New Phorpiex Botnet Variant Steals Half a Million Dollars in Cryptocurrency

Blog WriterThe Hacker News - Original news source is thehackernews.com

Cryptocurrency users in Ethiopia, Nigeria, India, Guatemala, and the Philippines are being targeted by a new variant of the Phorpiex botnet called Twizt that has resulted in the theft of virtual coins …

New Fileless Malware Uses Windows Registry as Storage to Evade Detection

Blog WriterThe Hacker News - Original news source is thehackernews.com

A new JavaScript-based remote access Trojan (RAT) propagated via a social engineering campaign has been observed employing sneaky “fileless” techniques as part of its detection-evasion methods to elude discovery and …

Hackers Begin Exploiting Second Log4j Vulnerability as a Third Flaw Emerges

Blog WriterThe Hacker News - Original news source is thehackernews.com

Web infrastructure company Cloudflare on Wednesday revealed that threat actors are actively attempting to exploit a second bug disclosed in the widely used Log4j logging utility, making it imperative that customers move …

Facebook to Pay Hackers for Reporting Data Scraping Bugs and Scraped Datasets

Blog WriterThe Hacker News - Original news source is thehackernews.com

Meta Platforms, the company formerly known as Facebook, has announced that it’s expanding its bug bounty program to start rewarding valid reports of scraping vulnerabilities across its platforms as well as include …

Hackers Using Malicious IIS Server Module to Steal Microsoft Exchange Credentials

Blog WriterThe Hacker News - Original news source is thehackernews.com

Malicious actors are deploying a previously undiscovered binary, an Internet Information Services (IIS) webserver module dubbed “Owowa,” on Microsoft Exchange Outlook Web Access servers with the goal of stealing credentials …

Cynet’s MDR Offers Organizations Continuous Security Oversight

Blog WriterThe Hacker News - Original news source is thehackernews.com

Today’s cyber attackers are constantly looking for ways to exploit vulnerabilities and infiltrate organizations. To keep up with this evolving threat landscape, security teams must be on the lookout for …

Microsoft Issues Windows Update to Patch 0-Day Used to Spread Emotet Malware

Blog WriterThe Hacker News - Original news source is thehackernews.com

Microsoft has rolled out Patch Tuesday updates to address multiple security vulnerabilities in Windows and other software, including one actively exploited flaw that’s being abused to deliver Emotet, TrickBot, or Bazaloader malware …

Second Log4j Vulnerability (CVE-2021-45046) Discovered — New Patch Released

Blog WriterThe Hacker News - Original news source is thehackernews.com

The Apache Software Foundation (ASF) has pushed out a new fix for the Log4j logging utility after the previous patch for the recently disclosed Log4Shell exploit was deemed as “incomplete in certain …

Hackers Exploit Log4j Vulnerability to Infect Computers with Khonsari Ransomware

Blog WriterThe Hacker News - Original news source is thehackernews.com

Romanian cybersecurity technology company Bitdefender on Monday revealed that attempts are being made to target Windows machines with a novel ransomware family called Khonsari as well as a remote access Trojan named Orcus by …