FreshRSS

๐Ÿ”’
โŒ Secure Planet Training Courses Updated For 2019 - Click Here
There are new available articles, click to refresh the page.
โ˜ โ˜† โœ‡ The Hacker News

Two Spyware Apps on Google Play with 1.5 Million Users Sending Data to China

By: Swati Khandelwal โ€” July 8th 2023 at 07:45
Two file management apps on the Google Play Store have been discovered to be spyware, putting the privacy and security of up to 1.5 million Android users at risk. These apps engage in deceptive behaviour and secretly send sensitive user data to malicious servers in China. Pradeo, a leading mobile security company, has uncovered this alarming infiltration. The report shows that both spyware apps,
โ˜ โ˜† โœ‡ The Hacker News

Vishing Goes High-Tech: New 'Letscall' Malware Employs Voice Traffic Routing

By: Swati Khandelwal โ€” July 7th 2023 at 18:12
Researchers have issued a warning about an emerging and advanced form of voice phishing (vishing) known as "Letscall." This technique is currently targeting individuals in South Korea. The criminals behind "Letscall" employ a multi-step attack to deceive victims into downloading malicious apps from a counterfeit Google Play Store website. Once the malicious software is installed, it redirects
โ˜ โ˜† โœ‡ The Hacker News

Another Critical Unauthenticated SQLi Flaw Discovered in MOVEit Transfer Software

By: Swati Khandelwal โ€” July 7th 2023 at 14:01
Progress Software has announced the discovery and patching of a critical SQL injection vulnerability in MOVEit Transfer, popular software used for secure file transfer. In addition, Progress Software has patched two other high-severity vulnerabilities. The identified SQL injection vulnerability, tagged as CVE-2023-36934, could potentially allow unauthenticated attackers to gain unauthorized
โ˜ โ˜† โœ‡ The Hacker News

Mastodon Social Network Patches Critical Flaws Allowing Server Takeover

By: Swati Khandelwal โ€” July 7th 2023 at 12:55
Mastodon, a popular decentralized social network, has released a security update to fix critical vulnerabilities that could expose millions of users to potential attacks. Mastodon is known for its federated model, consisting of thousands of separate servers called "instances," and it has over 14 million users across more than 20,000 instances. The most critical vulnerability, CVE-2023-36460,
โ˜ โ˜† โœ‡ The Hacker News

BlackByte 2.0 Ransomware: Infiltrate, Encrypt, and Extort in Just 5 Days

By: Swati Khandelwal โ€” July 7th 2023 at 10:20
Ransomware attacks are a major problem for organizations everywhere, and the severity of this problem continues to intensify. Recently, Microsoft's Incident Response team investigated the BlackByte 2.0 ransomware attacks and exposed these cyber strikes' terrifying velocity and damaging nature. The findings indicate that hackers can complete the entire attack process, from gaining initial access
โ˜ โ˜† โœ‡ The Hacker News

Google Releases Android Patch Update for 3 Actively Exploited Vulnerabilities

By: Swati Khandelwal โ€” July 7th 2023 at 07:24
Google has released its monthly security updates for the Android operating system, addressing 46 new software vulnerabilities. Among these, three vulnerabilities have been identified as actively exploited in targeted attacks. One of the vulnerabilities tracked as CVE-2023-26083 is a memory leak flaw affecting the Arm Mali GPU driver for Bifrost, Avalon, and Valhall chips. This particular
โ˜ โ˜† โœ‡ The Hacker News

JumpCloud Resets API Keys Amid Ongoing Cybersecurity Incident

By: Swati Khandelwal โ€” July 7th 2023 at 06:17
JumpCloud, a provider of cloud-based identity and access management solutions, has swiftly reacted to an ongoing cybersecurity incident that impacted some of its clients. As part of its damage control efforts, JumpCloud has reset the application programming interface (API) keys of all customers affected by this event, aiming to protect their valuable data. The company has informed the concerned
โ˜ โ˜† โœ‡ The Hacker News

Cybersecurity Agencies Sound Alarm on Rising TrueBot Malware Attacks

By: Swati Khandelwal โ€” July 7th 2023 at 05:12
Cybersecurity agencies have warned about the emergence of new variants of the TrueBot malware. This enhanced threat is now targeting companies in the U.S. and Canada with the intention of extracting confidential data from infiltrated systems. These sophisticated attacks exploit a critical vulnerability (CVE-2022-31199) in the widely used Netwrix Auditor server and its associated agents. This
โŒ