Author: Admin
October 2, 2024Hacker newsSupply Chain Attack / Cryptocurrency A new set of malicious packages was discovered in the Python Package Index (PyPI) repository, which masqueraded as cryptocurrency wallet recovery and management services with the sole purpose of exfiltrating sensitive data and facilitating the theft of valuable digital assets. “The attack targeted users of Atomic, Trust Wallet, Metamask, Ronin, TronLink, Exodus and other prominent wallets in the crypto ecosystem,” said Checkmarx researcher Yehuda Gelb. said in Tuesday’s analysis. “Positioning themselves as utilities for extracting mnemonic phrases and decrypting wallet data, these packages appeared to offer valuable functionality for cryptocurrency users involved…
Researchers are sounding the alarm about active attacks using a critical flaw in Zimbra Postjournal
October 2, 2024Hacker newsEmail Security / Vulnerability Cybersecurity researchers are warning of active exploit attempts targeting a newly discovered security flaw in Synacor’s Zimbra Collaboration. Enterprise security firm Proofpoint said it began monitoring activity on September 28, 2024. The attacks aimed to use CVE-2024-45519a serious security flaw in the postjournal service that could allow unauthenticated attackers to execute arbitrary commands on compromised Zimbra installations. “Gmail spoofed emails were sent to fake addresses in CC fields in an attempt by Zimbra servers to parse and execute them as commands” – Proofpoint said in a series of messages on X. “Addresses contained…
The threat actors behind the Rhadamanthys data stealer have added new advanced features to the malware, including the use of artificial intelligence (AI) for optical character recognition (OCR) in so-called “open phrase pattern recognition.” “This allows Rhadamanthys to extract cryptocurrency wallet seed phrases from images, making it a very strong threat to those dealing with cryptocurrencies.” – Recorded Future’s Insikt Group said in the analysis of version 0.7.0 of the malware. “The malware can recognize images of initial phrases on the client side and send them back to the control server (C2) for further use.” First found in the wild…
October 1, 2024Hacker newsGenerative artificial intelligence / Data protection Since its inception, Generative AI has revolutionized enterprise productivity. GenAI tools enable faster and more efficient software development, financial analysis, business planning and customer engagement. However, such agility in business is associated with significant risks, in particular with the possibility of leakage of confidential data. As organizations try to balance productivity gains with security concerns, many are forced to choose between the unrestricted use of GenAI and its complete ban. A new LayerX e-guide titled 5 effective measures to prevent data leakage through generative artificial intelligence tools designed to help organizations…
Free Sniper Dz Phishing Tools Trigger Over 140,000 Cyber Attacks Targeting User Credentials
In the past year, more than 140,000 phishing sites linked to a phishing-as-a-service (PhaaS) platform called Sniper Dz have been discovered, indicating that it is being used by a large number of cybercriminals to steal credentials. “For would-be phishers, Sniper Dz offers an online admin panel with a directory of phishing pages,” Palo Alto Networks Unit 42 researchers Shehroz Faruqi, Howard Tong, and Alex Starov said in the technical report. “Phishers can either host these phishing pages on infrastructure owned by Sniper Dz or download Sniper Dz phishing templates to host on their own servers.” Perhaps even more profitable is…
Cybersecurity researchers have discovered a new hacking campaign targeting the Docker Engine API to co-opt instances to join a malicious Docker Swarm controlled by a threat actor. This allowed attackers to “exploit Docker Swarm’s orchestration features for command and control (C2) purposes,” Datadog researchers Matt Muir and Andy Gearon said in the analysis. Levers of attack Docker for initial access to deploy a cryptocurrency miner on the cracked containers, and to obtain and execute additional payloads responsible for doing lateral push to linked hosts running Docker, Kubernetes, or SSH. In particular, this involves identifying unauthenticated and exposed Docker API endpoints…
October 1, 2024Ravi LakshmananCorporate Security / Financial Fraud The US Department of Justice (DoJ) has charged a 39-year-old British national with running a trade fraud scheme that netted him nearly $3.75 million in illegal profits. Robert Westbrook, of London, was arrested last week and is expected to be extradited to the U.S. to face charges of securities fraud, wire fraud and five counts of computer fraud. According to court documents, Westbrook allegedly ran a fraudulent scheme between January 2019 and May 2020 that allowed him to gain millions by gaining unauthorized access to Microsoft 365 accounts belonging to corporate executives.…
September 30, 2024Ravi LakshmananCyber Security / Weekly Summary Hold on to your hats folks, because the world of cyber security is far from quiet! We dodged a bullet last week when we discovered vulnerabilities in CUPS that could open the door to remote attacks. Google’s move to Rust is yielding big results by addressing memory-related vulnerabilities in Android. But it wasn’t all good news – Kaspersky’s forced exit from the US market left users with more questions than answers. And don’t even get me started on the Kia cars that could be stolen with just a license plate! Let’s unpack…
Six different automatic capacitance sensor (ATG) systems from five manufacturers were found to have critical security vulnerabilities that could expose them to remote attacks. “These vulnerabilities pose a significant real-world risk as they can be exploited by attackers to cause widespread damage, including physical damage, environmental hazards, and economic losses,” Bitsight researcher Pedro Umbelino said in a report published last week. To make matters worse, the analysis found that thousands of ATGs are exposed to the Internet, making them a lucrative target for attackers looking to launch disruptive and disruptive attacks on gas stations, hospitals, airports, military bases and other…
Meta has been fined 91 million euros for storing millions of Facebook and Instagram passwords in public
September 30, 2024Ravi LakshmananGDPR / data privacy Ireland’s Data Protection Commission (DPC) fined Meta €91 million ($101.56 million) as part of an investigation into a security breach in March 2019, when the company revealed it had mistakenly stored user passwords in clear text on its systems. investigation, DPC is started next month found that the social media giant violated four different articles of the European Union’s General Data Protection Regulation (GDPR). To that end, the DPC accused Meta of failing to notify the DPC of the data breach in a timely manner, to document the breach of personal data relating…