New Local Attack Vector Expands the Attack Surface of Log4j Vulnerability

Blog WriterThe Hacker News - Original news source is thehackernews.com

Cybersecurity researchers have discovered an entirely new attack vector that enables adversaries to exploit the Log4Shell vulnerability on servers locally by using a JavaScript WebSocket connection. “This newly-discovered attack vector …

New PseudoManuscrypt Malware Infected Over 35,000 Computers in 2021

Blog WriterThe Hacker News - Original news source is thehackernews.com

Industrial and government organizations, including enterprises in the military-industrial complex and research laboratories, are the targets of a new malware botnet dubbed PseudoManyscrypt that has infected roughly 35,000 Windows computers this year …

Facebook Bans 7 ‘Cyber Mercenary’ Companies for Spying on 50,000 Users

Blog WriterThe Hacker News - Original news source is thehackernews.com

Meta Platforms on Thursday revealed it took steps to deplatform seven cyber mercenaries that it said carried out “indiscriminate” targeting of journalists, dissidents, critics of authoritarian regimes, families of opposition, …

Researchers Uncover New Coexistence Attacks On Wi-Fi and Bluetooth Chips

Blog WriterThe Hacker News - Original news source is thehackernews.com

Cybersecurity researchers have demonstrated a new attack technique that makes it possible to leverage a device’s Bluetooth component to directly extract network passwords and manipulate traffic on a Wi-Fi chip, …

New Phorpiex Botnet Variant Steals Half a Million Dollars in Cryptocurrency

Blog WriterThe Hacker News - Original news source is thehackernews.com

Cryptocurrency users in Ethiopia, Nigeria, India, Guatemala, and the Philippines are being targeted by a new variant of the Phorpiex botnet called Twizt that has resulted in the theft of virtual coins …

New Fileless Malware Uses Windows Registry as Storage to Evade Detection

Blog WriterThe Hacker News - Original news source is thehackernews.com

A new JavaScript-based remote access Trojan (RAT) propagated via a social engineering campaign has been observed employing sneaky “fileless” techniques as part of its detection-evasion methods to elude discovery and …

Hackers Begin Exploiting Second Log4j Vulnerability as a Third Flaw Emerges

Blog WriterThe Hacker News - Original news source is thehackernews.com

Web infrastructure company Cloudflare on Wednesday revealed that threat actors are actively attempting to exploit a second bug disclosed in the widely used Log4j logging utility, making it imperative that customers move …

Facebook to Pay Hackers for Reporting Data Scraping Bugs and Scraped Datasets

Blog WriterThe Hacker News - Original news source is thehackernews.com

Meta Platforms, the company formerly known as Facebook, has announced that it’s expanding its bug bounty program to start rewarding valid reports of scraping vulnerabilities across its platforms as well as include …