Atlassian Confluence Flaw Being Used to Deploy Ransomware and Crypto Miners

Blog WriterThe Hacker News - Original news source is thehackernews.com

A recently patched critical security flaw in Atlassian Confluence Server and Data Center products is being actively weaponized in real-world attacks to drop cryptocurrency miners and ransomware payloads. In at …

Researchers Uncover ‘Hermit’ Android Spyware Used in Kazakhstan, Syria, and Italy

Blog WriterThe Hacker News - Original news source is thehackernews.com

An enterprise-grade surveillanceware dubbed Hermit has been put to use by entities operating from within Kazakhstan, Syria, and Italy over the years since 2019, new research has revealed. Lookout attributed …

Critical Flaw in Cisco Secure Email and Web Manager Lets Attackers Bypass Authentication

Blog WriterThe Hacker News - Original news source is thehackernews.com

Ravie Lakshmanan Cisco on Wednesday rolled out fixes to address a critical security flaw affecting Email Security Appliance (ESA) and Secure Email and Web Manager that could be exploited by …

New Hertzbleed Side Channel Attack Affects All Modern AMD and Intel CPUs

Blog WriterThe Hacker News - Original news source is thehackernews.com

Ravie Lakshmanan A newly discovered security vulnerability in modern Intel and AMD processors could let remote attackers steal encryption keys via a power side channel attack. Dubbed Hertzbleed by a …

Panchan: A New Golang-based Peer-To-Peer Botnet Targeting Linux Servers

Blog WriterThe Hacker News - Original news source is thehackernews.com

Ravie Lakshmanan A new Golang-based peer-to-peer (P2P) botnet has been spotted actively targeting Linux servers in the education sector since its emergence in March 2022. Dubbed Panchan by Akamai Security …

Cloudflare Saw Record-Breaking DDoS Attack Peaking at 26 Million Request Per Second

Blog WriterThe Hacker News - Original news source is thehackernews.com

Ravie Lakshmanan Cloudflare on Tuesday disclosed that it had acted to prevent a record-setting 26 million request per second (RPS) distributed denial-of-service (DDoS) attack last week, making it the largest …

Technical Details Released for ‘SynLapse’ RCE Vulnerability Reported in Microsoft Azure

Blog WriterThe Hacker News - Original news source is thehackernews.com

Microsoft has incorporated additional improvements to address the recently disclosed SynLapse security vulnerability in order to meet comprehensive tenant isolation requirements in Azure Data Factory and Azure Synapse Pipelines. The …

Patch Tuesday: Microsoft Issues Fix for Actively Exploited ‘Follina’ Vulnerability

Blog WriterThe Hacker News - Original news source is thehackernews.com

Microsoft officially released fixes to address an actively exploited Windows zero-day vulnerability known as Follina as part of its Patch Tuesday updates. Also addressed by the tech giant are 55 …

Unpatched Travis CI API Bug Exposes Thousands of Secret User Access Tokens

Blog WriterThe Hacker News - Original news source is thehackernews.com

June 14, 2022Ravie Lakshmanan An unpatched security issue in the Travis CI API has left tens of thousands of developers’ user tokens exposed to potential attacks, effectively allowing threat actors …