U.S. Cyber Command Warns of Ongoing Attacks Exploiting Atlassian Confluence Flaw

Blog WriterThe Hacker News - Original news source is thehackernews.com

The U.S. Cyber Command on Friday warned of ongoing mass exploitation attempts in the wild targeting a now-patched critical security vulnerability affecting Atlassian Confluence deployments that could be abused by …

Cisco Issues Patch for Critical Enterprise NFVIS Flaw — PoC Exploit Available

Blog WriterThe Hacker News - Original news source is thehackernews.com

Cisco has patched a critical security vulnerability impacting its Enterprise Network Function Virtualization Infrastructure Software (NFVIS) that could be exploited by an attacker to take control of an affected system. …

FIN7 Hackers Using Windows 11 Themed Documents to Drop Javascript Backdoor

Blog WriterThe Hacker News - Original news source is thehackernews.com

A recent wave of spear-phishing campaigns leveraged weaponized Windows 11 Alpha-themed Word documents with Visual Basic macros to drop malicious payloads, including a JavaScript implant, against a point-of-sale (PoS) service …

New BrakTooth Flaws Leave Millions of Bluetooth-enabled Devices Vulnerable

Blog WriterThe Hacker News - Original news source is thehackernews.com

A set of new security vulnerabilities has been disclosed in commercial Bluetooth stacks that could enable an adversary to execute arbitrary code and, worse, crash the devices via denial-of-service (DoS) …

WhatsApp Photo Filter Bug Could Have Exposed Your Data to Remote Attackers

Blog WriterThe Hacker News - Original news source is thehackernews.com

A now-patched high-severity security vulnerability in WhatApp’s image filter feature could have been abused to send a malicious image over the messaging app to read sensitive information from the app’s …

Is Traffic Mirroring for NDR Worth the Trouble? We Argue It Isn’t

Blog WriterThe Hacker News - Original news source is thehackernews.com

Network Detection & Response (NDR) is an emerging technology developed to close the blind security spots left by conventional security solutions, which hackers exploited to gain a foothold in target …

FTC Bans Stalkerware App SpyFone; Orders Company to Erase Secretly Stolen Data

Blog WriterThe Hacker News - Original news source is thehackernews.com

The U.S. Federal Trade Commission on Wednesday banned a stalkerware app company called SpyFone from the surveillance business over concerns that it stealthily harvested and shared data on people’s physical …

Cybercriminals Abusing Internet-Sharing Services to Monetize Malware Campaigns

Blog WriterThe Hacker News - Original news source is thehackernews.com

Threat actors are capitalizing on the growing popularity of proxyware platforms like Honeygain and Nanowire to monetize their own malware campaigns, once again illustrating how attackers are quick to repurpose and …