Hackers Exploited MSHTML Flaw to Spy on Government and Defense Targets

Blog WriterThe Hacker News - Original news source is thehackernews.com

Cybersecurity researchers on Tuesday took the wraps off a multi-stage espionage campaign targeting high-ranking government officials overseeing national security policy and individuals in the defense industry in Western Asia. The …

12-Year-Old Polkit Flaw Lets Unprivileged Linux Users Gain Root Access

Blog WriterThe Hacker News - Original news source is thehackernews.com

A 12-year-old security vulnerability has been disclosed in a system utility called Polkit that grants attackers root privileges on Linux systems, even as a proof-of-concept (PoC) exploit has emerged in …

TrickBot Malware Using New Techniques to Evade Web Injection Attacks

Blog WriterThe Hacker News - Original news source is thehackernews.com

The cybercrime operators behind the notorious TrickBot malware have once again upped the ante by fine-tuning its techniques by adding multiple layers of defense to slip past antimalware products. “As …

Hackers Infect macOS with New DazzleSpy Backdoor in Watering-Hole Attacks

Blog WriterThe Hacker News - Original news source is thehackernews.com

A previously undocumented cyber-espionage malware aimed at Apple’s macOS operating system leveraged a Safari web browser exploit as part of a watering hole attack targeting politically active, pro-democracy individuals in …

Hackers Using New Malware Packer DTPacker to Avoid Analysis, Detection

Blog WriterThe Hacker News - Original news source is thehackernews.com

A previously undocumented malware packer named DTPacker has been observed distributing multiple remote access trojans (RATs) and information stealers such as Agent Tesla, Ave Maria, AsyncRAT, and FormBook to plunder information and …

Emotet Now Using Unconventional IP Address Formats to Evade Detection

Blog WriterThe Hacker News - Original news source is thehackernews.com

Social engineering campaigns involving the deployment of the Emotet malware botnet have been observed using “unconventional” IP address formats for the first time in a bid to sidestep detection by …

Hackers Creating Fraudulent Crypto Tokens as Part of ‘Rug Pull’ Scams

Blog WriterThe Hacker News - Original news source is thehackernews.com

Misconfigurations in smart contracts are being exploited by scammers to create malicious cryptocurrency tokens with the goal of stealing funds from unsuspecting users. The instances of token fraud in the …