Linux Implementation of Cobalt Strike Beacon Targeting Organizations Worldwide

Blog WriterThe Hacker News - Original news source is thehackernews.com

Researchers on Monday took the wraps off a newly discovered Linux and Windows re-implementation of Cobalt Strike Beacon that’s actively set its sights on government, telecommunications, information technology, and financial institutions in …

Critical Bug Reported in NPM Package With Millions of Downloads Weekly

Blog WriterThe Hacker News - Original news source is thehackernews.com

A widely used NPM package called ‘Pac-Resolver’ for the JavaScript programming language has been remediated with a fix for a high-severity remote code execution vulnerability that could be abused to …

New SpookJS Attack Bypasses Google Chrome’s Site Isolation Protection

Blog WriterThe Hacker News - Original news source is thehackernews.com

A newly discovered side-channel attack demonstrated on modern processors can be weaponized to successfully overcome Site Isolation protections weaved into Google Chrome and Chromium browsers and leak sensitive data in a Spectre-style speculative execution attack. …

Mēris Botnet Hit Russia’s Yandex With Massive 22 Million RPS DDoS Attack

Blog WriterThe Hacker News - Original news source is thehackernews.com

Russian internet giant Yandex has been the target of a record-breaking distributed denial-of-service (DDoS) attack by a new botnet called Mēris. The botnet is believed to have pummeled the company’s …

Experts Link Sidewalk Malware Attacks to Grayfly Chinese Hacker Group

Blog WriterThe Hacker News - Original news source is thehackernews.com

A previously undocumented backdoor that was recently found targeting an unnamed computer retail company based in the U.S. has been linked to a longstanding Chinese espionage operation dubbed Grayfly. In …

Microsoft Warns of Cross-Account Takeover Bug in Azure Container Instances

Blog WriterThe Hacker News - Original news source is thehackernews.com

Microsoft on Wednesday said it remediated a vulnerability in its Azure Container Instances (ACI) services that could have been weaponized by a malicious actor “to access other customers’ information” in what …