Welcome, Guest
You have to register before you can post on our site.

Username/Email:
  

Password
  





Search Forums

(Advanced Search)

Online Users
There are currently 29 online users.
» 0 Member(s) | 28 Guest(s)
Google

Latest Threads
Mysterious Kill Switch Di...
Forum: The Hacker News
Last Post: yazrozzarn
01-10-2026, 04:36 AM
» Replies: 1
» Views: 846
UAW drops unfair labor pr...
Forum: Other Automakers
Last Post: BillyMum
06-16-2025, 09:15 PM
» Replies: 2
» Views: 2,504
Uber's Ex-CISO Appeals Co...
Forum: Dark Reading.com
Last Post: BillyMum
06-15-2025, 05:26 AM
» Replies: 2
» Views: 3,737
2021 Hyundai Ioniq SEL
Forum: Kia USB Entry
Last Post: HackMaster
03-31-2025, 07:17 AM
» Replies: 0
» Views: 441
Vulnerability of Remote K...
Forum: Keyless entry
Last Post: HackMaster
03-31-2025, 07:14 AM
» Replies: 0
» Views: 344
The (In)Security of Autom...
Forum: Keyless entry
Last Post: HackMaster
03-31-2025, 07:12 AM
» Replies: 0
» Views: 318
Relay Attacks on Passive ...
Forum: Keyless entry
Last Post: HackMaster
03-31-2025, 07:07 AM
» Replies: 0
» Views: 313
Hacking Tesla from Wirele...
Forum: Tesla
Last Post: HackMaster
03-31-2025, 06:58 AM
» Replies: 0
» Views: 355
Hacking Tesla from Wirele...
Forum: Tesla
Last Post: HackMaster
03-31-2025, 06:22 AM
» Replies: 0
» Views: 342
Schematics and Datasheets
Forum: Schematics
Last Post: HackMaster
02-27-2025, 12:26 AM
» Replies: 0
» Views: 296

 
  Over 800 npm Packages Found with Discrepancies, 18 Exploitable to 'Manifest Confusio
Posted by: The Hacker News - 03-25-2024, 06:02 AM - Forum: The Hacker News - No Replies

Over 800 npm Packages Found with Discrepancies, 18 Exploitable to 'Manifest Confusio

New research has discovered over 800 packages in the npm registry which have discrepancies from their registry entries, out of which 18 have been found to exploit a technique called manifest confusion.
The findings come from cybersecurity firm JFrog, which said the issue could be exploited by threat actors to trick developers into running malicious code.
"It's an actual threat since

https://thehackernews.com/2024/03/over-8...-with.html

Print this item

  Russia Hackers Using TinyTurla-NG to Breach European NGO's Systems
Posted by: The Hacker News - 03-25-2024, 06:02 AM - Forum: The Hacker News - No Replies

Russia Hackers Using TinyTurla-NG to Breach European NGO's Systems

The Russia-linked threat actor known as Turla infected several systems belonging to an unnamed European non-governmental organization (NGO) in order to deploy a backdoor called TinyTurla-NG (TTNG).
"The attackers compromised the first system, established persistence and added exclusions to antivirus products running on these endpoints as part of their preliminary post-compromise actions," Cisco

https://thehackernews.com/2024/03/russia...ng-to.html

Print this item

  Russian Hackers May Have Targeted Ukrainian Telecoms with Upgraded 'AcidPour' Malware
Posted by: The Hacker News - 03-25-2024, 06:02 AM - Forum: The Hacker News - No Replies

Russian Hackers May Have Targeted Ukrainian Telecoms with Upgraded 'AcidPour' Malware

The data wiping malware called AcidPour may have been deployed in attacks targeting four telecom providers in Ukraine, new findings from SentinelOne show.
The cybersecurity firm also confirmed connections between the malware and AcidRain, tying it to threat activity clusters associated with Russian military intelligence.
"AcidPour's expanded capabilities would enable it to better

https://thehackernews.com/2024/03/russia...inian.html

Print this item

  U.S. Justice Department Sues Apple Over Monopoly and Messaging Security
Posted by: The Hacker News - 03-25-2024, 06:02 AM - Forum: The Hacker News - No Replies

U.S. Justice Department Sues Apple Over Monopoly and Messaging Security

The U.S. Department of Justice (DoJ), along with 16 other state and district attorneys general, on Thursday accused Apple of illegally maintaining a monopoly over smartphones, thereby undermining, among other things, the security and privacy of users when messaging non-iPhone users.
"Apple wraps itself in a cloak of privacy, security, and consumer preferences to justify its

https://thehackernews.com/2024/03/us-jus...-over.html

Print this item

  Massive Sign1 Campaign Infects 39,000+ WordPress Sites with Scam Redirects
Posted by: The Hacker News - 03-25-2024, 06:02 AM - Forum: The Hacker News - No Replies

Massive Sign1 Campaign Infects 39,000+ WordPress Sites with Scam Redirects

A massive malware campaign dubbed Sign1 has compromised over 39,000 WordPress sites in the last six months, using malicious JavaScript injections to redirect users to scam sites.
The most recent variant of the malware is estimated to have infected no less than 2,500 sites over the past two months alone, Sucuri said in a report published this week.
The attacks entail injecting rogue

https://thehackernews.com/2024/03/massiv...39000.html

Print this item

  Implementing Zero Trust Controls for Compliance
Posted by: The Hacker News - 03-25-2024, 06:02 AM - Forum: The Hacker News - No Replies

Implementing Zero Trust Controls for Compliance

The ThreatLocker® Zero Trust Endpoint Protection Platform implements a strict deny-by-default, allow-by-exception security posture to give organizations the ability to set policy-based controls within their environment and mitigate countless cyber threats, including zero-days, unseen network footholds, and malware attacks as a direct result of user error.
With the capabilities of the

https://thehackernews.com/2024/03/implem...s-for.html

Print this item

  China-Linked Group Breaches Networks via Connectwise, F5 Software Flaws
Posted by: The Hacker News - 03-25-2024, 06:02 AM - Forum: The Hacker News - No Replies

China-Linked Group Breaches Networks via Connectwise, F5 Software Flaws

A China-linked threat cluster leveraged security flaws in Connectwise ScreenConnect and F5 BIG-IP software to deliver custom malware capable of delivering additional backdoors on compromised Linux hosts as part of an "aggressive" campaign.
Google-owned Mandiant is tracking the activity under its uncategorized moniker UNC5174 (aka Uteus or Uetus), describing it as a "former

https://thehackernews.com/2024/03/china-...works.html

Print this item

  AWS Patches Critical 'FlowFixation' Bug in Airflow Service to Prevent Session Hijack
Posted by: The Hacker News - 03-25-2024, 06:02 AM - Forum: The Hacker News - No Replies

AWS Patches Critical 'FlowFixation' Bug in Airflow Service to Prevent Session Hijack

Cybersecurity researchers have shared details of a now-patched security vulnerability in Amazon Web Services (AWS) Managed Workflows for Apache Airflow (MWAA) that could be potentially exploited by a malicious actor to hijack victims' sessions and achieve remote code execution on underlying instances.
The vulnerability, now addressed by AWS, has been codenamed FlowFixation by Tenable.

https://thehackernews.com/2024/03/aws-pa...n-bug.html

Print this item

  New StrelaStealer Phishing Attacks Hit Over 100 Organizations in E.U. and U.S.
Posted by: The Hacker News - 03-25-2024, 06:02 AM - Forum: The Hacker News - No Replies

New StrelaStealer Phishing Attacks Hit Over 100 Organizations in E.U. and U.S.

Cybersecurity researchers have detected a new wave of phishing attacks that aim to deliver an ever-evolving information stealer referred to as StrelaStealer.
The campaigns impact more than 100 organizations in the E.U. and the U.S., Palo Alto Networks Unit 42 researchers said in a new report published today.
"These campaigns come in the form of spam emails with attachments that eventually

https://thehackernews.com/2024/03/new-st...s-hit.html

Print this item

  Russian Hackers Use 'WINELOADER' Malware to Target German Political Parties
Posted by: The Hacker News - 03-25-2024, 06:02 AM - Forum: The Hacker News - No Replies

Russian Hackers Use 'WINELOADER' Malware to Target German Political Parties

The WINELOADER backdoor used in recent cyber attacks targeting diplomatic entities with wine-tasting phishing lures has been attributed as the handiwork of a hacking group with links to Russia's Foreign Intelligence Service (SVR), which was responsible for breaching SolarWinds and Microsoft.
The findings come from Mandiant, which said Midnight Blizzard (aka APT29, BlueBravo, or

https://thehackernews.com/2024/03/russia...lware.html

Print this item