A New Bug in Siemens PLCs Could Let Hackers Run Malicious Code Remotely

Blog WriterThe Hacker News - Original news source is thehackernews.com

Siemens on Friday shipped firmware updates to address a severe vulnerability in SIMATIC S7-1200 and S7-1500 programmable logic controllers (PLCs) that could be exploited by a malicious actor to remotely …

Researchers Demonstrate 2 New Hacks to Modify Certified PDF Documents

Blog WriterThe Hacker News - Original news source is thehackernews.com

Cybersecurity researchers have disclosed two new attack techniques on certified PDF documents that could potentially enable an attacker to alter a document’s visible content by displaying malicious content over the …

SolarWinds Hackers Target Think Tanks With New ‘NativeZone’ Backdoor

Blog WriterThe Hacker News - Original news source is thehackernews.com

Microsoft on Thursday disclosed that the threat actor behind the SolarWinds supply chain hack returned to the threat landscape to target government agencies, think tanks, consultants, and non-governmental organizations located across 24 …

Researchers Warn of Facefish Backdoor Spreading Linux Rootkits

Blog WriterThe Hacker News - Original news source is thehackernews.com

Cybersecurity researchers have disclosed a new backdoor program capable of stealing user login credentials, device information and executing arbitrary commands on Linux systems. The malware dropper has been dubbed “Facefish” …

Malvertising Campaign On Google Distributed Trojanized AnyDesk Installer

Blog WriterThe Hacker News - Original news source is thehackernews.com

Cybersecurity researchers on Wednesday publicized the disruption of a “clever” malvertising network targeting AnyDesk that delivered a weaponized installer of the remote desktop software via rogue Google ads that appeared …

Chinese Cyber Espionage Hackers Continue to Target Pulse Secure VPN Devices

Blog WriterThe Hacker News - Original news source is thehackernews.com

Cybersecurity researchers from FireEye unmasked additional tactics, techniques, and procedures (TTPs) adopted by Chinese threat actors who were recently found abusing Pulse Secure VPN devices to drop malicious web shells …

Newly Discovered Bugs in VSCode Extensions Could Lead to Supply Chain Attacks

Blog WriterThe Hacker News - Original news source is thehackernews.com

Severe security flaws uncovered in popular Visual Studio Code extensions could enable attackers to compromise local machines as well as build and deployment systems through a developer’s integrated development environment …