Researchers Trace Widespread Espionage Attacks Back to Chinese ‘Cicada’ Hackers

Blog WriterThe Hacker News - Original news source is thehackernews.com

A Chinese state-backed advanced persistent threat (APT) group known for singling out Japanese entities has been attributed to a new long-running espionage campaign targeting new geographies, suggesting a “widening” of …

CISA Warns of Active Exploitation of Critical Spring4Shell Vulnerability

Blog WriterThe Hacker News - Original news source is thehackernews.com

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added the recently disclosed remote code execution (RCE) vulnerability affecting the Spring Framework, to its Known Exploited Vulnerabilities Catalog based on “evidence …

Researchers Uncover New Android Spyware With C2 Server Linked to Turla Hackers

Blog WriterThe Hacker News - Original news source is thehackernews.com

An Android spyware application has been spotted masquerading as a “Process Manager” service to stealthily siphon sensitive information stored in the infected devices. Interestingly, the app — that has the …

Experts Shed Light on BlackGuard Infostealer Malware Sold on Russian Hacking Forums

Blog WriterThe Hacker News - Original news source is thehackernews.com

A previously undocumented “sophisticated” information-stealing malware named BlackGuard is being advertised for sale on Russian underground forums for a monthly subscription of $200. “BlackGuard has the capability to steal all …

Brokenwire Hack Could Let Remote Attackers Disrupt Charging for Electric Vehicles

Blog WriterThe Hacker News - Original news source is thehackernews.com

A group of academics from the University of Oxford and Armasuisse S+T has disclosed details of a new attack technique against the popular Combined Charging System (CCS) that could potentially …

Multiple Hacker Groups Capitalizing on Ukraine Conflict for Distributing Malware

Blog WriterThe Hacker News - Original news source is thehackernews.com

At least three different advanced persistent threat (APT) groups from across the world have launched spear-phishing campaigns in mid-March 2022 using the ongoing Russo-Ukrainian war as a lure to distribute …

Beastmode DDoS Botnet Exploiting New TOTOLINK Bugs to Enslave More Routers

Blog WriterThe Hacker News - Original news source is thehackernews.com

A variant of the Mirai botnet called Beastmode has been observed adopting newly disclosed vulnerabilities in TOTOLINK routers between February and March 2022 to infect unpatched devices and expand its …

15-Year-Old Bug in PEAR PHP Repository Could’ve Enabled Supply Chain Attacks

Blog WriterThe Hacker News - Original news source is thehackernews.com

A 15-year-old security vulnerability has been disclosed in the PEAR PHP repository that could permit an attacker to carry out a supply chain attack, including obtaining unauthorized access to publish …

GitLab Releases Patch for Critical Vulnerability That Could Let Attackers Hijack Accounts

Blog WriterThe Hacker News - Original news source is thehackernews.com

DevOps platform GitLab has released software updates to address a critical security vulnerability that, if potentially exploited, could permit an adversary to seize control of accounts. Tracked as CVE-2022-1162, the issue …