New Ransomware Variants Flourish Amid Law Enforcement Actions

Blog WriterThe Hacker News - Original news source is thehackernews.com

Ransomware groups continue to evolve their tactics and techniques to deploy file-encrypting malware on compromised systems, notwithstanding law enforcement’s disruptive actions against the cybercrime gangs to prevent them from victimizing …

Expert Details macOS Bug That Could Let Malware Bypass Gatekeeper Security

Blog WriterThe Hacker News - Original news source is thehackernews.com

Apple recently fixed a security vulnerability in the macOS operating system that could be potentially exploited by a threat actor to “trivially and reliably” bypass a “myriad of foundational macOS …

New BLISTER Malware Using Code Signing Certificates to Evade Detection

Blog WriterThe Hacker News - Original news source is thehackernews.com

Cybersecurity researchers have disclosed details of an evasive malware campaign that makes use of valid code signing certificates to sneak past security defenses and stay under the radar with the …

CISA, FBI and NSA Publish Joint Advisory and Scanner for Log4j Vulnerabilities

Blog WriterThe Hacker News - Original news source is thehackernews.com

Cybersecurity agencies from Australia, Canada, New Zealand, the U.S., and the U.K. on Wednesday released a joint advisory in response to widespread exploitation of multiple vulnerabilities in Apache’s Log4j software …

New Exploit Lets Malware Attackers Bypass Patch for Critical Microsoft MSHTML Flaw

Blog WriterThe Hacker News - Original news source is thehackernews.com

A short-lived phishing campaign has been observed taking advantage of a novel exploit that bypassed a patch put in place by Microsoft to fix a remote code execution vulnerability affecting …

China suspends deal with Alibaba for not sharing Log4j 0-day first with the government

Blog WriterThe Hacker News - Original news source is thehackernews.com

China’s internet regulator, the Ministry of Industry and Information Technology (MIIT), has temporarily suspended a partnership with Alibaba Cloud, the cloud computing subsidiary of e-commerce giant Alibaba Group, for six …

Active Directory Bugs Could Let hackers Take Over Windows Domain Controllers

Blog WriterThe Hacker News - Original news source is thehackernews.com

Microsoft is urging customers to patch two security vulnerabilities in Active Directory domain controllers that it addressed in November following the availability of a proof-of-concept (PoC) tool on December 12. The two …