Dozens of STARTTLS Related Flaws Found Affecting Popular Email Clients

Blog WriterThe Hacker News - Original news source is thehackernews.com

Security researchers have disclosed as many as 40 different vulnerabilities associated with an opportunistic encryption mechanism in mail clients and servers that could open the door to targeted man-in-the-middle (MitM) …

New Glowworm Attack Recovers Device’s Sound from Its LED Power Indicator

Blog WriterThe Hacker News - Original news source is thehackernews.com

A novel technique leverages optical emanations from a device’s power indicator LED to recover sounds from connected peripherals and spy on electronic conversations from a distance of as much as …

Facebook Adds End-to-End Encryption for Audio and Video Calls in Messenger

Blog WriterThe Hacker News - Original news source is thehackernews.com

Facebook on Friday said it’s extending end-to-end encryption (E2EE) for voice and video calls in Messenger, along with testing a new opt-in setting that will turn on end-to-end encryption for …

Hackers Spotted Using Morse Code in Phishing Attacks to Evade Detection

Blog WriterThe Hacker News - Original news source is thehackernews.com

Microsoft has disclosed details of an evasive year-long social engineering campaign wherein the operators kept changing their obfuscation and encryption mechanisms every 37 days on average, including relying on Morse …

Hackers Actively Searching for Unpatched Microsoft Exchange Servers

Blog WriterThe Hacker News - Original news source is thehackernews.com

Threat actors are actively carrying out opportunistic scanning and exploitation of Exchange servers using a new exploit chain leveraging a trio of flaws affecting on-premises installations, making them the latest set of bugs after …

Experts Shed Light On New Russian Malware-as-a-Service Written in Rust

Blog WriterThe Hacker News - Original news source is thehackernews.com

A nascent information-stealing malware sold and distributed on underground Russian underground forums has been written in Rust, signalling a new trend where threat actors are increasingly adopting exotic programming languages to bypass …

Ransomware Gangs Exploiting Windows Print Spooler Vulnerabilities

Blog WriterThe Hacker News - Original news source is thehackernews.com

Ransomware operators such as Magniber and Vice Society are actively exploiting vulnerabilities in Windows Print Spooler to compromise victims and spread laterally across a victim’s network to deploy file-encrypting payloads …