New Azure AD Bug Lets Hackers Brute-Force Passwords Without Getting Caught

Blog WriterThe Hacker News - Original news source is thehackernews.com

Cybersecurity researchers have disclosed an unpatched security vulnerability in the protocol used by Microsoft Azure Active Directory that potential adversaries could abuse to stage undetected brute-force attacks. “This flaw allows …

New Tomiris Backdoor Found Linked to Hackers Behind SolarWinds Cyberattack

Blog WriterThe Hacker News - Original news source is thehackernews.com

Cybersecurity researchers on Wednesday disclosed a previously undocumented backdoor likely designed and developed by the Nobelium advanced persistent threat (APT) behind last year’s SolarWinds supply chain attack, joining the threat actor’s …

Cybersecurity Firm Group-IB’s CEO Arrested Over Treason Charges in Russia

Blog WriterThe Hacker News - Original news source is thehackernews.com

Russian authorities on Wednesday arrested and detained Ilya Sachkov, the founder of cybersecurity firm Group-IB, for two months in Moscow on charges of state treason following a search of its office on …

Facebook Releases New Tool That Finds Security and Privacy Bugs in Android Apps

Blog WriterThe Hacker News - Original news source is thehackernews.com

Facebook on Wednesday announced it’s open-sourcing Mariana Trench, an Android-focused static analysis platform the company uses to detect and prevent security and privacy bugs in applications created for the mobile operating …

Beware! This Android Trojan Stole Millions of Dollars from Over 10 Million Users

Blog WriterThe Hacker News - Original news source is thehackernews.com

A newly discovered “aggressive” mobile campaign has infected north of 10 million users from over 70 countries via seemingly innocuous Android apps that subscribe the individuals to premium services costing …

Hackers Targeting Brazil’s PIX Payment System to Drain Users’ Bank Accounts

Blog WriterThe Hacker News - Original news source is thehackernews.com

Two newly discovered malicious Android applications on Google Play Store have been used to target users of Brazil’s instant payment ecosystem in a likely attempt to lure victims into fraudulently …

New FinSpy Malware Variant Infects Windows Systems With UEFI Bootkit

Blog WriterThe Hacker News - Original news source is thehackernews.com

Commercially developed FinFisher surveillanceware has been upgraded to infect Windows devices using a UEFI (Unified Extensible Firmware Interface) bootkit that leverages a trojanized Windows Boot Manager, marking a shift in infection vectors …