Researchers Uncover New Android Spyware With C2 Server Linked to Turla Hackers

Blog WriterThe Hacker News - Original news source is thehackernews.com

An Android spyware application has been spotted masquerading as a “Process Manager” service to stealthily siphon sensitive information stored in the infected devices. Interestingly, the app — that has the …

Experts Shed Light on BlackGuard Infostealer Malware Sold on Russian Hacking Forums

Blog WriterThe Hacker News - Original news source is thehackernews.com

A previously undocumented “sophisticated” information-stealing malware named BlackGuard is being advertised for sale on Russian underground forums for a monthly subscription of $200. “BlackGuard has the capability to steal all …

Brokenwire Hack Could Let Remote Attackers Disrupt Charging for Electric Vehicles

Blog WriterThe Hacker News - Original news source is thehackernews.com

A group of academics from the University of Oxford and Armasuisse S+T has disclosed details of a new attack technique against the popular Combined Charging System (CCS) that could potentially …

Multiple Hacker Groups Capitalizing on Ukraine Conflict for Distributing Malware

Blog WriterThe Hacker News - Original news source is thehackernews.com

At least three different advanced persistent threat (APT) groups from across the world have launched spear-phishing campaigns in mid-March 2022 using the ongoing Russo-Ukrainian war as a lure to distribute …

Beastmode DDoS Botnet Exploiting New TOTOLINK Bugs to Enslave More Routers

Blog WriterThe Hacker News - Original news source is thehackernews.com

A variant of the Mirai botnet called Beastmode has been observed adopting newly disclosed vulnerabilities in TOTOLINK routers between February and March 2022 to infect unpatched devices and expand its …

GitLab Releases Patch for Critical Vulnerability That Could Let Attackers Hijack Accounts

Blog WriterThe Hacker News - Original news source is thehackernews.com

DevOps platform GitLab has released software updates to address a critical security vulnerability that, if potentially exploited, could permit an adversary to seize control of accounts. Tracked as CVE-2022-1162, the issue …

15-Year-Old Bug in PEAR PHP Repository Could’ve Enabled Supply Chain Attacks

Blog WriterThe Hacker News - Original news source is thehackernews.com

A 15-year-old security vulnerability has been disclosed in the PEAR PHP repository that could permit an attacker to carry out a supply chain attack, including obtaining unauthorized access to publish …

Chinese Hackers Target VMware Horizon Servers with Log4Shell to Deploy Rootkit

Blog WriterThe Hacker News - Original news source is thehackernews.com

A Chinese advanced persistent threat tracked as Deep Panda has been observed exploiting the Log4Shell vulnerability in VMware Horizon servers to deploy a backdoor and a novel rootkit on infected machines with …

Critical Bugs in Rockwell PLC Could Allow Hackers to Implant Malicious Code

Blog WriterThe Hacker News - Original news source is thehackernews.com

Two new security vulnerabilities have been disclosed in Rockwell Automation’s programmable logic controllers (PLCs) and engineering workstation software that could be exploited by an attacker to inject malicious code on …