SharkBot Banking Malware Spreading via Fake Android Antivirus App on Google Play Store

Blog WriterThe Hacker News - Original news source is thehackernews.com

The threat actor behind a nascent Android banking trojan named SharkBot has managed to evade Google Play Store security barriers by masquerading as an antivirus app. SharkBot, like its malware counterparts TeaBot, FluBot, and Oscorp (UBEL), …

Ukrainian CERT Warns Citizens of Phishing Attacks Using Compromised Accounts

Blog WriterThe Hacker News - Original news source is thehackernews.com

Ukraine’s Computer Emergency Response Team (CERT-UA) warned of new phishing attacks aimed at its citizens by leveraging compromised email accounts belonging to three different Indian entities with the goal of …

Critical Bugs in TerraMaster TOS Could Open NAS Devices to Remote Hacking

Blog WriterThe Hacker News - Original news source is thehackernews.com

Researchers have disclosed details of critical security vulnerabilities in TerraMaster network-attached storage (TNAS) devices that could be chained to attain unauthenticated remote code execution with the highest privileges. The issues …

2 New Mozilla Firefox 0-Day Bugs Under Active Attack — Patch Your Browser ASAP!

Blog WriterThe Hacker News - Original news source is thehackernews.com

Mozilla has pushed out-of-band software updates to its Firefox web browser to contain two high-impact security vulnerabilities, both of which it says are being actively exploited in the wild. Tracked as CVE-2022-26485 …

New Linux Kernel cgroups Vulnerability Could Let Attackers Escape Container

Blog WriterThe Hacker News - Original news source is thehackernews.com

Details have emerged about a now-patched high-severity vulnerability in the Linux kernel that could potentially be abused to escape a container in order to execute arbitrary commands on the container …

Imperva Thwarts 2.5 Million RPS Ransom DDoS Extortion Attacks

Blog WriterThe Hacker News - Original news source is thehackernews.com

Cybersecurity company Imperva on Friday said it recently mitigated a ransom distributed denial-of-service (DDoS) attack targeting an unnamed website that peaked at 2.5 million requests per second (RPS). “While ransom …

New Security Vulnerability Affects Thousands of Self-Managed GitLab Instances

Blog WriterThe Hacker News - Original news source is thehackernews.com

Researchers have disclosed details of a new security vulnerability in GitLab, an open-source DevOps software, that could potentially allow a remote, unauthenticated attacker to recover user-related information. Tracked as CVE-2021-4191 …

Both Sides in Russia-Ukraine War Heavily Using Telegram for Disinformation and Hacktivism

Blog WriterThe Hacker News - Original news source is thehackernews.com

Cyber criminals and hacktivist groups are increasingly using the Telegram messaging app for their activities, as the Russia-Ukraine conflict enters its eighth day. A new analysis by Israeli cybersecurity company …

CISA Adds Another 95 Flaws to its Actively Exploited Vulnerabilities Catalog

Blog WriterThe Hacker News - Original news source is thehackernews.com

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) this week added 95 more security flaws to its Known Exploited Vulnerabilities Catalog, taking the total number of actively exploited vulnerabilities to 478. “These …