Ukraine Secret Service Arrests Hacker Helping Russian Invaders

Blog WriterThe Hacker News - Original news source is thehackernews.com

The Security Service of Ukraine (SBU) said it has detained a “hacker” who offered technical assistance to the invading Russian troops by providing mobile communication services inside the Ukrainian territory. …

TrickBot Malware Abusing MikroTik Routers as Proxies for Command-and-Control

Blog WriterThe Hacker News - Original news source is thehackernews.com

Microsoft on Wednesday detailed a previously undiscovered technique put to use by the TrickBot malware that involves using compromised Internet of Things (IoT) devices as a go-between for establishing communications …

German Government Warns Against Using Russia’s Kaspersky Antivirus Software

Blog WriterThe Hacker News - Original news source is thehackernews.com

Russian cybersecurity firm Kaspersky on Tuesday responded to an advisory released by Germany’s Federal Office of Information Security (BSI) against using the company’s security solutions in the country over “doubts …

Unpatched RCE Bug in dompdf Project Affects HTML to PDF Converters

Blog WriterThe Hacker News - Original news source is thehackernews.com

Researchers have disclosed an unpatched security vulnerability in “dompdf,” a PHP-based HTML to PDF converter, that, if successfully exploited, could lead to remote code execution in certain configurations. “By injecting …

FBI, CISA Warn of Russian Hackers Exploiting MFA and PrintNightmare Bug

Blog WriterThe Hacker News - Original news source is thehackernews.com

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) and the Federal Bureau of Investigation (FBI) have released a joint advisory warning that Russia-backed threat actors hacked the network of an …

New Infinite Loop Bug in OpenSSL Could Let Attackers Crash Remote Servers

Blog WriterThe Hacker News - Original news source is thehackernews.com

The maintainers of OpenSSL have shipped patches to resolve a high-severity security flaw in its software library that could lead to a denial-of-service (DoS) condition when parsing certificates. Tracked as CVE-2022-0778 (CVSS score: 7.5), …

Multiple Flaws Uncovered in ClickHouse OLAP Database System for Big Data

Blog WriterThe Hacker News - Original news source is thehackernews.com

Researchers have disclosed seven new security vulnerabilities in an open-source database management system solution called ClickHouse that could be weaponized to crash the servers, leak memory contents, and even lead …