Mēris Botnet Hit Russia’s Yandex With Massive 22 Million RPS DDoS Attack

Blog WriterThe Hacker News - Original news source is thehackernews.com

Russian internet giant Yandex has been the target of a record-breaking distributed denial-of-service (DDoS) attack by a new botnet called Mēris. The botnet is believed to have pummeled the company’s …

Experts Link Sidewalk Malware Attacks to Grayfly Chinese Hacker Group

Blog WriterThe Hacker News - Original news source is thehackernews.com

A previously undocumented backdoor that was recently found targeting an unnamed computer retail company based in the U.S. has been linked to a longstanding Chinese espionage operation dubbed Grayfly. In …

Microsoft Warns of Cross-Account Takeover Bug in Azure Container Instances

Blog WriterThe Hacker News - Original news source is thehackernews.com

Microsoft on Wednesday said it remediated a vulnerability in its Azure Container Instances (ACI) services that could have been weaponized by a malicious actor “to access other customers’ information” in what …

Russian Ransomware Group REvil Back Online After 2-Month Hiatus

Blog WriterThe Hacker News - Original news source is thehackernews.com

The operators behind the REvil ransomware-as-a-service (RaaS) staged a surprise return after a two-month hiatus following the widely publicized attack on technology services provider Kaseya on July 4. Two of the dark …

Hackers Leak VPN Account Passwords From 87,000 Fortinet FortiGate Devices

Blog WriterThe Hacker News - Original news source is thehackernews.com

Network security solutions provider Fortinet confirmed that a malicious actor had unauthorizedly disclosed VPN login names and passwords associated with 87,000 FortiGate SSL-VPN devices. “These credentials were obtained from systems …

CISA Warns of Actively Exploited Zoho ManageEngine ADSelfService Vulnerability

Blog WriterThe Hacker News - Original news source is thehackernews.com

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday issued a bulletin warning of a zero-day flaw affecting Zoho ManageEngine ADSelfService Plus deployments that is currently being actively exploited …

HAProxy Found Vulnerable to Critical HTTP Request Smuggling Attack

Blog WriterThe Hacker News - Original news source is thehackernews.com

A critical security vulnerability has been disclosed in HAProxy, a widely used open-source load balancer and proxy server, that could be abused by an adversary to possibly smuggle HTTP requests, resulting …