Magecart Hackers Hide Stolen Credit Card Data Into Images for Evasive Exfiltration

Blog WriterThe Hacker News - Original news source is thehackernews.com

Cybercrime actors part of the Magecart group have latched on to a new technique of obfuscating the malware code within comment blocks and encoding stolen credit card data into images and other …

Hackers Use New Trick to Disable Macro Security Warnings in Malicious Office Files

Blog WriterThe Hacker News - Original news source is thehackernews.com

While it’s a norm for phishing campaigns that distribute weaponized Microsoft Office documents to prompt victims to enable macros in order to trigger the infection chain directly, new findings indicate …

Experts Uncover Malware Attacks Targeting Corporate Networks in Latin America

Blog WriterThe Hacker News - Original news source is thehackernews.com

Cybersecurity researchers on Thursday took the wraps off a new, ongoing espionage campaign targeting corporate networks in Spanish-speaking countries, specifically Venezuela, to spy on its victims. Dubbed “Bandidos” by ESET …

Critical Flaws Reported in Sage X3 Enterprise Management Software

Blog WriterThe Hacker News - Original news source is thehackernews.com

Four security vulnerabilities have been uncovered in the Sage X3 enterprise resource planning (ERP) product, two of which could be chained together as part of an attack sequence to enable adversaries to …

Security Awareness Training is Broken. Human Risk Management (HRM) is the Fix

Blog WriterThe Hacker News - Original news source is thehackernews.com

Humans are an organization’s strongest defence against evolving cyber threats, but security awareness training alone often isn’t enough to transform user behaviour. In this guide, usecure looks at why Human …

How to Mitigate Microsoft Print Spooler Vulnerability – PrintNightmare

Blog WriterThe Hacker News - Original news source is thehackernews.com

This week, PrintNightmare – Microsoft’s Print Spooler vulnerability (CVE-2021-34527) was upgraded from a ‘Low’ criticality to a ‘Critical’ criticality. This is due to a Proof of Concept published on GitHub, …

Microsoft’s Emergency Patch Fails to Fully Fix PrintNightmare RCE Vulnerability

Blog WriterThe Hacker News - Original news source is thehackernews.com

Even as Microsoft expanded patches for the so-called PrintNightmare vulnerability for Windows 10 version 1607, Windows Server 2012, and Windows Server 2016, it has come to light that the fix for the …