
01-10-2026, 04:36 AM
» Replies: 1
» Views: 858
UAW drops unfair labor pr...
Forum: Other Automakers
Last Post: BillyMum
06-16-2025, 09:15 PM
» Replies: 2
» Views: 2,528
Uber's Ex-CISO Appeals Co...
Forum: Dark Reading.com
Last Post: BillyMum
06-15-2025, 05:26 AM
» Replies: 2
» Views: 3,791
2021 Hyundai Ioniq SEL
Forum: Kia USB Entry
Last Post: HackMaster
03-31-2025, 07:17 AM
» Replies: 0
» Views: 450
Vulnerability of Remote K...
Forum: Keyless entry
Last Post: HackMaster
03-31-2025, 07:14 AM
» Replies: 0
» Views: 349
The (In)Security of Autom...
Forum: Keyless entry
Last Post: HackMaster
03-31-2025, 07:12 AM
» Replies: 0
» Views: 327
Relay Attacks on Passive ...
Forum: Keyless entry
Last Post: HackMaster
03-31-2025, 07:07 AM
» Replies: 0
» Views: 321
Hacking Tesla from Wirele...
Forum: Tesla
Last Post: HackMaster
03-31-2025, 06:58 AM
» Replies: 0
» Views: 360
Hacking Tesla from Wirele...
Forum: Tesla
Last Post: HackMaster
03-31-2025, 06:22 AM
» Replies: 0
» Views: 346
Schematics and Datasheets
Forum: Schematics
Last Post: HackMaster
02-27-2025, 12:26 AM
» Replies: 0
» Views: 303

 
  Iranian Hackers Masquerade as Journalists to Spy on Israel-Hamas War Experts
Posted by: The Hacker News - 01-25-2024, 03:33 PM - Forum: The Hacker News - No Replies

Iranian Hackers Masquerade as Journalists to Spy on Israel-Hamas War Experts

High-profile individuals working on Middle Eastern affairs at universities and research organizations in Belgium, France, Gaza, Israel, the U.K., and the U.S. have been targeted by an Iranian cyber espionage group called Mint Sandstorm since November 2023.
The threat actor "used bespoke phishing lures in an attempt to socially engineer targets into downloading malicious files," the

https://thehackernews.com/2024/01/irania...es-as.html

Print this item

  PixieFail UEFI Flaws Expose Millions of Computers to RCE, DoS, and Data Theft
Posted by: The Hacker News - 01-25-2024, 03:33 PM - Forum: The Hacker News - No Replies

PixieFail UEFI Flaws Expose Millions of Computers to RCE, DoS, and Data Theft

Multiple security vulnerabilities have been disclosed in the TCP/IP network protocol stack of an open-source reference implementation of the Unified Extensible Firmware Interface (UEFI) specification used widely in modern computers.
Collectively dubbed PixieFail by Quarkslab, the nine issues reside in the TianoCore EFI Development Kit II (EDK II) and could be exploited to

https://thehackernews.com/2024/01/pixief...ns-of.html

Print this item

  MFA Spamming and Fatigue: When Security Measures Go Wrong
Posted by: The Hacker News - 01-25-2024, 03:33 PM - Forum: The Hacker News - No Replies

MFA Spamming and Fatigue: When Security Measures Go Wrong

In today's digital landscape, traditional password-only authentication systems have proven to be vulnerable to a wide range of cyberattacks. To safeguard critical business resources, organizations are increasingly turning to multi-factor authentication (MFA) as a more robust security measure. MFA requires users to provide multiple authentication factors to verify their identity, providing an

https://thehackernews.com/2024/01/mfa-sp...urity.html

Print this item

  TensorFlow CI/CD Flaw Exposed Supply Chain to Poisoning Attacks
Posted by: The Hacker News - 01-25-2024, 03:33 PM - Forum: The Hacker News - No Replies

TensorFlow CI/CD Flaw Exposed Supply Chain to Poisoning Attacks

Continuous integration and continuous delivery (CI/CD) misconfigurations discovered in the open-source TensorFlow machine learning framework could have been exploited to orchestrate supply chain attacks.
The misconfigurations could be abused by an attacker to "conduct a supply chain compromise of TensorFlow releases on GitHub and PyPi by compromising TensorFlow's build agents via

https://thehackernews.com/2024/01/tensor...upply.html

Print this item

  Russian COLDRIVER Hackers Expand Beyond Phishing with Custom Malware
Posted by: The Hacker News - 01-25-2024, 03:33 PM - Forum: The Hacker News - No Replies

Russian COLDRIVER Hackers Expand Beyond Phishing with Custom Malware

The Russia-linked threat actor known as COLDRIVER has been observed evolving its tradecraft to go beyond credential harvesting to deliver its first-ever custom malware written in the Rust programming language.
Google's Threat Analysis Group (TAG), which shared details of the latest activity, said the attack chains leverage PDFs as decoy documents to trigger the infection sequence. The lures are

https://thehackernews.com/2024/01/russia...eyond.html

Print this item

  New Docker Malware Steals CPU for Crypto & Drives Fake Website Traffic
Posted by: The Hacker News - 01-25-2024, 03:33 PM - Forum: The Hacker News - No Replies

New Docker Malware Steals CPU for Crypto & Drives Fake Website Traffic

Vulnerable Docker services are being targeted by a novel campaign in which the threat actors are deploying XMRig cryptocurrency miner as well as the 9Hits Viewer software as part of a multi-pronged monetization strategy.
"This is the first documented case of malware deploying the 9Hits application as a payload," cloud security firm Cado said, adding the development is a sign that adversaries are

https://thehackernews.com/2024/01/new-do...u-for.html

Print this item

  U.S. Cybersecurity Agency Warns of Actively Exploited Ivanti EPMM Vulnerability
Posted by: The Hacker News - 01-25-2024, 03:33 PM - Forum: The Hacker News - No Replies

U.S. Cybersecurity Agency Warns of Actively Exploited Ivanti EPMM Vulnerability

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Thursday added a now-patched critical flaw impacting Ivanti Endpoint Manager Mobile (EPMM) and MobileIron Core to its Known Exploited Vulnerabilities (KEV) catalog, stating it's being actively exploited in the wild.
The vulnerability in question is CVE-2023-35082 (CVSS score: 9.8), an authentication bypass

https://thehackernews.com/2024/01/us-cyb...ns-of.html

Print this item

  Npm Trojan Bypasses UAC, Installs AnyDesk with "Oscompatible" Package
Posted by: The Hacker News - 01-25-2024, 03:33 PM - Forum: The Hacker News - No Replies

Npm Trojan Bypasses UAC, Installs AnyDesk with "Oscompatible" Package

A malicious package uploaded to the npm registry has been found deploying a sophisticated remote access trojan on compromised Windows machines.
The package, named "oscompatible," was published on January 9, 2024, attracting a total of 380 downloads before it was taken down.
oscompatible included a "few strange binaries," according to software supply chain security firm Phylum, including a single

https://thehackernews.com/2024/01/npm-tr...talls.html

Print this item

  Preventing Data Loss: Backup and Recovery Strategies for Exchange Server Administrat
Posted by: The Hacker News - 01-25-2024, 03:33 PM - Forum: The Hacker News - No Replies

Preventing Data Loss: Backup and Recovery Strategies for Exchange Server Administrat

In the current digital landscape, data has emerged as a crucial asset for organizations, akin to currency. It’s the lifeblood of any organization in today's interconnected and digital world. Thus, safeguarding the data is of paramount importance. Its importance is magnified in on-premises Exchange Server environments where vital business communication and emails are stored and managed. 
In

https://thehackernews.com/2024/01/preven...p-and.html

Print this item

  Experts Warn of macOS Backdoor Hidden in Pirated Versions of Popular Software
Posted by: The Hacker News - 01-25-2024, 03:33 PM - Forum: The Hacker News - No Replies

Experts Warn of macOS Backdoor Hidden in Pirated Versions of Popular Software

Pirated applications targeting Apple macOS users have been observed containing a backdoor capable of granting attackers remote control to infected machines.
"These applications are being hosted on Chinese pirating websites in order to gain victims," Jamf Threat Labs researchers Ferdous Saljooki and Jaron Bradley said.
"Once detonated, the malware will download and execute multiple payloads

https://thehackernews.com/2024/01/expert...idden.html

Print this item