Researchers Find Additional Infrastructure Used By SolarWinds Hackers

Blog WriterThe Hacker News - Original news source is thehackernews.com

The sprawling SolarWinds cyberattack which came to light last December was known for its sophistication in the breadth of tactics used to infiltrate and persist in the target infrastructure, so much so …

Hackers Exploit VPN to Deploy SUPERNOVA malware on SolarWinds Orion

Blog WriterThe Hacker News - Original news source is thehackernews.com

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has disclosed details of a new advanced persistent threat (APT) that’s leveraging the Supernova backdoor to compromise SolarWinds Orion installations after gaining …

Cybercriminals Using Telegram Messenger to Control ToxicEye Malware

Blog WriterThe Hacker News - Original news source is thehackernews.com

Adversaries are increasingly abusing Telegram as a “command-and-control” system to distribute malware into organizations that could then be used to capture sensitive information from targeted systems. “Even when Telegram is …

Facebook Busts Palestinian Hackers’ Operation Spreading Mobile Spyware

Blog WriterThe Hacker News - Original news source is thehackernews.com

Facebook on Wednesday said it took steps to dismantle malicious activities perpetrated by two state-sponsored hacking groups operating out of Palestine that abused its platform to distribute malware. The social …

3 Zero-Day Exploits Hit SonicWall Enterprise Email Security Appliances

Blog WriterThe Hacker News - Original news source is thehackernews.com

SonicWall has addressed three critical security vulnerabilities in its hosted and on-premises email security (ES) product that are being actively exploited in the wild. Tracked as CVE-2021-20021 and CVE-2021-20022, the flaws were …

WARNING: Hackers Exploit Unpatched Pulse Secure 0-Day to Breach Organizations

Blog WriterThe Hacker News - Original news source is thehackernews.com

If the Pulse Connect Secure gateway is part of your organization network, you need to be aware of a newly discovered critical zero-day authentication bypass vulnerability (CVE-2021-22893) that is currently …