North Korean Hackers Distributing Trojanized DeFi Wallet Apps to Steal Victims’ Crypto

Blog WriterThe Hacker News - Original news source is thehackernews.com

The North Korean state-backed hacking crew, otherwise known as the Lazarus Group, has been attributed to yet another financially motivated campaign that leverages a trojanized decentralized finance (DeFi) wallet app to …

Apple Issues Patches for 2 Actively Exploited Zero-Days in iPhone, iPad and Mac Devices

Blog WriterThe Hacker News - Original news source is thehackernews.com

Apple on Thursday rolled out emergency patches to address two zero-day flaws in its mobile and desktop operating systems that it said may have been exploited in the wild. The shortcomings have been fixed …

Zyxel Releases Patches for Critical Bug Affecting Business Firewall and VPN Devices

Blog WriterThe Hacker News - Original news source is thehackernews.com

Networking equipment maker Zyxel has pushed security updates for a critical vulnerability affecting some of its business firewall and VPN products that could enable an attacker to take control of …

Researchers Expose Mars Stealer Malware Campaign Using Google Ads to Spread

Blog WriterThe Hacker News - Original news source is thehackernews.com

A nascent information stealer called Mars has been observed in campaigns that take advantage of cracked versions of the malware to steal information stored in web browsers and cryptocurrency wallets. …

QNAP Warns of OpenSSL Infinite Loop Vulnerability Affecting NAS Devices

Blog WriterThe Hacker News - Original news source is thehackernews.com

Taiwanese company QNAP this week revealed that a selected number of its network-attached storage (NAS) appliances are affected by a recently-disclosed bug in the open-source OpenSSL cryptographic library. “An infinite …

Unpatched Java Spring Framework 0-Day RCE Bug Threatens Enterprise Web Apps Security

Blog WriterThe Hacker News - Original news source is thehackernews.com

A zero-day remote code execution (RCE) vulnerability has come to light in the Spring framework shortly after a Chinese security researcher briefly leaked a proof-of-concept (PoC) exploit on GitHub before deleting their account. According to cybersecurity …

CISA Warns of Ongoing Cyber Attacks Targeting Internet-Connected UPS Devices

Blog WriterThe Hacker News - Original news source is thehackernews.com

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) and the Department of Energy (DoE) are jointly warning of attacks against internet-connected uninterruptible power supply (UPS) devices by means of default …