Critical RCE Flaws in ‘PHP Everywhere’ Plugin Affect Thousands of WordPress Sites

Blog WriterThe Hacker News - Original news source is thehackernews.com

Critical security vulnerabilities have been disclosed in a WordPress plugin known as PHP Everywhere that’s used by more than 30,000 websites worldwide and could be abused by an attacker to …

Guide: Alert Overload and Handling for Lean IT Security Teams

Blog WriterThe Hacker News - Original news source is thehackernews.com

Alarming research reveals the stress and strains the average cybersecurity team experiences on a daily basis. As many as 70% of teams report feeling emotionally overwhelmed by security alerts. Those alerts come …

U.S. Arrests Two and Seizes $3.6 Billion Cryptocurrency Stolen in 2016 Bitfinex Hack

Blog WriterThe Hacker News - Original news source is thehackernews.com

The U.S. Justice Department (DoJ) on Tuesday announced the arrest of a married couple in connection with conspiring to launder cryptocurrency worth $4.5 billion that was siphoned during the hack of the virtual currency …

Russian APT Hackers Used COVID-19 Lures to Target European Diplomats

Blog WriterThe Hacker News - Original news source is thehackernews.com

The Russia-linked threat actor known as APT29 targeted European diplomatic missions and Ministries of Foreign Affairs as part of a series of spear-phishing campaigns mounted in October and November 2021. …

Iranian Hackers Using New Marlin Backdoor in ‘Out to Sea’ Espionage Campaign

Blog WriterThe Hacker News - Original news source is thehackernews.com

An advanced persistent threat (APT) group with ties to Iran has refreshed its malware toolset to include a new backdoor dubbed Marlin as part of a long-running espionage campaign that started in …

Microsoft and Other Major Software Firms Release February 2022 Patch Updates

Blog WriterThe Hacker News - Original news source is thehackernews.com

Microsoft on Tuesday rolled out its monthly security updates with fixes for 51 vulnerabilities across its software line-up consisting of Windows, Office, Teams, Azure Data Explorer, Visual Studio Code, and other components …

Several Malware Families Using Pay-Per-Install Service to Expand Their Targets

Blog WriterThe Hacker News - Original news source is thehackernews.com

A detailed examination of a Pay-per-install (PPI) malware service called PrivateLoader has revealed its crucial role in the delivery of a variety of malware such as SmokeLoader, RedLine Stealer, Vidar, Raccoon, and GCleaner since at least …

Palestinian Hackers Use New NimbleMamba Implant in Recent Attacks

Blog WriterThe Hacker News - Original news source is thehackernews.com

An advanced persistent threat (APT) hacking group operating with motives that likely align with Palestine has embarked on a new campaign that leverages a previously undocumented implant called NimbleMamba. The …

Medusa Android Banking Trojan Spreading Through Flubot’s Attacks Network

Blog WriterThe Hacker News - Original news source is thehackernews.com

Two different Android banking Trojans, FluBot and Medusa, are relying on the same delivery vehicle as part of a simultaneous attack campaign, according to new research published by ThreatFabric. The …