Malware Attack on South Korean Entities Was Work of Andariel Group

Blog WriterThe Hacker News - Original news source is thehackernews.com

A malware campaign targeting South Korean entities that came to light earlier this year has been attributed to a North Korean nation-state hacking group called Andariel, once again indicating that Lazarus attackers …

Ransomware Attackers Partnering With Cybercrime Groups to Hack High-Profile Targets

Blog WriterThe Hacker News - Original news source is thehackernews.com

As ransomware attacks against critical infrastructure skyrocket, new research shows that threat actors behind such disruptions are increasingly shifting from using email messages as an intrusion route to purchasing access …

Critical ThroughTek Flaw Opens Millions of Connected Cameras to Eavesdropping

Blog WriterThe Hacker News - Original news source is thehackernews.com

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday issued an advisory regarding a critical software supply-chain flaw impacting ThroughTek’s software development kit (SDK) that could be abused by …

Experts Shed Light On Distinctive Tactics Used by Hades Ransomware

Blog WriterThe Hacker News - Original news source is thehackernews.com

Cybersecurity researchers on Tuesday disclosed “distinctive” tactics, techniques, and procedures (TTPs) adopted by operators of Hades ransomware that set it apart from the rest of the pack, attributing it to …

Apple Issues Urgent Patches for 2 Zero-Day Flaws Exploited in the Wild

Blog WriterThe Hacker News - Original news source is thehackernews.com

Apple on Monday shipped out-of-band security patches to address two zero-day vulnerabilities in iOS 12.5.3 that it says are being actively exploited in the wild. The latest update, iOS 12.5.4, comes …

Google Workspace Now Offers Client-side Encryption For Drive and Docs

Blog WriterThe Hacker News - Original news source is thehackernews.com

Google on Monday announced that it’s rolling out client-side encryption to Google Workspace (formerly G Suite), thereby giving its enterprise customers direct control of encryption keys and the identity service …

NoxPlayer Supply-Chain Attack is Likely the Work of Gelsemium Hackers

Blog WriterThe Hacker News - Original news source is thehackernews.com

A new cyber espionage group named Gelsemium has been linked to a supply chain attack targeting the NoxPlayer Android emulator that was disclosed earlier this year. The findings come from a systematic …

Cybersecurity Executive Order 2021: What It Means for Cloud and SaaS Security

Blog WriterThe Hacker News - Original news source is thehackernews.com

In response to malicious actors targeting US federal IT systems and their supply chain, the President released the “Executive Order on Improving the Nation’s Cybersecurity (Executive Order).” Although directed at Federal …