Another Israeli Firm, QuaDream, Caught Weaponizing iPhone Bug for Spyware

Blog WriterThe Hacker News - Original news source is thehackernews.com

A now-patched security vulnerability in Apple iOS that was previously found to be exploited by Israeli company NSO Group was also separately weaponized by a different surveillance vendor named QuaDream …

New SEO Poisoning Campaign Distributing Trojanized Versions of Popular Software

Blog WriterThe Hacker News - Original news source is thehackernews.com

An ongoing search engine optimization (SEO) poisoning attack campaign has been observed abusing trust in legitimate software utilities to trick users into downloading BATLOADER malware on compromised machines. “The threat …

Critical Flaws Discovered in Cisco Small Business RV Series Routers

Blog WriterThe Hacker News - Original news source is thehackernews.com

Cisco has patched multiple critical security vulnerabilities impacting its RV Series routers that could be weaponized to elevate privileges and execute arbitrary code on affected systems, while also warning of the existence …

Hackers Exploited 0-Day Vulnerability in Zimbra Email Platform to Spy on Users

Blog WriterThe Hacker News - Original news source is thehackernews.com

A threat actor, likely Chinese in origin, is actively attempting to exploit a zero-day vulnerability in the Zimbra open-source email platform as part of spear-phishing campaigns that commenced in December …

CISA Warns of Critical Vulnerabilities Discovered in Airspan Networks Mimosa

Blog WriterThe Hacker News - Original news source is thehackernews.com

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Thursday published an Industrial Controls Systems Advisory (ICSA) warning of multiple vulnerabilities in the Airspan Networks Mimosa equipment that could be …

Dozens of Security Flaws Discovered in UEFI Firmware Used by Several Vendors

Blog WriterThe Hacker News - Original news source is thehackernews.com

As many as 23 new high severity security vulnerabilities have been disclosed in different implementations of Unified Extensible Firmware Interface (UEFI) firmware used by numerous vendors, including Bull Atos, Fujitsu, …

Hacker Group ‘Moses Staff’ Using New StrifeWater RAT in Ransomware Attacks

Blog WriterThe Hacker News - Original news source is thehackernews.com

A politically motivated hacker group tied to a series of espionage and sabotage attacks on Israeli entities in 2021 incorporated a previously undocumented remote access trojan (RAT) that masquerades the …

Iranian Hackers Using New PowerShell Backdoor in Cyber Espionage Attacks

Blog WriterThe Hacker News - Original news source is thehackernews.com

An advanced persistent threat group with links to Iran has updated its malware toolset to include a novel PowerShell-based implant called PowerLess Backdoor, according to new research published by Cybereason. …