Russian Ransomware Group REvil Back Online After 2-Month Hiatus

Blog WriterThe Hacker News - Original news source is thehackernews.com

The operators behind the REvil ransomware-as-a-service (RaaS) staged a surprise return after a two-month hiatus following the widely publicized attack on technology services provider Kaseya on July 4. Two of the dark …

Hackers Leak VPN Account Passwords From 87,000 Fortinet FortiGate Devices

Blog WriterThe Hacker News - Original news source is thehackernews.com

Network security solutions provider Fortinet confirmed that a malicious actor had unauthorizedly disclosed VPN login names and passwords associated with 87,000 FortiGate SSL-VPN devices. “These credentials were obtained from systems …

CISA Warns of Actively Exploited Zoho ManageEngine ADSelfService Vulnerability

Blog WriterThe Hacker News - Original news source is thehackernews.com

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday issued a bulletin warning of a zero-day flaw affecting Zoho ManageEngine ADSelfService Plus deployments that is currently being actively exploited …

HAProxy Found Vulnerable to Critical HTTP Request Smuggling Attack

Blog WriterThe Hacker News - Original news source is thehackernews.com

A critical security vulnerability has been disclosed in HAProxy, a widely used open-source load balancer and proxy server, that could be abused by an adversary to possibly smuggle HTTP requests, resulting …

Experts Uncover Mobile Spyware Attacks Targeting Kurdish Ethnic Group

Blog WriterThe Hacker News - Original news source is thehackernews.com

Cybersecurity researchers on Tuesday released new findings that reveal a year-long mobile espionage campaign against the Kurdish ethnic group to deploy two Android backdoors that masquerade as legitimate apps. Active …

[Ebook] The Guide for Speeding Time to Response for Lean IT Security Teams

Blog WriterThe Hacker News - Original news source is thehackernews.com

Most cyber security today involves much more planning, and much less reacting than in the past. Security teams spend most of their time preparing their organizations’ defenses and doing operational …

New 0-Day Attack Targeting Windows Users With Microsoft Office Documents

Blog WriterThe Hacker News - Original news source is thehackernews.com

Microsoft on Tuesday warned of an actively exploited zero-day flaw impacting Internet Explorer that’s being used to hijack vulnerable Windows systems by leveraging weaponized Office documents. Tracked as CVE-2021-40444 (CVSS …

Latest Atlassian Confluence Flaw Exploited to Breach Jenkins Project Server

Blog WriterThe Hacker News - Original news source is thehackernews.com

The maintainers of Jenkins—a popular open-source automation server software—have disclosed a security breach after unidentified threat actors gained access to one of their servers by exploiting a recently disclosed vulnerability …