Hackers‌ ‌Actively‌ ‌Exploiting‌ ‌0-Day‌ ‌in WordPress Plugin Installed on Over ‌17,000‌ ‌Sites

Blog WriterThe Hacker News - Original news source is thehackernews.com

Fancy Product Designer, a WordPress plugin installed on over 17,000 sites, has been discovered to contain a critical file upload vulnerability that’s being actively exploited in the wild to upload …

US Seizes Domains Used by SolarWinds Hackers in Cyber Espionage Attacks

Blog WriterThe Hacker News - Original news source is thehackernews.com

Days after Microsoft, Secureworks, and Volexity shed light on a new spear-phishing activity unleashed by the Russian hackers who breached SolarWinds IT management software, the U.S. Department of Justice (DoJ) Tuesday said it intervened …

Malware Can Use This Trick to Bypass Ransomware Defense in Antivirus Solutions

Blog WriterThe Hacker News - Original news source is thehackernews.com

Researchers have disclosed significant security weaknesses in popular software applications that could be abused to deactivate their protections and take control of allow-listed applications to perform nefarious operations on behalf …

Report: Danish Secret Service Helped NSA Spy On European Politicians

Blog WriterThe Hacker News - Original news source is thehackernews.com

The U.S. National Security Agency (NSA) used a partnership with Denmark’s foreign and military intelligence service to eavesdrop on top politicians and high-ranking officials in Germany, Sweden, Norway, and France …

A New Bug in Siemens PLCs Could Let Hackers Run Malicious Code Remotely

Blog WriterThe Hacker News - Original news source is thehackernews.com

Siemens on Friday shipped firmware updates to address a severe vulnerability in SIMATIC S7-1200 and S7-1500 programmable logic controllers (PLCs) that could be exploited by a malicious actor to remotely …

Researchers Demonstrate 2 New Hacks to Modify Certified PDF Documents

Blog WriterThe Hacker News - Original news source is thehackernews.com

Cybersecurity researchers have disclosed two new attack techniques on certified PDF documents that could potentially enable an attacker to alter a document’s visible content by displaying malicious content over the …

SolarWinds Hackers Target Think Tanks With New ‘NativeZone’ Backdoor

Blog WriterThe Hacker News - Original news source is thehackernews.com

Microsoft on Thursday disclosed that the threat actor behind the SolarWinds supply chain hack returned to the threat landscape to target government agencies, think tanks, consultants, and non-governmental organizations located across 24 …

Researchers Warn of Facefish Backdoor Spreading Linux Rootkits

Blog WriterThe Hacker News - Original news source is thehackernews.com

Cybersecurity researchers have disclosed a new backdoor program capable of stealing user login credentials, device information and executing arbitrary commands on Linux systems. The malware dropper has been dubbed “Facefish” …