DirtyMoe Botnet Gains New Exploits in Wormable Module to Spread Rapidly

Blog WriterThe Hacker News - Original news source is thehackernews.com

The malware known as DirtyMoe has gained new worm-like propagation capabilities that allow it to expand its reach without requiring any user interaction, the latest research has found. “The worming …

New Vulnerability in CRI-O Engine Lets Attackers Escape Kubernetes Containers

Blog WriterThe Hacker News - Original news source is thehackernews.com

A newly disclosed security vulnerability in the Kubernetes container engine CRI-O called cr8escape could be exploited by an attacker to break out of containers and obtain root access to the host. “Invocation …

Ukraine Secret Service Arrests Hacker Helping Russian Invaders

Blog WriterThe Hacker News - Original news source is thehackernews.com

The Security Service of Ukraine (SBU) said it has detained a “hacker” who offered technical assistance to the invading Russian troops by providing mobile communication services inside the Ukrainian territory. …

TrickBot Malware Abusing MikroTik Routers as Proxies for Command-and-Control

Blog WriterThe Hacker News - Original news source is thehackernews.com

Microsoft on Wednesday detailed a previously undiscovered technique put to use by the TrickBot malware that involves using compromised Internet of Things (IoT) devices as a go-between for establishing communications …

German Government Warns Against Using Russia’s Kaspersky Antivirus Software

Blog WriterThe Hacker News - Original news source is thehackernews.com

Russian cybersecurity firm Kaspersky on Tuesday responded to an advisory released by Germany’s Federal Office of Information Security (BSI) against using the company’s security solutions in the country over “doubts …

Unpatched RCE Bug in dompdf Project Affects HTML to PDF Converters

Blog WriterThe Hacker News - Original news source is thehackernews.com

Researchers have disclosed an unpatched security vulnerability in “dompdf,” a PHP-based HTML to PDF converter, that, if successfully exploited, could lead to remote code execution in certain configurations. “By injecting …

FBI, CISA Warn of Russian Hackers Exploiting MFA and PrintNightmare Bug

Blog WriterThe Hacker News - Original news source is thehackernews.com

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) and the Federal Bureau of Investigation (FBI) have released a joint advisory warning that Russia-backed threat actors hacked the network of an …

New Infinite Loop Bug in OpenSSL Could Let Attackers Crash Remote Servers

Blog WriterThe Hacker News - Original news source is thehackernews.com

The maintainers of OpenSSL have shipped patches to resolve a high-severity security flaw in its software library that could lead to a denial-of-service (DoS) condition when parsing certificates. Tracked as CVE-2022-0778 (CVSS score: 7.5), …