Security News

UK and South Korea: Hackers use zero-day in supply-chain attack
2023-11-24 17:28

The attack started with compromising a media outlet's website to embed malicious scripts into an article, allowing for a 'watering hole' attack. State-backed North Korean hacking operations consistently rely on supply chain attacks and the exploitation of zero-day vulnerabilities as part of their cyber warfare tactics.

N. Korean Hackers Distribute Trojanized CyberLink Software in Supply Chain Attack
2023-11-23 05:46

A North Korean state-sponsored threat actor tracked as Diamond Sleet is distributing a trojanized version of a legitimate application developed by a Taiwanese multimedia software developer called...

US nuke reactor lab hit by 'gay furry hackers' demanding cat-human mutants
2023-11-22 21:38

SiegedSec, which also claimed to have breached NATO's IT security on two occasions this year, said it has now hit Idaho National laboratory, which is run by the US Department of Energy's Office of Nuclear Energy. "On Monday, November 20, Idaho National Laboratory determined that it was the target of a cybersecurity data breach in a federally approved vendor system outside the lab that supports INL cloud Human Resources services," spokesperson Lori McNamara told The Register today.

Microsoft: Lazarus hackers breach CyberLink in supply chain attack
2023-11-22 18:06

Microsoft says a North Korean hacking group has breached Taiwanese multimedia software company CyberLink and trojanized one of its installers to push malware in a supply chain attack targeting potential victims worldwide. According to Microsoft Threat Intelligence, activity suspected to be linked with the altered CyberLink installer file surfaced as early as October 20, 2023.

North Korean Hackers Pose as Job Recruiters and Seekers in Malware Campaigns
2023-11-22 12:14

North Korean threat actors have been linked to two campaigns in which they masquerade as both job recruiters and seekers to distribute malware and obtain unauthorized employment with organizations...

Citrix warns admins to kill NetScaler user sessions to block hackers
2023-11-21 16:36

Citrix reminded admins today that they must take additional measures after patching their NetScaler appliances against the CVE-2023-4966 'Citrix Bleed' vulnerability to secure vulnerable devices against attacks. Kill icaconnection -all kill rdp connection -all kill pcoipConnection -all kill aaa session -all clear lb persistentSessions.

Kinsing Hackers Exploit Apache ActiveMQ Vulnerability to Deploy Linux Rootkits
2023-11-21 10:00

The Kinsing threat actors are actively exploiting a critical security flaw in vulnerable Apache ActiveMQ servers to infect Linux systems with cryptocurrency miners and rootkits. "Once Kinsing...

Mustang Panda Hackers Targets Philippines Government Amid South China Sea Tensions
2023-11-21 06:58

The China-linked Mustang Panda actor has been linked to a cyber attack targeting a Philippines government entity amid rising tensions between the two countries over the disputed South China Sea....

Why Defenders Should Embrace a Hacker Mindset
2023-11-20 11:02

Today’s security leaders must manage a constantly evolving attack surface and a dynamic threat environment due to interconnected devices, cloud services, IoT technologies, and hybrid work...

Russian hackers use Ngrok feature and WinRAR exploit to attack embassies
2023-11-19 16:14

NDSC says that the Russian hackers used a Ngrok free static domain to access the command and control server hosted on their Ngrok instance. A report from Google in October notes that the security issue was exploited by Russian and Chinese state hackers to steal credentials and other sensitive data, as well as to establish persistence on target systems.