Microsoft Warns of Continued Supply-Chain Attacks by the Nobelium Hacker Group

Blog WriterThe Hacker News - Original news source is thehackernews.com

Nobelium, the threat actor behind the SolarWinds compromise in December 2020, has been behind a new wave of attacks that compromised 14 downstream customers of multiple cloud service providers (CSP), managed service …

Hackers Exploited Popular BillQuick Billing Software to Deploy Ransomware

Blog WriterThe Hacker News - Original news source is thehackernews.com

Cybersecurity researchers on Friday disclosed a now-patched critical vulnerability in multiple versions of a time and billing system called BillQuick that’s being actively exploited by threat actors to deploy ransomware …

NYT Journalist Repeatedly Hacked with Pegasus after Reporting on Saudi Arabia

Blog WriterThe Hacker News - Original news source is thehackernews.com

The iPhone of New York Times journalist Ben Hubbard was repeatedly hacked with NSO Group’s Pegasus spyware tool over a three-year period stretching between June 2018 to June 2021, resulting …

Microsoft Warns of TodayZoo Phishing Kit Used in Extensive Credential Stealing Attacks

Blog WriterThe Hacker News - Original news source is thehackernews.com

Microsoft on Thursday disclosed an “extensive series of credential phishing campaigns” that takes advantage of a custom phishing kit that stitched together components from at least five different widely circulated …

Feds Reportedly Hacked REvil Ransomware Group and Forced it Offline

Blog WriterThe Hacker News - Original news source is thehackernews.com

The Russian-led REvil ransomware gang was felled by an active multi-country law enforcement operation that resulted in its infrastructure being hacked and taken offline for a second time earlier this week, in …

‘Lone Wolf’ Hacker Group Targeting Afghanistan and India with Commodity RATs

Blog WriterThe Hacker News - Original news source is thehackernews.com

A new malware campaign targeting Afghanistan and India is exploiting a now-patched, 20-year-old flaw affecting Microsoft Office to deploy an array of commodity remote access trojans (RATs) that allow the …

Popular NPM Package Hijacked to Publish Crypto-mining Malware

Blog WriterThe Hacker News - Original news source is thehackernews.com

The U.S. Cybersecurity and Infrastructure Security Agency on Friday warned of crypto-mining malware embedded in “UAParser.js,” a popular JavaScript NPM library with over 6 million weekly downloads, days after the NPM repository …

Hackers Set Up Fake Company to Get IT Experts to Launch Ransomware Attacks

Blog WriterThe Hacker News - Original news source is thehackernews.com

The financially motivated FIN7 cybercrime gang has masqueraded as yet another fictitious cybersecurity company called “Bastion Secure” to recruit unwitting software engineers under the guise of penetration testing in a …