Dozens of Security Flaws Discovered in UEFI Firmware Used by Several Vendors

Blog WriterThe Hacker News - Original news source is thehackernews.com

As many as 23 new high severity security vulnerabilities have been disclosed in different implementations of Unified Extensible Firmware Interface (UEFI) firmware used by numerous vendors, including Bull Atos, Fujitsu, …

Hacker Group ‘Moses Staff’ Using New StrifeWater RAT in Ransomware Attacks

Blog WriterThe Hacker News - Original news source is thehackernews.com

A politically motivated hacker group tied to a series of espionage and sabotage attacks on Israeli entities in 2021 incorporated a previously undocumented remote access trojan (RAT) that masquerades the …

SolarMarker Malware Uses Novel Techniques to Persist on Hacked Systems

Blog WriterThe Hacker News - Original news source is thehackernews.com

In a sign that threat actors continuously shift tactics and update their defensive measures, the operators of the SolarMarker information stealer and backdoor have been found leveraging stealthy Windows Registry …

Critical Bug Found in WordPress Plugin for Elementor with Over a Million Installations

Blog WriterThe Hacker News - Original news source is thehackernews.com

A WordPress plugin with over one million installs has been found to contain a critical vulnerability that could result in the execution of arbitrary code on compromised websites. The plugin …

Iranian Hackers Using New PowerShell Backdoor in Cyber Espionage Attacks

Blog WriterThe Hacker News - Original news source is thehackernews.com

An advanced persistent threat group with links to Iran has updated its malware toolset to include a novel PowerShell-based implant called PowerLess Backdoor, according to new research published by Cybereason. …

Researchers Uncover New Iranian Hacking Campaign Targeting Turkish Users

Blog WriterThe Hacker News - Original news source is thehackernews.com

Details have emerged about a previously undocumented malware campaign undertaken by the Iranian MuddyWater advanced persistent threat (APT) group targeting Turkish private organizations and governmental institutions. “This campaign utilizes malicious …

Ukraine Continues to Face Cyber Espionage Attacks from Russian Hackers

Blog WriterThe Hacker News - Original news source is thehackernews.com

Cybersecurity researchers on Monday said they uncovered evidence of attempted attacks by a Russia-linked hacking operation targeting a Ukrainian entity in July 2021. Broadcom-owned Symantec, in a new report published …

New Samba Bug Allows Remote Attackers to Execute Arbitrary Code as Root

Blog WriterThe Hacker News - Original news source is thehackernews.com

Samba has issued software updates to address multiple security vulnerabilities that, if successfully exploited, could allow remote attackers to execute arbitrary code with the highest privileges on affected installations. Chief among them …

New SureMDM Vulnerabilities Could Expose Companies to Supply Chain Attacks

Blog WriterThe Hacker News - Original news source is thehackernews.com

A number of security vulnerabilities have been disclosed in 42 Gears’ SureMDM device management solution that could be weaponized by attackers to perform a supply chain compromise against affected organizations. …