Chinese Hackers Spotted Using New UEFI Firmware Implant in Targeted Attacks

Blog WriterThe Hacker News - Original news source is thehackernews.com

A previously undocumented firmware implant deployed to maintain stealthy persistence as part of a targeted espionage campaign has been linked to the Chinese-speaking Winnti advanced persistent threat group (APT41). Kaspersky, …

Critical Bugs in Control Web Panel Expose Linux Servers to RCE Attacks

Blog WriterThe Hacker News - Original news source is thehackernews.com

Researchers have disclosed details of two critical security vulnerabilities in Control Web Panel that could be abused as part of an exploit chain to achieve pre-authenticated remote code execution on …

Interpol Busted 11 Members of Nigerian BEC Cybercrime Gang

Blog WriterThe Hacker News - Original news source is thehackernews.com

A coordinated law enforcement operation has resulted in the arrest of 11 members allegedly belonging to a Nigerian cybercrime gang notorious for perpetrating business email compromise (BEC) attacks targeting more …

Google Details Two Zero-Day Bugs Reported in Zoom Clients and MMR Servers

Blog WriterThe Hacker News - Original news source is thehackernews.com

An exploration of zero-click attack surface for the popular video conferencing solution Zoom has yielded two previously undisclosed security vulnerabilities that could have been exploited to crash the service, execute …

Cisco Issues Patch for Critical RCE Vulnerability in RCM for StarOS Software

Blog WriterThe Hacker News - Original news source is thehackernews.com

Cisco Systems has rolled out fixes for a critical security flaw affecting Redundancy Configuration Manager (RCM) for Cisco StarOS Software that could be weaponized by an unauthenticated, remote attacker to …

DoNot Hacking Team Targeting Government and Military Entities in South Asia

Blog WriterThe Hacker News - Original news source is thehackernews.com

A threat actor with potential links to an Indian cybersecurity company has been nothing if remarkably persistent in its attacks against military organizations based in South Asia, including Bangladesh, Nepal, …

Microsoft: Hackers Exploiting New SolarWinds Serv-U Bug Related to Log4j Attacks

Blog WriterThe Hacker News - Original news source is thehackernews.com

Microsoft on Wednesday disclosed details of a new security vulnerability in SolarWinds Serv-U software that it said was being weaponized by threat actors to propagate attacks leveraging the Log4j flaws …