Generated by Rank Math SEO, this is an llms.txt file designed to help LLMs better understand and index this website. # FirstHackersNews: Latest cybersecurity news, real attacks, and practical IOCs—made simple and actionable. ## Sitemaps [XML Sitemap](https://firsthackersnews.com/sitemap_index.xml): Includes all crawlable and indexable pages. ## Posts - [ClickFix Malware Targets Crypto Experts via Fake LinkedIn VCs](https://firsthackersnews.com/clickfix-malware-campaign-targets-crypto-web3-professionals/): Security researchers have uncovered a coordinated malware campaign targeting people working in the cryptocurrency and Web3 industry. - [Fake LastPass Support Scam Targets Password Vaults](https://firsthackersnews.com/lastpass-support-phishing-attack/): A new phishing campaign is pretending to be LastPass support emails to trick users into revealing their vault passwords and account credentials. - [OAuth Phishing Campaign Targets Entra ID and Google Workspace](https://firsthackersnews.com/oauth-phishing-campaign-targets-entra-id-and-google-workspace/): Microsoft has discovered advanced phishing campaigns that misuse the normal behavior of the OAuth 2.0 authentication process. - [Chrome Introduces Quantum-Safe HTTPS Protection](https://firsthackersnews.com/chrome-quantum-safe-https-merkle-tree-certificates/): Google Chrome’s security team has announced a new plan to protect HTTPS from future quantum computer attacks. - [MS-Agent Flaw Allows Remote Hijacking of AI Agents](https://firsthackersnews.com/ms-agent-remote-hijacking-vulnerability-cve-2026/): A serious security issue has been found in the MS-Agent framework. The flaw, tracked as CVE-2026-2256, allows attackers to take control of AI agents and potentially the entire system they run on. - [GTFire Phishing Attack Hides Behind Google Services](https://firsthackersnews.com/gtfire-google-phishing-campaign/): GTFire is a newly identified phishing campaign that misuses trusted Google services, including Firebase and Google Translate, to steal user credentials. - [Claude AI Outage Causes Widespread Service Errors](https://firsthackersnews.com/claude-ai-global-outage/): On March 2, 2026, Anthropic’s AI assistant Claude experienced a major global outage that disrupted users and developers worldwide. - [Critical OneUptime Vulnerability Allows Remote System Takeover](https://firsthackersnews.com/oneuptime-command-injection-vulnerability/): A critical security flaw (CVE-2026-27728) has been identified in OneUptime, a service monitoring platform. The issue allows authenticated users to run system-level commands on the Probe server. - [Massive Scanning Campaign Targets SonicWall Firewalls](https://firsthackersnews.com/sonicwall-vpn-scanning-campaign/): Hackers are actively mapping SonicWall firewalls worldwide. In just four days, over 84,000 SonicOS scanning sessions were launched from more than 4,300 unique IP addresses to identify devices with SSL VPN enabled. - [OpenClaw Exploit Compromises Developer AI Agents](https://firsthackersnews.com/openclaw-zero-click-ai-agent-compromise/): OpenClaw, a popular open-source AI assistant with over 100,000 GitHub stars, recently fixed a serious security flaw that allowed malicious websites to silently take control of developer AI agents. - [i6 — Your Business Continuity Partner During the Ongoing Middle East Conflict](https://firsthackersnews.com/business-continuity-middle-east-conflict-bcp-support/): The ongoing Middle East conflict has significantly elevated cyber risk across the region. During periods of geopolitical tension, cyberattacks increase in frequency, coordination, and intent. Organizations across finance, energy, telecom, government, and large enterprises are facing intensified disruption attempts, including DDoS campaigns, ransomware operations, infrastructure targeting, and supply chain exploitation. - [Fake Zoom Update Infects 1,437 in Days](https://firsthackersnews.com/zoom-update-scam-teramind-surveillance-attack/): A new scam is targeting Zoom users by exploiting trust in meeting invitations. - [Hacker Manipulates Claude AI to Steal Government Data](https://firsthackersnews.com/ai-jailbreak-cyberattack-government-data-breach/): A hacker reportedly manipulated Anthropic’s Claude AI to assist in a coordinated cyberattack against Mexican government agencies, exposing how AI tools can be misused in real-world operations. - [Microsoft Detects Malicious Next.js Repos Used in Live Attack Campaigns](https://firsthackersnews.com/microsoft-malicious-nextjs-repositories-attack/): Microsoft says attackers are creating fake Next.js projects to trick developers. These projects look normal and often appear as job assignments or coding tests. But once a developer opens or runs them, hidden code starts executing. - [AI Tools Help Hacker Breach 600+ FortiGate Devices](https://firsthackersnews.com/ai-driven-fortigate-attack-600-devices/): A financially motivated threat actor used commercial generative AI tools to compromise more than 600 FortiGate devices across 55 countries. According to Amazon Threat Intelligence, the activity took place between January 11 and February 18, 2026. - [ZeroDayRAT Turns Mobile Phones into Spy and Theft Tools](https://firsthackersnews.com/zerodayrat-mobile-spyware-android-ios/): ZeroDayRAT is a newly discovered mobile spyware service that targets both Android and iOS devices. Unlike traditional malware that focuses only on spying or financial theft, this tool combines both into a single platform. It allows attackers to monitor victims in real time while also stealing money directly from banking and cryptocurrency apps. - [Google Blocks 1.75 Million Harmful Apps from Play Store in 2025](https://firsthackersnews.com/google-blocks-malicious-apps-2025/): Google says it stopped more than 1.75 million malicious or policy-violating Android apps from reaching users in 2025. Over 80,000 developer accounts were also banned to prevent repeat abuse. - [PayPal Data Exposure: Six Months of User Information Leaked Online](https://firsthackersnews.com/paypal-working-capital-data-exposure-2025/): PayPal has notified a small group of customers about a cybersecurity incident that exposed personal data for almost six months. The issue was traced to a software error in its PayPal Working Capital (PPWC) loan application system, which provides funding to small businesses based on their PayPal sales history. - [Google Fixes Critical Chrome Flaws in PDFium and V8](https://firsthackersnews.com/chrome-critical-update-pdfium-v8-vulnerabilities-2026/): Three Vulnerabilities Could Allow Remote Code Execution - [PromptSpy: Android Malware Uses Google Gemini AI](https://firsthackersnews.com/promptspy/): PromptSpy is a newly discovered Android malware family that uses Google’s Gemini AI model to make real-time decisions on infected devices. - [Microsoft 365 Copilot AI Summary Flaw Exposes Emails](https://firsthackersnews.com/copilot-dlp-bypass-email-summaries/): A security weakness in Microsoft 365 Copilot is allowing the AI assistant to generate summaries of emails that are marked as confidential. This happens even when Data Loss Prevention (DLP) controls are configured to block access to sensitive content. - [Threat Actors Push ClickFix Payload via Browser Cache](https://firsthackersnews.com/clickfix-payload/): Cybersecurity researchers have uncovered a new version of the ‘ClickFix’ social engineering campaign. In this updated attack, malware is hidden directly inside the victim’s browser cache to avoid detection. - [Critical zero-day vulnerability is being actively exploited in Dell RecoverPoint](https://firsthackersnews.com/cve-2026-22769-dell-zero-day/): The flaw, tracked as CVE-2026-22769, has a maximum CVSS score of 10.0 (Critical) and has been exploited since at least mid-2024. - [Cloud Password Managers Expose 25 Security Flaws](https://firsthackersnews.com/cloud-password-managers-25-security-flaws/): Researchers from ETH Zurich have discovered 25 serious security vulnerabilities in three major cloud password managers: Bitwarden, LastPass, and Dashlane. Together, these platforms protect more than 60 million users worldwide. - [Critical Chrome Zero-Day Under Active Exploitation](https://firsthackersnews.com/chrome-cve-2026-2441-zero-day-rce/): Google has released an urgent Chrome update to fix a high-severity vulnerability that is actively being exploited. - [BeyondTrust Flaw Opens the Door to Complete Active Directory Compromise](https://firsthackersnews.com/beyondtrust-cve-2026-1731-active-directory-exploit/): A newly disclosed high-risk vulnerability, tracked as CVE-2026-1731, is impacting self-managed deployments of BeyondTrust Remote Support (RS) and Privileged Remote Access (PRA). The flaw enables attackers to send specially crafted requests that trigger operating system command execution on vulnerable appliances — no login required. In simple terms, a remote attacker can gain code execution on the system without authentication. - [Critical Notepad++ Flaw Allows Code Execution, CISA Issues Alert](https://firsthackersnews.com/notepad-plus-plus-code-execution-flaw/): CISA has raised concerns about a serious security issue affecting Notepad++, one of the most widely used text editors. - [Over 37 Million Users Targeted by 287 Malicious Chrome Extensions](https://firsthackersnews.com/malicious-chrome-extensions-37-million-users-data-leak/): A recent investigation uncovered 287 Chrome extensions that may be quietly collecting users’ browsing data and transmitting it to external servers. These extensions represent around 37.4 million installs — close to 1% of Chrome’s global user base. - [Threat Actors Leverage ChatGPT, Grok, and Google Ads to Deploy macOS AMOS Stealer](https://firsthackersnews.com/chatgpt-grok-google-ads-macos-amos-stealer/): Threat actors are evolving — and they’re doing it on trusted platforms. - [Microsoft 365 Admin Center Disruption Affects North American Users](https://firsthackersnews.com/microsoft-365-admin-center-outage-north-america/): Microsoft 365 administrators across North America are experiencing significant access issues with the Microsoft 365 admin center, creating operational challenges for organizations that depend on the platform for daily management tasks. The issue has been acknowledged through Microsoft’s service health communications, confirming that this is a broader service disruption rather than isolated user-side trouble. - [Malicious 7-Zip Files Converting PCs into Proxy Nodes](https://firsthackersnews.com/fake-7zip-malware-proxy-infection/): Cybercriminals are running a sneaky operation that uses a fake version of the popular 7-Zip archiving tool to compromise everyday home computers. Instead of just installing file compression software, victims unknowingly install malware that turns their machines into part of a residential proxy network. - [FortiOS Authentication Flaw Enables LDAP Bypass](https://firsthackersnews.com/fortios-ldap-authentication-bypass-vulnerability/): A new security advisory from Fortinet highlights a serious weakness in FortiOS that could let attackers slip past authentication controls in certain environments. - [Claude Desktop Security Bug Opens Door to RCE](https://firsthackersnews.com/claude-desktop-rce-vulnerability/): Security researchers at LayerX uncovered a design-level weakness affecting Claude Desktop Extensions (DXT), the extension framework tied to Anthropic’s assistant. - [Using Windows Minifilters to Identify Ransomware Activity](https://firsthackersnews.com/windows-minifilter-ransomware-detection/): The project is part of a wider Endpoint Detection and Response effort called Sanctum. It shows how defenders can use Windows Minifilters to spot and interrupt malicious file encryption before user data is damaged. - [5 Million+ Misconfigured Git Servers Leave Secrets Open to the Internet](https://firsthackersnews.com/git-repository-exposure-misconfigured-web-servers/): A widespread web server misconfiguration issue has quietly exposed millions of websites to potential data theft and unauthorized system access, according to new research from the Mysterium VPN research team. - [Apple Pay Users Hit by Phishing Scam Designed to Harvest Payment Data](https://firsthackersnews.com/apple-pay-phishing-scam-account-takeover/): A new and well-planned phishing campaign is targeting users of Apple’s payment ecosystem. The attackers are not using the usual low-quality scam emails. Instead, they combine professional email design with phone-based fraud to trick victims into giving away access to their accounts. - [The Next Generation of Malware: AI-Enabled and Adaptive Threats ](https://firsthackersnews.com/promptflux-and-quietvault/): Recent research from Google’s Threat Intelligence Group reveals that adversaries are now building malware that actively leverages artificial intelligence (AI) during execution, not just during development or planning. This is a major evolution: malicious code is now capable of adapting itself dynamically at runtime, making it harder to detect and prevent using traditional defenses.  - [Critical Flaws in F5 BIG-IP and NGINX Prompt Urgent Security Patches](https://firsthackersnews.com/f5-bigip-nginx-critical-vulnerabilities-security-fixes/): F5 has released its latest security update, fixing several vulnerabilities across its products. Although F5 lists some of these issues as “medium” under its internal scale, the newer CVSS v4.0 system rates the main ones at 8.2, which is considered high risk for enterprise environments. - [Security Gaps in TP-Link Devices Expose Users to Full Control Attacks](https://firsthackersnews.com/tp-link-devices/): TP-Link has disclosed multiple serious security flaws in its Archer BE230 v1.2 Wi-Fi router. These vulnerabilities allow attackers with administrative access to run system commands and take complete control of the device. - [Mass Scanning Campaign Targets Exposed Citrix NetScaler Login Pages](https://firsthackersnews.com/citrix-netscaler-login-scanning-campaign/): A large, organized scanning campaign has been observed targeting Citrix NetScaler (ADC) Gateway systems across the internet. The goal appears to be identifying exposed login pages and gathering software version details — a strong sign that attackers are preparing for possible exploitation. - [Hackers Leverage LOLBins to Deliver Advanced PeckBirdy Malware](https://firsthackersnews.com/peckbirdy-lolbins-advanced-malware-campaign/): A malware framework called PeckBirdy has been active since 2023, using built-in system tools (LOLBins) to quietly deliver backdoors. Instead of dropping obvious malicious files, attackers use trusted programs already present on systems, helping their activity blend in with normal operations. - [Windows 11 Strengthens Protection of System Files](https://firsthackersnews.com/windows-11-kb5074105-system-file-protection-update/): Microsoft has issued KB5074105, an important preview update for Windows 11 versions 24H2 and 25H2, aimed at strengthening the operating system’s defense against unauthorized access to sensitive system files. - [ShadowHS Linux Malware Spreading Quietly](https://firsthackersnews.com/shadowhs-linux-malware-spreading-quietly/): A newly observed Linux threat called ShadowHS is showing how modern attackers are moving beyond traditional malware. Instead of dropping files on a system, this framework runs completely in memory, making it much harder for standard security tools to detect. - [Security Lapse Exposes 21,000+ OpenClaw AI Deployments](https://firsthackersnews.com/open-source-ai-assistant-security-exposure/): The growing number of internet-exposed OpenClaw deployments is creating security concerns that go beyond simple setup mistakes. Large clusters of these systems appear to be hosted on major cloud platforms, with a visible share on Alibaba Cloud infrastructure, though that may reflect scanning visibility rather than actual dominance. - [Metasploit Update Adds New Exploits for Enterprise Platforms](https://firsthackersnews.com/metasploit-security-update/): The latest Metasploit Framework update brings several new modules that help security teams test real-world attack paths. This release focuses on widely used enterprise and infrastructure software, showing how attackers can combine multiple weaknesses to gain full system control. - [Johnson Controls Products Exposed to Remote SQL Injection Flaws](https://firsthackersnews.com/johnson-controls-critical-security-flaw/): A serious security warning has been issued for several Johnson Controls industrial control products due to a critical SQL injection flaw. The issue allows attackers to remotely manipulate databases in affected systems, potentially leading to major disruption in environments that rely on these platforms. - [Semantic Chaining Attack Bypasses AI Safety Controls](https://firsthackersnews.com/semantic-chaining-attack-ai-safety-bypass/): Researchers at NeuralTrust uncovered a new AI weakness called Semantic Chaining. It affects multimodal systems like Grok 4 and Gemini Nano Banana Pro, showing how attackers can slip past safety controls using a sequence of harmless-looking steps. - [Growing eSkimming Attacks Create Ongoing Security Challenges](https://firsthackersnews.com/eskimming-attack-prevention/): A year-long study tracking 550 hacked e-commerce sites across 68 countries shows that removing a skimmer once does not mean the threat is gone. eSkimming is turning into a long-term problem, not a one-time incident. - [New MITRE Framework Aims to Protect Embedded Devices](https://firsthackersnews.com/mitre-framework-embedded-systems-cybersecurity/): MITRE has just unveiled a dedicated cybersecurity framework — the Embedded Systems Threat Matrix™ (ESTM) — to help defenders understand and protect embedded technologies that are now at the heart of modern critical infrastructure and defense systems. - [PoC Released for GNU Telnetd RCE, 800K+ Still Exposed](https://firsthackersnews.com/cve-2026-24061/): A working proof-of-concept exploit has been made public for CVE-2026-24061, a critical remote code execution vulnerability affecting GNU Inetutils telnetd. - [Microsoft Teams Is Adding Wi-Fi Location Tracking — and It’s Raising Big Questions](https://firsthackersnews.com/wi-fi-location-tracking/): Microsoft is preparing to introduce a new Teams feature that can automatically show where employees are working based on the Wi-Fi networks they connect to. Instead of users manually setting their location, Teams will detect whether someone is in the office and update their work status automatically. - [Windows 11 January Update Triggers Serious Boot Issues](https://firsthackersnews.com/windows-11/): Microsoft investigates startup and stability issues affecting recent Windows 11 versions - [New Osiris Ransomware Campaign Exploits Living-off-the-Land Tools](https://firsthackersnews.com/osiris/): A recently identified ransomware strain named Osiris was linked to an intrusion at a large food services organization in Southeast Asia in November 2025. Analysts confirmed that this malware is a new development and is not related to the ransomware that used the same name nearly a decade ago. - [OWASP ZAP Releases New Penetration Testing Browser Extension](https://firsthackersnews.com/owasp-zap/): The OWASP ZAP project has introduced a new add-on that brings the OWASP Penetration Testing Kit (PTK) directly into browsers opened through ZAP. The current release, version 0.2.0 (alpha), removes the need for separate browser extension setup during testing. - [BIND 9 Vulnerability Can Crash DNS Servers](https://firsthackersnews.com/bind-9-vulnerability/): A newly reported high-impact security flaw in BIND 9, one of the most widely deployed DNS server implementations, could allow attackers to disrupt DNS operations remotely. By sending specially crafted DNS data, an attacker may cause the DNS service to stop unexpectedly. - [Cisco Unified Communications Zero-Day RCE Enables Root Access](https://firsthackersnews.com/cisco-3/): Cisco has issued an urgent security alert after identifying a previously unknown remote code execution flaw being exploited against its Unified Communications platforms. The vulnerability, tracked as CVE-2026-20045, enables attackers to compromise systems without authentication and ultimately obtain root-level control. - [Apache Airflow Flaws Risk Exposure of Sensitive Data](https://firsthackersnews.com/apache-airflow/): Multiple vulnerabilities in Apache Airflow versions prior to 3.1.6 could lead to the exposure of sensitive credentials through task logs and the web interface. The issues are caused by improper masking of secrets during logging and template rendering. - [Critical WordPress Plugin Bug Puts 100K+ Sites at Risk](https://firsthackersnews.com/wordpress-plugin-2/): A critical security vulnerability has been identified in the Advanced Custom Fields: Extended WordPress plugin, exposing more than 100,000 websites to the risk of complete compromise. The flaw allows attackers to gain full administrator access without authentication, making it especially dangerous for sites with public-facing forms. - [𝗠𝗰𝗗𝗼𝗻𝗮𝗹𝗱’𝘀 𝗜𝗻𝗱𝗶𝗮 𝗧𝗮𝗿𝗴𝗲𝘁𝗲𝗱 𝗯𝘆 𝗘𝘃𝗲𝗿𝗲𝘀𝘁 𝗥𝗮𝗻𝘀𝗼𝗺𝘄𝗮𝗿𝗲](https://firsthackersnews.com/everest-ransomware/): The Everest ransomware group is claiming a significant breach involving McDonald’s India, alleging that hundreds of gigabytes of data were taken from the company’s environment. - [VoidLink Signals a New Era of Linux Rootkits in Cloud Environments](https://firsthackersnews.com/voidlink/): VoidLink has emerged as a serious threat to Linux-based cloud infrastructure, marking a clear shift in how modern rootkits are designed and deployed. Unlike older Linux malware that often struggled with compatibility across kernel versions, VoidLink introduces a more flexible and resilient approach built for today’s cloud environments. - [Critical Privilege Escalation Vulnerabilities Discovered in Google Vertex AI](https://firsthackersnews.com/google-vertex-ai/): Security researchers have uncovered critical privilege escalation vulnerabilities in Google Cloud’s Vertex AI platform, allowing attackers with minimal permissions to gain control over high-privileged Service Agent accounts. These flaws stem from default configurations within Vertex AI Agent Engine and Ray on Vertex AI, exposing powerful managed identities at the project level. - [Android Volume Button Bug Tied to Select to Speak Feature](https://firsthackersnews.com/volume-button/): Google has confirmed an Android bug that affects how volume buttons behave when the Select to Speak accessibility feature is enabled. The issue interferes with everyday actions like adjusting media volume and taking photos, creating a frustrating experience for affected users. - [Security Bypass Issue Found in Windows Remote Assistance](https://firsthackersnews.com/windows-remote-assistance-security-bypass/): Microsoft has addressed a security weakness in Windows Remote Assistance that could allow attackers to bypass built-in protection mechanisms and access sensitive data under certain conditions. The vulnerability, tracked as CVE-2026-20824, has been rated Important and mainly impacts how Windows applies trust checks to files involved in Remote Assistance sessions. - [Critical Cal.com Vulnerability Enables Account Takeover](https://firsthackersnews.com/cal-com/): A newly disclosed critical vulnerability in Cal.com, an open-source scheduling and booking platform, could allow attackers to bypass authentication and take over user accounts without valid credentials. - [DragonForce Ransomware Targets ESXi and Windows Systems](https://firsthackersnews.com/dragonforce-ransomware/): Security researchers have released a detailed technical analysis of the DragonForce ransomware, along with confirmation that working decryptors exist for certain Windows and ESXi victims. By the time DragonForce’s Data Leak Site (DLS) was discovered, at least 17 organizations had already been listed as victims. - [Palo Alto Networks Fixes Firewall DoS Vulnerability](https://firsthackersnews.com/palo-alto-networks/): Palo Alto Networks has released security updates to fix a denial-of-service (DoS) vulnerability in its PAN-OS firewall software. The issue, tracked as CVE-2026-0227, could allow unauthenticated attackers to disrupt GlobalProtect gateways and portals, forcing affected firewalls into maintenance mode. - [Elastic Security Updates Address File Theft and DoS Risks](https://firsthackersnews.com/elastic/): Elastic has released new security updates to fix multiple vulnerabilities across its platform, including a high-severity issue that could allow attackers to read arbitrary files from affected systems. - [ServiceNow AI Platform Privilege Escalation Vulnerability](https://firsthackersnews.com/servicenow-ai-platform/): A serious security issue has been identified in the ServiceNow AI Platform, exposing organizations to the risk of unauthorized access and privilege escalation. The flaw allows attackers to act as legitimate users without needing to log in, making it a high-impact threat for affected environments. - [SAP January 2026 Patch Day: Critical Fixes](https://firsthackersnews.com/sap/): SAP has released its January 2026 Security Patch Day updates, publishing 17 new security notes on January 13, 2026. The updates address multiple vulnerabilities across SAP products, including critical injection flaws and remote code execution (RCE) issues that could allow attackers to compromise affected systems. - [Instagram Says No Breach After Password Reset Issue](https://firsthackersnews.com/instagram-password-reset-issue/): Instagram has confirmed that its platform was not compromised after a wave of unexpected password reset emails reached some users. The company explained that the messages were triggered by a now-resolved issue that was misused by an outside party. - [Researchers Track IPs and Domains Linked to Carding Markets](https://firsthackersnews.com/carding-market-infrastructure-analysis/): Recent research has shed light on how underground carding markets operate online. Investigators identified 28 active IP addresses and 85 domains that were being used to host illegal marketplaces where stolen credit card data is sold. - [React2Shell Vulnerability Under Mass Exploitation](https://firsthackersnews.com/react2shell-vulnerability-2/): The React2Shell vulnerability (CVE-2025-55182) continues to be heavily targeted, with attackers launching more than 8.1 million attack attempts since the flaw was disclosed. - [LockBit 5.0 Adds New Evasion Techniques](https://firsthackersnews.com/lockbit-5-0/): LockBit 5.0 has appeared as the newest version of one of the most active ransomware groups in recent years. Active since 2019, LockBit continues to evolve its tools to stay effective against modern defenses. - [Chrome Extension Used to Steal AI Chat Data](https://firsthackersnews.com/chrome-extension-2/): More than 900,000 Chrome users were impacted by two harmful browser extensions that quietly collected AI chat content and browsing activity. - [Flaw in Chrome WebView Exposes Security Controls](https://firsthackersnews.com/webview/): The issue affects Chrome’s WebView tag component and is tracked as CVE-2026-0628. To address it, Google rolled out the following updates via the Stable channel: - [Infostealers Lead to Cloud Account Compromises](https://firsthackersnews.com/zestix/): Several large organizations worldwide have been breached after attackers reused stolen login details collected by infostealer malware. - [Security Flaws in Eaton Products May Allow Code Execution](https://firsthackersnews.com/etn-va-2025-1026/): The advisory, tracked as ETN-VA-2025-1026, affects all versions of Eaton UPS Companion before version 3.0. Eaton has rated the overall risk as High and recommends immediate action. - [Phishing Campaign Exploits Google Tasks Feature](https://firsthackersnews.com/google-tasks/): The attack started with emails that looked like routine Google Tasks notifications. They appeared to be normal internal task requests, asking employees to review or verify information. - [Apache NuttX Bug Allows Remote System Crashes](https://firsthackersnews.com/apache-nuttx-rtos/): A newly disclosed vulnerability in Apache NuttX RTOS could allow attackers to crash systems or trigger unexpected file operations. The issue affects devices running network-exposed services and has prompted security warnings for impacted users. - [ErrTraffic Tool Automates ClickFix Cyber Attacks](https://firsthackersnews.com/clickfix-4/): Cybercrime activity is increasingly shaped by automation and repeatable services. Researchers at Hudson Rock have identified ErrTraffic v2, a platform designed to operationalize ClickFix attacks at scale by packaging social-engineering techniques into an easy-to-use service. - [GlassWorm malware uses malicious VS Code extensions to attack macOS systems](https://firsthackersnews.com/glassworm-malware/): GlassWorm has returned with a dangerous new evolution, shifting its focus entirely to macOS. First discovered in October, the malware originally spread through malicious VS Code extensions that used invisible Unicode characters to hide their behavior. The latest wave shows a major increase in sophistication, scale, and impact. - [IBM API Connect Flaw Enables Authentication Bypass](https://firsthackersnews.com/cve-2025-13915/): IBM has disclosed a critical security flaw in its API Connect platform that allows attackers to bypass authentication entirely. The vulnerability is tracked as CVE-2025-13915 and has been assigned a CVSS score of 9.8, placing it in the critical severity category. - [Magecart Attack Uses 50+ Scripts to Steal Payments](https://firsthackersnews.com/magecart-campaign/): A newly uncovered Magecart operation shows how web-based attacks on online stores are becoming more advanced. - [CISA Warns: MongoDB (CVE-2025-14847) Flaw](https://firsthackersnews.com/mongodb/): CISA has flagged a serious security issue affecting MongoDB Server and confirmed that it is being actively abused by attackers. The flaw has now been added to CISA’s Known Exploited Vulnerabilities (KEV) catalog, which means it is being used in real-world attacks. - [AI-Driven Phishing Kit Targets Microsoft Accounts](https://firsthackersnews.com/ai-driven-phishing-kit/): Since March 2025, attackers running a Spanish-language phishing campaign have been going after Microsoft Outlook accounts. The phishing tool they use appears advanced and likely built with help from AI. - [Windows Kernel and Named Pipe Flaws Enable Privilege Escalation](https://firsthackersnews.com/windows-privilege-escalation-attack-surfaces/): Windows privilege escalation remains a common technique used by attackers to gain deeper control of a system. - [Hackers Claim Access to WIRED Subscriber Database](https://firsthackersnews.com/wired/): A massive data leak linked to WIRED has surfaced online, exposing personal information tied to more than 2.3 million subscribers. The incident is connected to Condé Nast’s shared subscriber infrastructure, which supports several of its media brands. - [Users Report Major Losses After TrustWallet Extension Hack](https://firsthackersnews.com/trustwallet/): A security issue in the Trust Wallet Chrome extension led to losses of more than $7 million. The problem was linked to extension version 2.68.0, released on December 24, 2025. - [Users Can Now Change Their Gmail Email Address](https://firsthackersnews.com/gmail/): For a long time, Gmail users had only one option if they wanted a new email address: create a new Google account and start over. The original @gmail.com address was locked in, even if it no longer reflected who the user was or how they wanted to be seen online. - [Microsoft Teams to Enforce Messaging Safety Defaults](https://firsthackersnews.com/microsoft-teams-4/): Microsoft is making Microsoft Teams safer by default. Beginning January 12, 2026, the platform will automatically apply new messaging safety protections for organizations that are still using standard Teams settings. - [Hackers Abuse ClickFix Technique to Hide Images](https://firsthackersnews.com/clickfix-3/): Threat actors are using a new attack method that combines ClickFix social engineering with image steganography to hide malware inside PNG image files. - [Malicious NPM Package Targets WhatsApp Messages](https://firsthackersnews.com/lotusbail/): A malicious npm package called “lotusbail” has been secretly stealing WhatsApp messages and user data from developers around the world. - [Marquis Data Breach Exposes Hundreds of Thousands of Bank Customers](https://firsthackersnews.com/marquis/): A major data breach at Marquis has compromised the personal information of hundreds of thousands of bank customers, creating concern across the financial sector. - [GitHub Copilot Gets Claude Opus 4.5 Integration](https://firsthackersnews.com/claude-opus-4-5/): GitHub has officially introduced Claude Opus 4.5, Anthropic’s latest flagship AI model, into its Copilot platform. With this upgrade, developers gain access to stronger reasoning, improved code generation, and more reliable AI-assisted workflows across all supported environments. - [𝗖𝗶𝘀𝗰𝗼 𝗔𝘀𝘆𝗻𝗰𝗢𝗦 𝟬-𝗗𝗮𝘆 𝗨𝗻𝗱𝗲𝗿 𝗔𝗰𝘁𝗶𝘃𝗲 𝗘𝘅𝗽𝗹𝗼𝗶𝘁𝗮𝘁𝗶𝗼𝗻](https://firsthackersnews.com/%f0%9d%97%96%f0%9d%97%b6%f0%9d%98%80%f0%9d%97%b0%f0%9d%97%bc-%f0%9d%97%94%f0%9d%98%80%f0%9d%98%86%f0%9d%97%bb%f0%9d%97%b0%f0%9d%97%a2%f0%9d%97%a6/): An active zero-day exploit in Cisco AsyncOS is being used to target Secure Email Gateway and Secure Email & Web Manager appliances. - [𝗙𝗼𝗿𝘂𝗺𝗧𝗿𝗼𝗹 𝗨𝘀𝗲𝘀 𝗖𝗵𝗿𝗼𝗺𝗲 𝟬-𝗗𝗮𝘆 𝗶𝗻 𝗡𝗲𝘄 𝗣𝗵𝗶𝘀𝗵𝗶𝗻𝗴 𝗖𝗮𝗺𝗽𝗮𝗶𝗴𝗻](https://firsthackersnews.com/%f0%9d%97%96%f0%9d%97%b5%f0%9d%97%bf%f0%9d%97%bc%f0%9d%97%ba%f0%9d%97%b2-%f0%9d%9f%ac-%f0%9d%97%97%f0%9d%97%ae%f0%9d%98%86/): Operation ForumTrol has launched a new phishing campaign aimed at Russian political scientists and academic researchers. The group has been active throughout 2025 and first drew major attention after exploiting a Chrome zero-day vulnerability (CVE-2025-2783). - [𝗔𝗽𝗽𝗹𝗲 𝗪𝗲𝗯𝗞𝗶𝘁 𝟬-𝗗𝗮𝘆 𝗘𝘅𝗽𝗹𝗼𝗶𝘁𝗲𝗱, 𝗖𝗜𝗦𝗔 𝗪𝗮𝗿𝗻𝘀](https://firsthackersnews.com/webkit-vulnerability/): CISA has issued an urgent alert about a critical zero-day vulnerability in Apple WebKit that is being actively exploited in real-world attacks. - [Microsoft Shares Fixes for React2Shell RCE Flaw](https://firsthackersnews.com/react2shell-vulnerability/): Microsoft has released security guidance to address a critical vulnerability called React2Shell (CVE-2025-55182). The issue affects applications built with React Server Components and Next.js and can result in full server compromise. - [Frogblight Android Malware Steals SMS & Device Data](https://firsthackersnews.com/frogblight/): Frogblight is a sophisticated Android banking Trojan mainly targeting users in Turkey by pretending to be official government services. - [JSCEAL Malware Targeting Windows Users to Steal Credentials](https://firsthackersnews.com/jsceal/): JSCEAL is a new threat targeting Windows users, mainly people using cryptocurrency apps or accounts with sensitive data. - [𝗩𝗦 𝗖𝗼𝗱𝗲 𝗠𝗮𝗹𝘄𝗮𝗿𝗲 𝗔𝗹𝗲𝗿𝘁: 𝗙𝗮𝗸𝗲 𝗣𝗡𝗚 𝗙𝗶𝗹𝗲𝘀 𝗛𝗶𝗱𝗶𝗻𝗴 𝗧𝗿𝗼𝗷𝗮𝗻𝘀](https://firsthackersnews.com/vscode-malware-fake-png-extensions/): ReversingLabs has uncovered a supply-chain attack involving 19 malicious VS Code extensions.Active since February 2025, the campaign was exposed on December 2 and takes advantage of the trust developers place in extensions by hiding malware inside their dependency folders. - [AI Detects Large-Scale Chinese Malware Network Across 5,000 Domains](https://firsthackersnews.com/chinese-malware-spoofing/): DomainTools Investigations has uncovered a rapidly growing malware network aimed at Chinese-speaking users around the world. - [𝗔𝗠𝗢𝗦 𝗦𝘁𝗲𝗮𝗹𝗲𝗿 𝗦𝗽𝗿𝗲𝗮𝗱 𝘃𝗶𝗮 𝗔𝗯𝘂𝘀𝗲𝗱 𝗖𝗵𝗮𝘁𝗚𝗣𝗧 & 𝗚𝗿𝗼𝗸 𝗖𝗵𝗮𝘁𝘀](https://firsthackersnews.com/macos-amos/): The cybersecurity landscape is at a worrying point. On December 5, 2025, Huntress discovered a smart attack using the Atomic macOS Stealer (AMOS) delivered through a very simple method. - [Vishing Scam Uses Teams & QuickAssist to Deploy .NET Malware](https://firsthackersnews.com/vishing-scam/): A new vishing attack uses social engineering and legitimate Microsoft tools to run commands and deploy multi-stage .NET malware. - [Android Users Hit as Hackers Push Triada via Ad Networks](https://firsthackersnews.com/triada/): Adex, an anti-fraud platform under AdTech Holding, has uncovered and shut down a long-running malware scheme tied to the Triada Trojan. The operation had been active for several years and was quietly abusing the digital advertising ecosystem to infect Android users. - [Major Tech Brands to Roll Out Always-On GPS in India Soon](https://firsthackersnews.com/always-on-gps-mandate-india/): India is weighing a new rule that would force all smartphones to keep GPS-based location tracking active at all times. If this becomes law, users would not be able to switch the feature off. - [2.15M Next.js sites are exposed and being attacked — update ASAP.](https://firsthackersnews.com/react2shell/): Security teams around the world are rushing to fix systems after a major React vulnerability was revealed: CVE-2025-55182, also called “React2Shell.” - [ArrayOS AG VPN Flaw Exploited for Webshell Attacks](https://firsthackersnews.com/arrayos-ag-vpn-webshell-exploit/): A critical command injection vulnerability in Array Networks’ ArrayOS AG systems is being actively exploited, with confirmed attacks on Japanese organizations since August 2025. - [BRICKSTORM Malware Targeting ESXi and Windows](https://firsthackersnews.com/brickstorm-malware/): Three major cyber agencies — CISA, NSA, and the Canadian Cyber Centre — have issued a new alert about a powerful malware called BRICKSTORM. They say this threat comes from state-sponsored hackers in China and is aimed at important government and technology systems. - [Calendly-Themed Scam Aims at Google Workspace Credentials](https://firsthackersnews.com/calendly/): A new phishing campaign has been uncovered using fake Calendly pages to steal credentials from Google Workspace and Facebook Business users. Push Security analyzed the operation and found that the attackers are combining realistic social engineering with multiple detection-evasion techniques to compromise business ad accounts. - [Chrome 143 Update Patches 13 Vulnerabilities Allowing Code Execution](https://firsthackersnews.com/chrome-143/): Google has released Chrome 143 to the Stable channel, with version 143.0.7499.40 now available for Linux and 143.0.7499.40/41 for Windows and Mac. - [Apache Struts Bug Allows Disk Exhaustion Attacks](https://firsthackersnews.com/apache-struts/): A newly disclosed security flaw in Apache Struts could let attackers trigger disk exhaustion attacks, potentially making affected servers slow, unstable, or completely unusable. - [New Outlook Glitch Prevents Excel Attachments](https://firsthackersnews.com/new-outlook/): Users of the new Outlook for Windows are facing a problem where Excel attachments won’t open if their filenames include non-standard characters. - [Malicious VS Code Icon Theme Targets Windows & macOS](https://firsthackersnews.com/windows-macos/): A fake VS Code extension pretending to be the Material Icon Theme was found targeting Windows and macOS users. Attackers added hidden backdoor files into the marketplace package, giving them quiet access to developer systems after installation. - [PoC Released for Critical Outlook Zero-Click RCE Bug](https://firsthackersnews.com/monikerlink/): The flaw, known as “MonikerLink,” allows attackers to bypass Outlook’s Protected View and execute malicious code or steal credentials. The PoC release highlights the continuing risk and provides security teams with insight into the attack vector. - [Android Users Hit by New Albiriox Malware](https://firsthackersnews.com/albiriox-malware/): Albiriox is a new Android malware that recently appeared on cybercrime forums. It offers advanced remote-access features and is sold as a Malware-as-a-Service tool. Researchers at Cleafy found that the main goal of this malware is to perform On-Device Fraud. It gives attackers full control of an infected device and lets them bypass security checks to steal money from banking apps. - [GitLab Patches Critical Auth & DoS Bugs](https://firsthackersnews.com/gitlab-2/): GitLab has released important security updates for both its Community Edition (CE) and Enterprise Edition (EE) to fix several serious vulnerabilities. - [Legacy Python Bugs Enable PyPI Attacks via Domain Hijack](https://firsthackersnews.com/python/): Hidden vulnerabilities in old Python code can create serious risks for today’s development environments. - [Microsoft Teams Guest Chat Risk Lets Attackers Bypass Security](https://firsthackersnews.com/teams-guest-chat/): A gap in Microsoft Teams’ B2B guest access allows attackers to bypass Defender for Office 365 protections, creating unprotected spaces for phishing and malware. - [Threat Actors List iOS 26 Full-Chain 0-Day on Dark Web](https://firsthackersnews.com/ios-26/): A threat actor calling themselves ResearcherX has claimed to sell a full-chain zero-day exploit for Apple’s new iOS 26. The listing, posted on a major dark web marketplace, says the exploit abuses a serious memory-corruption flaw in the iOS Message Parser. - [Malware in Chrome Extension Found Stealing SOL via Hidden Swap Fees](https://firsthackersnews.com/chrome-extension/): Security researchers at Socket discovered a deceptive Chrome extension called Crypto Copilot. It pretends to be a legitimate Solana trading tool but secretly takes SOL from users’ swap transactions. - [Tor Enhances Security with Galois Encryption](https://firsthackersnews.com/counter-galois-onion/): The Tor Project has introduced a major upgrade to its cryptographic system, replacing its long-standing relay encryption algorithm with the new Counter Galois Onion (CGO) design. - [W3 Total Cache PoC Published, Putting Millions of WordPress Sites at Risk](https://firsthackersnews.com/w3-total-cache/): A proof-of-concept (PoC) exploit has been released for CVE-2025-9501, a critical command-injection vulnerability in W3 Total Cache, one of the most widely used caching plugins for WordPress. - [Threat Actors Exploit WhatsApp to Stealthily Gather User Data](https://firsthackersnews.com/whatsapp-malware-campaign/): A new malware campaign is actively targeting users in Brazil, using WhatsApp as the primary channel to deliver banking trojans and steal sensitive data. The operation combines social engineering, browser manipulation, and automated account abuse to spread quickly and discreetly. - [Gainsight Breach Exposes Data from 200+ Organizations](https://firsthackersnews.com/gainsight/): Salesforce has disclosed a significant security incident involving unauthorized access to customer data through compromised OAuth tokens used by Gainsight-published applications. - [CISA Alerts Organizations to Oracle Identity Manager RCE Attack](https://firsthackersnews.com/known-exploited-vulnerabilities/): The flaw, tracked as CVE-2025-61757, affects Oracle Identity Manager, a core component of Oracle Fusion Middleware. CISA has classified it as a “missing authentication for critical function” issue, which enables remote, unauthenticated attackers to access privileged functionality. Successful exploitation can lead to remote code execution (RCE) and full compromise of the identity platform. - [Hackers Use Matrix Push C2 for Malware and Browser Phishing](https://firsthackersnews.com/matrix-push-c2/): A new command-and-control system called Matrix Push C2 has become a major threat to users on all operating systems. This tool uses normal web browser features to deliver malware and phishing attacks without needing any file downloads. - [Windows Graphics Vulnerability Opens the Door to System Hijack with a Single Image](https://firsthackersnews.com/windows-graphics-vulnerability/): A serious remote code execution flaw in Microsoft’s Windows Graphics Component allows attackers to take control of a device using a specially crafted JPEG image. - [Investigation Underway: Microsoft Copilot File Processing Concern](https://firsthackersnews.com/microsoft-copilot/): Microsoft has launched an investigation into a widespread issue affecting Microsoft Copilot in Microsoft 365, where users are experiencing limitations when performing file operations. The company has assigned the tracking ID CP1188020 for administrative reference. - [WhatsApp Screen-Sharing Scam Exposes Users to Data Theft](https://firsthackersnews.com/whatsapp-screen-share/): A new and rapidly growing scam is targeting WhatsApp users worldwide, exploiting the platform’s screen-sharing feature introduced in 2023. Cybercriminals are using this tool to trick victims into revealing highly sensitive financial and personal information. - [Cloudflare Reveals Key Technical Causes of Massive Global Outage](https://firsthackersnews.com/cloudflare-2/): Cloudflare released a detailed report explaining the cause of a major network outage that disrupted global internet traffic for several hours. Millions of users and services were affected. - [Attackers Can Exploit Multiple Flaws in Cisco Unified CCX to Run Commands](https://firsthackersnews.com/unified-ccx/): Cisco has revealed serious security vulnerabilities in Cisco Unified Contact Center Express (Unified CCX). These issues allow remote, unauthenticated attackers to run commands, gain root-level access, and bypass authentication. - [Cisco Catalyst Center Bug Lets Attackers Gain Higher Access](https://firsthackersnews.com/cve-2025-20341/): Cisco has released a warning about a newly discovered high-severity vulnerability (CVE-2025-20341) affecting the Cisco Catalyst Center Virtual Appliance. This flaw allows authenticated remote users to escalate their privileges to Administrator, giving them full control over the system. - [Active Exploits Target Critical FortiWeb WAF Flaw](https://firsthackersnews.com/cve-2025-64446/): The vulnerability, CVE-2025-64446, allows attackers to run admin-level commands without logging in. This means they can take complete control of the system. The issue has a CVSS score of 9.1, making it very serious. - [npm Package With 206K Downloads Steals GitHub Tokens](https://firsthackersnews.com/npm-package/): A fake npm package called “@acitons/artifact” had already reached 206,000 downloads before it was removed. This package looked almost identical to the real “@actions/artifact” package. The attacker simply swapped two letters — “ti” became “it” — hoping developers would mistype the name and install the wrong package. - [Lite XL Text Editor Vulnerability Allows Remote Code Execution](https://firsthackersnews.com/lite-xl/): A new vulnerability has been discovered in Lite XL, a lightweight open-source text editor, that could let attackers run arbitrary code on affected systems. - [New Phishing Trick Hits People Who Lost Their iPhones](https://firsthackersnews.com/apple-activation-lock/): A new phishing scam is targeting iPhone users who have lost their devices, taking advantage of their hope to recover them. The goal: to steal Apple ID credentials. - [DarkComet RAT Hides Behind Fake Bitcoin Tools](https://firsthackersnews.com/darkcomet-rat/): A newly discovered malware campaign is leveraging one of cybercriminals’ most effective lures cryptocurrency to distribute DarkComet RAT. - [𝗠𝗶𝗰𝗿𝗼𝘀𝗼𝗳𝘁 𝗣𝗮𝘁𝗰𝗵 𝗧𝘂𝗲𝘀𝗱𝗮𝘆 – 𝗖𝗿𝗶𝘁𝗶𝗰𝗮𝗹 𝟬-𝗱𝗮𝘆 𝗣𝗮𝘁𝗰𝗵 + 𝗠𝗮𝗷𝗼𝗿 𝗦𝗲𝗰𝘂𝗿𝗶𝘁𝘆 𝗙𝗶𝘅𝗲𝘀](https://firsthackersnews.com/%f0%9d%97%a0%f0%9d%97%b6%f0%9d%97%b0%f0%9d%97%bf%f0%9d%97%bc%f0%9d%98%80%f0%9d%97%bc%f0%9d%97%b3%f0%9d%98%81-%f0%9d%97%a3%f0%9d%97%ae%f0%9d%98%81%f0%9d%97%b0%f0%9d%97%b5-%f0%9d%97%a7%f0%9d%98%82/): One of the most serious issues is a zero-day vulnerability in the Windows Kernel (CVE-2025-62215). This flaw is already being actively exploited and allows attackers to gain higher system privileges. Because of this, system administrators should install this update immediately. - [Security Flaw in Ivanti Endpoint Manager Allows File Writes](https://firsthackersnews.com/ivanti-endpoint/): Ivanti has released an urgent security update for Ivanti Endpoint Manager, addressing a newly discovered high-severity flaw that allows authenticated attackers to write files anywhere on the system. The advisory was published on November 10, 2025, and patches are now available. - [Websites Compromised to Boost Hacker SEO](https://firsthackersnews.com/blackhat-seo/): Cybercriminals are now hacking websites to insert malicious links that help boost their own search engine rankings. This technique, known as blackhat SEO, is becoming increasingly common. - [PATCH NOW: QNAP Fixes 7 Zero-Days Exploited at Pwn2Own 2025](https://firsthackersnews.com/qnap/): QNAP has released an urgent security update after security researchers at Pwn2Own Ireland 2025 successfully hacked QNAP NAS devices using seven zero-day vulnerabilities. - [Introducing HackGPT: A New AI Engine for Pen Testing](https://firsthackersnews.com/hackgpt/): HackGPT Enterprise aims to change that. - [Google Uncovers AI-Powered Malware PROMPTFLUX Using Gemini API for Code Evasion](https://firsthackersnews.com/google-discovers-promptflux-ai-malware-using-gemini-api/): Google has uncovered a new form of AI-assisted malware that uses its own Gemini large language model (LLM) to rewrite its code and evade detection.The malicious script, called PROMPTFLUX, was discovered by the Google Threat Intelligence Group (GTIG). - [CISA Adds Gladinet and Control Web Panel Flaws to Known Exploited Vulnerabilities List](https://firsthackersnews.com/cisa-adds-gladinet-control-web-panel-vulnerabilities-2025/): The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added two new security flaws affecting Gladinet and Control Web Panel (CWP) to its Known Exploited Vulnerabilities (KEV) catalog. The agency warned that attackers are actively exploiting these vulnerabilities in real-world attacks. - [Microsoft Teams Vulnerabilities Expose Users to Impersonation and Social Engineering Attacks](https://firsthackersnews.com/microsoft-teams-vulnerabilities-2024-impersonation-attacks/): Cybersecurity researchers have revealed four critical vulnerabilities in Microsoft Teams that could have allowed attackers to impersonate colleagues, manipulate messages, and carry out social engineering attacks on users. - [Lampion Stealer Evolves: Silent Credential Theft via ClickFix Attacks](https://firsthackersnews.com/lampion/): Researchers have discovered a new wave of attacks using the Lampion banking trojan, a malware active since 2019 and now targeting users of Portuguese banks more aggressively. - [WhatsApp Rolls Out Passkey Encryption for Backups](https://firsthackersnews.com/whatsapp-passkey/): WhatsApp has rolled out passkey-encrypted backups, a major upgrade that makes protecting chat history easier and more secure. - [Patch Now: CISA Releases Detections for Zero-Day WSUS Exploit](https://firsthackersnews.com/wsus-exploit/): On October 29, 2025, CISA released new guidance to help organizations detect and reduce attacks exploiting CVE-2025-59287, a critical flaw in Microsoft’s WSUS. The bug allows attackers to run code on servers without logging in, giving them full system control. - [Phishing Attack Hides Malicious Emails with Invisible Characters](https://firsthackersnews.com/invisible-characters/): The attack uses MIME encoding and Unicode soft hyphens to make the subject appear normal to human readers while concealing malicious intent from email scanners. - [Herodotus mimics humans to bypass biometrics](https://firsthackersnews.com/herodotus/): A sophisticated Android banking trojan called Herodotus has appeared, using new techniques to evade detection. - [OpenAI Atlas Browser Vulnerability Exposed to Prompt Injection Attack](https://firsthackersnews.com/openai-atlas-prompt-injection-vulnerability/): A new security flaw has been discovered in the recently released OpenAI Atlas browser. The issue was reported by cybersecurity firm NeuralTrust, which identified a prompt injection technique capable of compromising the browser’s built-in AI assistant. - [PHP Variable Function Malware Targets WordPress Sites, Wordfence Reports](https://firsthackersnews.com/php-variable-function-malware-targets-wordpress-sites-wordfence-reports/): A new analysis by Wordfence security researchers has revealed a recurring malware strain that uses PHP’s variable function feature and browser cookies for advanced obfuscation.The malware has been observed in multiple evolving variants and continues to affect WordPress environments worldwide. - [“Jingle Thief” Cybercrime Group Targets Cloud Gift Card Systems in Retail Sector](https://firsthackersnews.com/jingle-thief-cloud-gift-card-fraud/): Cybersecurity researchers have uncovered a sophisticated cybercriminal operation dubbed “Jingle Thief,” which has been targeting cloud environments linked to retail and consumer service organizations to carry out large-scale gift card fraud. - [Critical Adobe Commerce & Magento Vulnerability CVE-2025-54236 Under Active Attack – Apply Security Patch Now](https://firsthackersnews.com/critical-adobe-commerce-magento-vulnerability-cve-2025-54236/): E-commerce security experts at Sansec have issued a warning about active exploitation targeting a newly disclosed Adobe Commerce and Magento Open Source vulnerability. Known as CVE-2025-54236 and nicknamed SessionReaper, this critical security flaw (CVSS score: 9.1) allows attackers to compromise customer accounts through the Commerce REST API. - [Iranian Hackers Target Over 100 Government Bodies with ‘Phoenix’ Backdoor](https://firsthackersnews.com/iranian-hackers-phoenix-backdoor-cyberattack/): A new cyber espionage campaign has been launched by an Iranian state-sponsored hacking group known as MuddyWater, targeting more than 100 government and diplomatic organisations. The campaign was uncovered by cybersecurity firm Group-IB, which linked the attacks to the group with high confidence. - [Hackers Expose 34 Zero-Day Flaws at Pwn2Own Ireland 2025 — Over $522,000 Awarded on Day One](https://firsthackersnews.com/pwn2own-ireland-2025-zero-day-vulnerabilities/): Day One of Pwn2Own Ireland 2025 concluded with an extraordinary showcase of cybersecurity talent, as researchers demonstrated 34 unique zero-day vulnerabilities across a wide range of consumer devices.The exploits earned participants a combined payout of $522,500, marking one of the most successful opening days in the competition’s history. - [Critical Oracle EBS Vulnerability CVE-2025-61882 Actively Exploited by Cl0p Ransomware Group](https://firsthackersnews.com/clop-exploits-oracle-ebs-cve-2025-61882-remote-code-execution/): A critical security flaw in Oracle E-Business Suite (EBS) is being actively exploited by the Cl0p ransomware group, also known as Graceful Spider, according to a new advisory from CrowdStrike. The first known exploitation was detected on August 9, 2025. - [Akira Ransomware Now Breaches MFA‑Protected SonicWall VPNs, Researchers Warn](https://firsthackersnews.com/akira-ransomware-bypass-sonicwall-vpn-mfa/): The Akira ransomware gang is now reportedly bypassing multi-factor authentication (MFA) protections on SonicWall VPN devices, according to a new report from cybersecurity firm Arctic Wolf. This development represents a serious escalation in the group’s tactics, as the criminals appear to be using stolen one-time password (OTP) seeds to successfully log in—even when MFA is fully enabled. - [Critical Cisco ASA and FTD Zero-Day Vulnerabilities Under Active Attack](https://firsthackersnews.com/cisco-asa-zero-day-vulnerabilities-2025/): Two critical zero-day vulnerabilities in Cisco’s firewall technologies—ASA (Adaptive Security Appliance) and FTD (Firepower Threat Defense)—are currently being actively exploited in the wild, prompting an emergency directive from the U.S. Cybersecurity and Infrastructure Security Agency (CISA). Cisco confirmed the vulnerabilities, tracked as CVE-2025-20333 and CVE-2025-20362, which could allow attackers to bypass authentication, gain root access, and even tamper with device memory. - [ComicForm and SectorJ149 Hackers Ramp Up Eurasian Cyberattacks with Formbook Malware Deployment](https://firsthackersnews.com/comicform-sectorj149-formbook-malware-attacks/): In a series of escalating cyber threats, two distinct hacking groups— the newly identified ComicForm and the pro-Russian SectorJ149—have been deploying the notorious Formbook malware in targeted phishing campaigns across Eurasia and beyond. These attacks, which began as early as April 2025 for ComicForm and November 2024 for SectorJ149, are hitting critical sectors including finance, manufacturing, and energy, raising alarms about potential data breaches and geopolitical motivations. - [Massive Email Spoofing Attack Enabled by DNS Misconfiguration and MikroTik Router Hijack](https://firsthackersnews.com/dns-misconfiguration-email-spoofing-attack/): A large-scale cyberattack has been uncovered. The attack was enabled by DNS misconfigurations across global networks. Over 13,000 MikroTik routers were hijacked. These routers were used in a botnet-powered email spoofing campaign. - [Google Chrome Zero-Day Vulnerability Exploited in the Wild: Urgent Update Required to Patch CVE-2025-10585](https://firsthackersnews.com/google-chrome-zero-day-vulnerability-fix-2025/): Google has issued an emergency security update for its Chrome browser following the discovery of a critical zero-day vulnerability actively being exploited by threat actors. On September 16, 2025, Google's Threat Analysis Group identified CVE-2025-10585, a type confusion flaw in the V8 JavaScript engine that powers Chrome's web rendering capabilities. This vulnerability allows attackers to corrupt memory by misinterpreting data types during JavaScript execution on malicious websites, potentially enabling remote code execution (RCE) on victims' devices. Such exploits can lead to full system compromise, data theft, or malware installation without user interaction, making it a high-risk threat for everyday web users, enterprises, and organizations relying on Chrome. - [Gentlemen Ransomware: Exploiting Drivers and Policies in Sophisticated Cyber Attacks](https://firsthackersnews.com/gentlemen-ransomware-attack/): A newly identified ransomware group known as The Gentlemen has been targeting enterprises across 17 countries since August 2025. Advanced evasion techniques are employed by the group to breach manufacturing, construction, healthcare, and insurance sectors. Critical infrastructure risks are heightened, particularly in healthcare, where public safety could be compromised by these ransomware attacks. - [China-Backed Hackers Used 45 Hidden Domains in Telecom Cyber Attacks](https://firsthackersnews.com/china-backed-salt-typhoon-45-domains-telecom-cyber-attacks/): Threat hunters recently found 45 secret domains linked to Salt Typhoon, a China-backed hacking group. These domains, some created in May 2020, show their cyber espionage started years before the 2024 telecom attacks. For example, the oldest domain, onlineeylitycom, was registered on May 19, 2020, using a fake name, Monica Burch, with a false Los Angeles address. - [iCloud Calendar Phishing Scam: Cybercriminals Use Apple’s Servers](https://firsthackersnews.com/icloud-calendar-phishing-scam-cybercriminals-use-apples-servers/): Cybercriminals are misusing iCloud Calendar to send phishing emails from Apple’s servers. These fake emails look like purchase alerts and trick users. Consequently, they often slip past spam filters. This cybersecurity threat shows how clever phishing scams have become. Therefore, let’s explore how it works, why it’s dangerous, and how to stay safe. - [Hackers Launch Daring $130 Million Bank Heist Attempt on Brazilian Fintech Firm](https://firsthackersnews.com/brazilian-fintech-130m-bank-heist-attempt/): In a shocking cybersecurity incident that highlights the growing threats to global financial systems, hackers recently targeted a prominent Brazilian fintech company in an audacious bid to siphon off $130 million. This attempted bank heist underscores the vulnerabilities in real-time payment platforms and the critical need for robust third-party access controls. If you're in the fintech industry or concerned about cyber threats, here's everything you need to know about this high-stakes breach. - [Zscaler Data Breach 2025: Customer Names, Emails, and Support Data Exposed in SalesLoft and Drift Hack](https://firsthackersnews.com/zscaler-data-breach-2025-salesloft-drift-hack/): In a major cybersecurity incident shaking the tech world, Zscaler, a leading cloud security provider, has confirmed a data breach that exposed sensitive customer information due to a supply chain attack targeting SalesLoft and Drift integrations with Salesforce. This breach, reported on September 1, 2025, has sparked widespread concern about the vulnerabilities in third-party SaaS integrations. If you’re a Zscaler customer or care about data security, here’s everything you need to know about the breach, the exposed data, and how to protect yourself from potential fallout. - [Meet SafeLine: The Future of Free Zero Trust Web Security in 2026](https://firsthackersnews.com/free-safeline-waf/): Every organization - whether it's a global enterprise with thousands of employees or an individual tech enthusiast managing a homelab - needs a Web Application Firewall (WAF). - [New Malware “ClickFix” Targets macOS Users to Steal Login Credentials](https://firsthackersnews.com/clickfix-phishing-macos-captcha-malware/): In recent months, security researchers have identified a new phishing campaign aimed at macOS users, disguised as a CAPTCHA verification process. - [Malicious Packages Target RubyGems and PyPI: Stealing Credentials and Crypto, Leading to Security Overhaul](https://firsthackersnews.com/rubygems-malicious-packages-credential-stealing/): A new set of 60 malicious packages targeting the RubyGems ecosystem has been discovered. These packages masquerade as harmless automation tools for social media, blogging, and messaging platforms, but their true intent is to steal users' credentials. The attack has been ongoing since at least March 2023, according to security firm Socket. In total, these gems have been downloaded over 275,000 times. - [Malicious Go and npm Packages Spread Cross-Platform Malware, Enable Remote Data Wipes](https://firsthackersnews.com/malicious-go-packages-supply-chain-attack/): Cybersecurity researchers have identified 11 malicious Go packages engineered to download and execute additional payloads from remote servers on both Windows and Linux platforms. - [Mozilla Issues Warning About Phishing Attacks Targeting Add-on Developer Accounts](https://firsthackersnews.com/mozilla-phishing-attack-amo-developer-accounts/): Mozilla has issued an urgent security alert to its developer community after identifying a sophisticated phishing campaign aimed at compromising AMO (addons.mozilla.org) accounts. - [Cybercriminals Are Using Free EDR Trials to Disable Your Current EDR](https://firsthackersnews.com/exploit-edr-trial-bypass-endpoint-security/): A sophisticated attack technique has emerged in which cybercriminals exploit free trials of Endpoint Detection and Response (EDR) software to disable existing security protections on compromised systems. - [Apple Fixes Safari Security Flaw Also Targeted in Recent Chrome Zero-Day Exploit](https://firsthackersnews.com/apple-security-update-cve-2025-6558/): On Tuesday, Apple rolled out security updates for its entire software lineup, addressing a vulnerability that Google identified as a zero-day exploit in Chrome earlier this month. - [New Choicejacking Attack Exploits Public Chargers to Steal Data from Phones](https://firsthackersnews.com/choicejacking-usb-attack-security-threat/): Choicejacking is a new USB attack that tricks phones into sharing data at public charging stations, bypassing security prompts in milliseconds. - [Hackers Compromise Toptal’s GitHub, Release 10 Malicious npm Packages With 5,000 Downloads](https://firsthackersnews.com/software-supply-chain-attack-toptal-github-npm/): In the latest example of a software supply chain attack, unidentified threat actors breached Toptal's GitHub organization account and used the access to upload 10 malicious packages to the npm registry. - [A massive data breach on the Leak Zone Dark Web forum has resulted in the exposure of sensitive information, including the IP addresses and geographical locations of over 22 million users](https://firsthackersnews.com/leakzone-data-breach-exposes-22-million-records/): A significant cybersecurity breach has compromised the privacy of users accessing one of the internet's most infamous illegal marketplaces. - [New Phishing Scam Imitates Facebook Login Page to Harvest User Credentials](https://firsthackersnews.com/browser-in-the-browser-phishing-facebook-credentials/): A fast-growing phishing campaign is leveraging a Browser-in-the-Browser (BitB) overlay to mimic Facebook's login page and steal user credentials. - [Stealthy Backdoor Discovered in WordPress Plugins Grants Hackers Long-Term Website Access](https://firsthackersnews.com/wordpress-mu-plugins-malware-backdoor/): A highly sophisticated WordPress malware campaign has been uncovered, exploiting the seldom-monitored mu-plugins (must-use plugins) directory to gain persistent access to compromised sites while avoiding detection by conventional security tools. - [Google Launches OSS Rebuild to Detect Malicious Code in Popular Open-Source Software](https://firsthackersnews.com/oss-rebuild-open-source-security-google/): Google has unveiled a new initiative called OSS Rebuild, aimed at strengthening the security of open-source package ecosystems and defending against software supply chain attacks. - [New DCHSpy Malware Targets Android: Steals WhatsApp Data, Call Logs, and More](https://firsthackersnews.com/dchspy-iranian-cyber-espionage-mobile-data-theft/): "A New DCHSpy Variant Unveiled: Iranian Cyber Group MuddyWater Targets Mobile Data Amid Rising Israel-Iran Tensions" - [CoinDCX Hack: $44.2 Million Drained from the Platform](https://firsthackersnews.com/coindcx-44-million-crypto-hack-2025/): On July 19, 2025, CoinDCX, India's second-largest cryptocurrency exchange, confirmed a sophisticated security breach that led to the theft of approximately $44.2 million from its platform. - [CISA Issues Three ICS Advisories Addressing Vulnerabilities and Exploitation Risks](https://firsthackersnews.com/cisa-ics-vulnerability-advisories-july-2025/): On July 17, 2025, CISA released three important advisories concerning Industrial Control Systems (ICS), targeting critical vulnerabilities in energy monitoring, healthcare imaging, and access control technologies. - [Google’s AI tool Big Sleep has discovered a critical zero-day vulnerability in SQLite and has successfully blocked its active exploitation](https://firsthackersnews.com/big-sleep-ai-blocks-sqlite-0day-vulnerability/): Google’s cutting-edge AI-driven security tool, Big Sleep, has reached a major milestone by identifying and halting the exploitation of a critical SQLite 0-day vulnerability, making it the first instance where an AI agent has actively neutralized a live cyber threat. - [Octalyn Stealer Collects VPN Configs, Passwords, and Cookies into Organized Folder Structures](https://firsthackersnews.com/octalyn-stealer-malware-analysis/): A sophisticated new credential stealer has surfaced on GitHub, masquerading as a legitimate forensic toolkit while targeting sensitive user data such as VPN configurations, browser credentials, and cryptocurrency wallet information. - [Red Bull-Themed Phishing Scams Target Job Seekers to Steal Login Credentials](https://firsthackersnews.com/red-bull-social-media-manager-phishing-scam/): A new wave of phishing emails is circulating globally, posing as offers for a “Social Media Manager” role at Red Bull. - [Google Gemini Workspace Vulnerability Allows Attackers to Conceal Malicious Scripts in Emails](https://firsthackersnews.com/google-gemini-vulnerability-exposes-phishing-risk/): Security researchers have identified a critical vulnerability in Google Gemini for Workspace that allows attackers to insert concealed malicious commands into emails. - [Microsoft Remote Desktop Client Vulnerability Allowed Attackers to Execute Remote Code](https://firsthackersnews.com/microsoft-remote-desktop-client-vulnerability-cve-2025-48817/): A critical security flaw in Microsoft Remote Desktop Client, identified as CVE-2025-48817, could enable attackers to execute arbitrary code on targeted systems. - [WordPress Under Threat: Malicious SEO Plugins Enable Full Site Control](https://firsthackersnews.com/malicious-seo-plugins-wordpress-site-hijack/): A new wave of cyberattacks is actively compromising WordPress websites through the use of malicious SEO plugins capable of enabling full site takeovers. - [Linux at Risk: Critical Sudo Vulnerabilities Enable Root Access for Local Attackers](https://firsthackersnews.com/linux-risk-sudo-vulnerabilities-cve-2025-32462-32463/): Cybersecurity researchers have uncovered two security vulnerabilities in the Sudo command-line utility used in Linux and Unix-like systems, which could allow local attackers to gain root-level access on affected machines. - [CrowdStrike Services has observed SCATTERED SPIDER escalating its attacks across multiple industries](https://firsthackersnews.com/scattered-spider-attack-techniques-crowdstrike-response-guidance/): CrowdStrike Services outlines the techniques used by SCATTERED SPIDER in attacks targeting the aviation, insurance, and retail sectors, and provides guidance to help organizations defend against this threat. - [Critical Vulnerability in Anthropic’s MCP Inspector Exposes AI Developers to Remote Exploits](https://firsthackersnews.com/critical-vulnerability-anthropic-mcp-inspector-ai-security/): A critical security flaw in Anthropic’s Model Context Protocol (MCP) Inspector tool, identified as CVE-2025-49596, has raised alarms in the AI development community. This vulnerability, with a CVSS score of 9.4, allows attackers to execute remote code (RCE) on developers’ machines through malicious websites, posing severe risks to AI systems and sensitive data. Discovered by Oligo Security, the flaw exploits a 19-year-old browser vulnerability known as “0.0.0.0-day” combined with inadequate authentication in MCP Inspector’s default settings. - [Cyber Fattah’s Saudi Games Breach: A New Front in Middle East Cyber Warfare](https://firsthackersnews.com/cyber-fattah-saudi-games-data-leak-hacktivism-iran/): In a significant cyber incident that underscores the escalating digital tensions in the Middle East, the pro-Iranian hacktivist collective known as Cyber Fattah has claimed responsibility for a massive data leak targeting the 2024 Saudi Games. The breach, publicly announced on Telegram on June 22, 2025, involved the exfiltration and subsequent release of thousands of personal records, primarily through SQL database dumps. This operation is widely interpreted as a strategic information campaign orchestrated by Iran and its proxies. - [Microsoft Boosts Windows 10 Security with Updates Until 2026](https://firsthackersnews.com/microsoft-windows-10-security-updates-2026/): Microsoft has unveiled plans to extend security updates for Windows 10 until October 13, 2026, offering critical protection beyond the operating system’s end-of-support date on October 14, 2025. This initiative ensures millions of users stay safeguarded against escalating cyber threats like ransomware while planning their transition to Windows 11. - [U.S. House Bans WhatsApp on Official Devices Citing Security Risks](https://firsthackersnews.com/us-house-bans-whatsapp-government-devices/): In a decisive move highlighting growing concerns over digital privacy and cybersecurity, the United States House of Representatives has officially prohibited the use of WhatsApp on all government-issued devices. The ban, enacted by the Office of Cybersecurity within the House Chief Administrative Office (CAO), applies to WhatsApp across all platforms, including mobile applications, desktop clients, and web versions. - [CoinMarketCap Hacked: Fake Web3 Popup Drains Crypto Wallets in Supply Chain Attack](https://firsthackersnews.com/coinmarketcap-hack-2025-web3-phishing/): In a shocking cryptocurrency security breach, CoinMarketCap, the leading crypto price tracking platform, fell victim to a supply chain attack on June 20, 2025, exposing users to a malicious Web3 wallet drainer campaign. Hackers exploited a vulnerability in the site’s homepage “doodle” image, injecting malicious JavaScript to display fake wallet verification popups. This phishing scam tricked users into connecting their crypto wallets, resulting in stolen digital assets. - [Critical Linux Vulnerabilities Expose Systems to Root Access Exploits](https://firsthackersnews.com/critical-linux-vulnerabilities-root-access-exploits/): Newly discovered Linux vulnerabilities, identified as CVE-2025-6018, CVE-2025-6019, and CVE-2025-6020, threaten major distributions like Ubuntu, Debian, Fedora, and openSUSE Leap 15. Uncovered by the Qualys Threat Research Unit (TRU), these local privilege escalation (LPE) flaws allow attackers to gain full root access, risking data breaches and system compromise. - [Zoomcar Hit by Major Data Breach, Affecting 8.4 Million Users](https://firsthackersnews.com/zoomcar-data-breach-8-4-million-users-exposed/): Zoomcar, India's prominent car-sharing platform, has disclosed a significant data breach affecting approximately 8.4 million of its users. The cybersecurity incident, which came to light on June 9, 2025, involved unauthorized access to the company's information systems, leading to the compromise of a substantial amount of sensitive personal data. This event underscores the growing challenges in digital security within the mobility sector and highlights the constant threat of cyberattacks. - [Paddle Faces $5 Million FTC Penalty for Enabling Tech Support Fraud](https://firsthackersnews.com/paddle-5-million-ftc-settlement-tech-support-scams/): On June 16, 2025, the Federal Trade Commission (FTC) announced a $5 million settlement with Paddle.com Market Limited and its U.S. subsidiary, addressing allegations that the payment processing platform facilitated deceptive tech support scams targeting U.S. consumers, particularly older adults. The settlement highlights the FTC’s focus on holding payment facilitators accountable for enabling fraudulent schemes, raising concerns for the subscription billing and merchant-of-record ecosystem. - [Scattered Spider Hackers Shift Focus to U.S. Insurance Firms: Expert Analysis](https://firsthackersnews.com/scattered-spider-hackers-shift-focus-to-u-s-insurance-firms/): Google’s Threat Intelligence Group has identified multiple cybersecurity breaches in American insurance companies, all consistent with Scattered Spider’s signature tactics. Previously targeting UK and U.S. retailers—including prominent names like Marks & Spencer, Harrods, and Co-op—this hacker collective is now pivoting to a new vertical insurance. - [Coinbase Data Breach 2025: India-Based Insider Leak Impacts 69,000 Users](https://firsthackersnews.com/coinbase-data-breach-2025/): In June 2025, global crypto exchange Coinbase disclosed a serious data breach involving 69,000 customers. The incident stemmed from a malicious insider at TaskUs India, an outsourcing vendor handling Coinbase's customer support operations. - [Apache Tomcat CGI Servlet Flaw Bypasses Security](https://firsthackersnews.com/cve-2025-46701/): A newly discovered security vulnerability, identified as CVE-2025-46701, has been found in Apache Tomcat’s CGI servlet implementation. - [PureHVNC RAT Evades Defenses with Fake Jobs & PowerShell](https://firsthackersnews.com/purehvnc-rat/): This payload—encrypted with AES-256 and protected with .NET Reactor—ultimately loads the PureHVNC RAT. Its configuration files reveal multiple campaign IDs and connections to command-and-control (C2) servers like 85.192.48.3 and 139.99.188.124. - [Nifty[.]com Infrastructure Exploited in Phishing Attack](https://firsthackersnews.com/nifty-com/): Between April and May 2025, threat actors launched a multi-wave phishing campaign by exploiting the trusted infrastructure of Niftycom, a major Japanese ISP. - [Cloud Devices Under Attack: 251 IPs Exploit 75 Flaws](https://firsthackersnews.com/cloud-devices/): On May 8, 2025, cybersecurity analysts at GreyNoise identified a large-scale and tightly coordinated scanning campaign that swept across 75 known exposure points on the internet—all within a 24-hour window. - [Evertz SDN Vulnerability Allows Arbitrary Command Execution](https://firsthackersnews.com/evertz-sdn-vulnerability/): A critical vulnerability (CVE-2025-4009) was found in Evertz’s Software Defined Video Network (SDVN) products, allowing attackers to run remote code without logging in. - [Mozilla Urgently Patches Firefox Pwn2Own 2025 Flaws](https://firsthackersnews.com/pwn2own/): At this year’s Pwn2Own Berlin, researchers revealed two new zero-day flaws in Mozilla Firefox, targeting its content process. - [Threat Actors Use Fake DocuSign for Corporate Data Theft](https://firsthackersnews.com/docusign/): DocuSign is trusted by over 1.6 million customers, including 95% of Fortune 500 companies, and has more than a billion users. But its popularity has also made it a major target for cybercriminals. - [TI WooCommerce Wishlist Flaw: 100,000+ Sites at Risk](https://firsthackersnews.com/ti-woocommerce-wishlist-flaw/): A serious security issue has been discovered in the TI WooCommerce Wishlist plugin, which is used on over 100,000 WordPress sites. - [Linux 6.15 Released: Major Performance & Hardware Upgrades](https://firsthackersnews.com/linux-6-15/): Linux 6.15, released on May 25, 2025, brings major updates to the open-source world with new features and Rust integration. - [Fake DigiYatra Apps Steal Indian Financial Data](https://firsthackersnews.com/digiyatra-apps/): A new phishing scam is targeting Indian air travelers by pretending to be the trusted DigiYatra service. This fake website, digiyatrain, looks like the real government-backed travel platform but is actually stealing personal and financial information from users. - [ChatGPT Deep Research Integrates Dropbox & OneDrive](https://firsthackersnews.com/chatgpt/): OpenAI has upgraded ChatGPT with powerful deep research features, now supporting direct integration with cloud platforms like Dropbox and Microsoft OneDrive. - [Cisco Webex Flaw Allows HTTP Response Tampering](https://firsthackersnews.com/cisco-webex-flaw/): Cisco has patched a security flaw (CVE-2025-20255) in its Webex Meetings service that could let attackers manipulate cached HTTP responses. The bug was rated with a CVSS score of 4.3 (medium severity). - [PowerDNS Vulnerability Enables DoS via TCP Connection](https://firsthackersnews.com/powerdns-vulnerability/): PowerDNS has released an important security update to fix a high-risk vulnerability in DNSdist, its DNS proxy and load balancer. This flaw could allow remote attackers to crash the service by sending specially crafted TCP connections—no login or authentication needed. - [Enhanced Admin Security for Windows 11](https://firsthackersnews.com/administrator-protection/): Microsoft is rolling out a major security upgrade in Windows 11 called Administrator Protection, aimed at stopping privilege escalation attacks and making admin rights more secure. This new feature is part of a broader push to reduce risks from stolen admin tokens and misused permissions. - [RVTools Exploited to Deliver Bumblebee Malware to Windows Users](https://firsthackersnews.com/rvtools/): On May 13, 2025, a sophisticated supply chain attack compromised the trusted VMware administration tool RVTools, turning it into a malware delivery platform. - [AutoIT Scripts Exploited to Deploy Windows Malware](https://firsthackersnews.com/autoit/): Cybersecurity researchers have discovered a sophisticated malware campaign that leverages AutoIT, a scripting language known for its seamless integration with Windows environments. - [Auth0-PHP Vulnerability: Unauthorized Access Risk](https://firsthackersnews.com/auth0-php/): A critical vulnerability has been found in the Auth0-PHP SDK that could let attackers bypass authentication by brute-forcing session cookie tags. - [Cache Timing Bypasses Windows 11 KASLR, Reveals Kernel Base](https://firsthackersnews.com/kaslr/): Researchers have found a way to bypass Kernel Address Space Layout Randomization (KASLR) on fully updated Windows 11 systems using a cache timing side-channel attack. - [Zoom Phishing Steals Login Credentials](https://firsthackersnews.com/zoom/): A new phishing campaign is tricking users with fake Zoom meeting invites that appear to come from coworkers. - [Xerox FreeFlow Print Server v2: April 2025 Security Patch](https://firsthackersnews.com/xerox-freeflow/): Xerox has rolled out its April 2025 security update for the FreeFlow Print Server v2 (Windows 10), fixing over 40 critical vulnerabilities and strengthening encryption for safer file transfers. - [Critical Adobe Illustrator Vulnerability (CVE-2025-30330) – Update Now](https://firsthackersnews.com/adobe-illustrator/): Adobe has released an urgent security update for Illustrator after discovering a critical vulnerability (CVE-2025-30330) that affects both Windows and macOS versions of Illustrator 2024 and 2025. - [Critical Command Injection Flaw Found in F5 BIG-IP Systems (CVE-2025-31644)](https://firsthackersnews.com/cve-2025-31644/): A critical vulnerability, CVE-2025-31644, has been discovered in F5 BIG-IP systems running in Appliance mode. The flaw allows authenticated administrators to run arbitrary system commands, bypassing key security protections. - [VMware Tools Vulnerability: File Modification & Malicious Ops](https://firsthackersnews.com/vmware-tools/): A new macOS vulnerability, CVE-2025-31258, has been disclosed by security researcher wh1te4ever, along with a proof-of-concept (PoC) exploit published on GitHub. - [VMware Patches Security Flaw in VMware Tools (CVE-2025-22247)](https://firsthackersnews.com/cve-2025-22247/): Broadcom-owned VMware has released security updates to fix a moderate-severity vulnerability (CVE-2025-22247) in VMware Tools, which has a CVSS score of 6.1. - [IPFire 2.29: Core Update 194 is Here!](https://firsthackersnews.com/ipfire-2-29/): The IPFire team has officially released IPFire 2.29 – Core Update 194, bringing a host of security fixes, performance improvements, and new features designed to protect networks of all sizes. - [Phishing Bypasses Email Security with Blob URLs](https://firsthackersnews.com/email-security/): Cofense Intelligence researchers have uncovered a phishing method that uses Blob URIs to sneak fake login pages into users’ inboxes while avoiding email security filters. - [New Malware Hides in Bitmap Images of .NET Apps](https://firsthackersnews.com/bitmap-images/): Cybersecurity experts at Palo Alto Networks’ Unit 42 have discovered a new method attackers use to hide malware inside bitmap images found in harmless-looking 32-bit .NET applications. - [Cybercriminals Exploit IT Help Desks as Entry Point for Attacks](https://firsthackersnews.com/it-help-desks/): Cybercriminals are increasingly pretending to be IT staff or trusted authorities to trick employees into giving them access to sensitive systems, recent cybersecurity reports reveal. - [Cisco Patches Critical SISF Vulnerability Affecting Multiple Products](https://firsthackersnews.com/cisco-2/): Cisco has issued critical security updates to address a vulnerability in its Switch Integrated Security Features (SISF), which affects several of its software platforms. - [Agenda Ransomware Adds SmokeLoader & NETXLOADER](https://firsthackersnews.com/agenda-ransomware-2/): The Agenda ransomware group (Qilin) ramped up attacks in early 2025, hitting key sectors worldwide with tools like NETXLOADER and SmokeLoader, Trend Micro reports. - [Wormable Linux Rootkit Steals SSH Keys, Escalates Privileges](https://firsthackersnews.com/linux-rootkit/): Researchers at ANY.RUN have discovered a complex attack using the Diamorphine rootkit to install a crypto miner on Linux systems, showing how open-source tools are being misused in cyberattacks. - [Pahalgam Attack Lure Used in Cyberattacks Against Indian Government](https://firsthackersnews.com/pahalgam-attack-lure/): In a targeted cyber espionage campaign, attackers are using fake documents referencing the recent Pahalgam attack to go after Indian government personnel. Discovered in early May 2025, the campaign relies on spear-phishing emails with attachments meant to exploit officials' interest in the ongoing security situation. - [Hackers Exploit 21 Apps to Take Full Control of E-Commerce Servers](https://firsthackersnews.com/supply-chain-attack-2/): Cybersecurity firm Sansec has exposed a sophisticated supply chain attack that compromised 21 popular e-commerce applications, giving hackers full control over hundreds of online stores. - [Critical Apache ActiveMQ Vulnerability Allows Remote Code Execution](https://firsthackersnews.com/apache-activemq-vulnerability/): A serious security flaw has been discovered in Apache ActiveMQ’s .NET Message Service (NMS) library. This vulnerability, tracked as CVE-2025-29953, could allow remote attackers to run malicious code on systems that haven’t been updated. - [Quantum Computing’s Cybersecurity Impact: Key Considerations for CISOs](https://firsthackersnews.com/quantum-computing/): Quantum computing is moving from theory to reality—and with it comes a serious challenge for today’s encryption systems. For Chief Information Security Officers (CISOs), the threat isn’t in the distant future. It’s already starting to take shape. - [Tesla Model 3 VCSEC Flaw Allows Arbitrary Code Execution](https://firsthackersnews.com/tesla-model-3/): A serious security flaw in Tesla’s Model 3 was revealed during the 2025 Pwn2Own hacking competition. The issue allowed attackers to run malicious code remotely through the car’s Tire Pressure Monitoring System (TPMS). - [Commvault Discloses Azure Cloud Breach After Zero-Day Exploit](https://firsthackersnews.com/commvault/): Commvault, a global company known for data protection and information management, has confirmed a cyberattack on its Azure cloud environment earlier this week. - [Netgear EX6200 Bug Allows Remote Data Theft](https://firsthackersnews.com/netgear-ex6200/): Security researchers have found three serious flaws in the Netgear EX6200 Wi-Fi extender that let hackers access the device and steal data. - [CISO to CEO: A Reporting Structure Argument](https://firsthackersnews.com/ciso-to-ceo/): In today’s cyber threat landscape, who the Chief Information Security Officer (CISO) reports to is more than just an organizational detail—it directly impacts how well a company can respond to cyber risks. - [Nitrogen Ransomware: Cobalt Strike & Log Wipe in Attacks](https://firsthackersnews.com/nitrogen-ransomware/): Cybercriminals have used the Nitrogen ransomware campaign to target victims through fake online ads. - [Chrome Sandbox Security Flaw: Technical Analysis](https://firsthackersnews.com/cve-2025-2783/): A serious security flaw, CVE-2025-2783, has been found in Google Chrome, affecting the Mojo inter-process communication (IPC) system on Windows. - [Magento Carding Attack Leverages Fake GIFs and Proxy Malware](https://firsthackersnews.com/magento/): A multi-stage carding attack targeted a Magento eCommerce site running outdated version 1.9.2.4, unsupported since June 2020. Unpatched flaws allowed malware to use a fake .gif file, tamper with browser sessionStorage, and deploy a reverse proxy to steal credit card data, credentials, cookies, and more. - [Defender XDR False Positive Leaked 1700+ Docs](https://firsthackersnews.com/defender-xdr/): A significant data leak involving Microsoft Defender XDR exposed over 1,700 sensitive documents from many organizations, triggered by a critical false positive error. - [Chrome UAF Vulnerabilities: Active Exploits](https://firsthackersnews.com/chrome-uaf-vulnerability/): Researchers discovered two critical UAF vulnerabilities in Chrome, actively exploited in the wild, but Google’s MiraclePtr defense has now blocked them, strengthening browser security. - [Ivanti 0-Day Exploited for DslogdRAT & Web Shell](https://firsthackersnews.com/dslogdrat/): Threat actors have exploited a zero-day flaw in Ivanti Connect Secure (CVE-2025-0282) to install a web shell and a remote access trojan (DslogdRAT), according to JPCERT/CC. - [Commvault RCE Exploited, PoC Available](https://firsthackersnews.com/cve-2025-34028/): A major remote code execution (RCE) vulnerability, CVE-2025-34028, has been discovered in Commvault’s on-premise backup and recovery software, posing serious risks to enterprises and managed service providers worldwide. - [NFC Exploited to Steal Funds from ATMs and POS](https://firsthackersnews.com/nfc-technology/): Cybercriminals, mainly from Chinese underground networks, are using NFC (Near Field Communication) technology to carry out large-scale fraud at ATMs and point-of-sale (POS) terminals. - [TP-Link Router Vulnerabilities Enable Malicious SQL Execution](https://firsthackersnews.com/tp-link-router/): Cybersecurity researchers have found critical SQL injection vulnerabilities in four TP-Link router models, which could allow attackers to bypass authentication, execute malicious commands, and potentially take control of the devices. - [Impersonated Dev Tools on npm/PyPI Used for Credential Theft](https://firsthackersnews.com/npm-pypi/): The Socket Threat Research Team has discovered three malicious open-source packages—two on PyPI and one on npm—designed to steal sensitive cryptocurrency data like mnemonic seed phrases and private keys. - [Hackers Leverage Cloudflare for RAT Deployment](https://firsthackersnews.com/asyncrat-2/): Hackers have been using Cloudflare tunnels since February 2024 to host malware and spread remote access trojans like AsyncRAT, according to Sekoia TDR. - [Infostealer Malware Surges 84% in Phishing Emails, IBM Warns](https://firsthackersnews.com/infostealer-malware-2/): A recent report from IBM X-Force reveals that infostealer malware delivered through phishing emails has spiked by 84% week-over-week in 2024. - [KeyPlug Server Leak Reveals Fortinet Exploits](https://firsthackersnews.com/keyplug-server-malware/): Cybersecurity researchers recently uncovered a server linked to the KeyPlug malware, used by the threat group RedGolf (also known as APT41). The server was accidentally exposed for less than 24 hours but revealed valuable insight into the group’s advanced attack methods. - [AnythingLLM Systems at Risk: Critical Remote Code Execution Vulnerability Discovered](https://firsthackersnews.com/cve-2024-13059/): A major security flaw (CVE-2024-13059) was found in the open-source AI tool AnythingLLM. Discovered in February 2025, the bug lets attackers with admin access run harmful code remotely, putting systems at serious risk. - [Server-Side Phishing Targets Portals for Logins](https://firsthackersnews.com/server-side-phishing/): Attackers are now using server-side phishing to target employee and member login portals, making it harder to detect and analyze their tactics. - [Two Apple Zero-Days Under Active iOS Attack](https://firsthackersnews.com/ios-attack/): Apple has released iOS 18.4.1 and iPadOS 18.4.1 to fix two zero-day vulnerabilities that were actively exploited in highly targeted and sophisticated attacks. - [Critical Chrome Flaw Allowed Data Theft & Unauthorized Access](https://firsthackersnews.com/chrome-vulnerabilities-2/): Google has released an urgent security update for its Chrome browser after two critical vulnerabilities were found, putting users at risk of data theft and unauthorized access. - [Key Security Awareness Metrics for CISOs](https://firsthackersnews.com/security-awareness/): As companies shift to zero-trust security models, security awareness has become a key line of defense. - [Microsoft Teams File Sharing Down Due to Outage](https://firsthackersnews.com/microsoft-teams-3/): Many Microsoft Teams users around the world are currently facing issues with file sharing due to an unexpected outage. This disruption is affecting communication and collaboration across businesses, schools, and other organizations. - [VMware ESXi 8.0 Update 3e Now Available for Free](https://firsthackersnews.com/vmware-esxi-8-0-update/): VMware has announced the release of ESXi 8.0 Update 3e, the latest version of its industry-leading hypervisor. The update, released on April 10, 2025, includes several enhancements, important security fixes, and new features that further strengthen VMware’s position in the virtualization space. - [Smishing Attack Targets Toll Road U Users](https://firsthackersnews.com/smishing-campaign/): Cisco Talos researchers have found a major smishing campaign targeting U.S. toll road users. Active since October 2024, the scam tricks people with fake toll payment messages to steal personal and financial details. - [BPFDoor Malware Leverages Reverse Shell for Network Control](https://firsthackersnews.com/bpfdoor-malware/): A new wave of cyber espionage has highlighted BPFDoor, a stealthy malware used to secretly access and control networks. - [Stealthy ResolverRAT Employs Advanced In-Memory Execution](https://firsthackersnews.com/resolverrat/): A new remote access trojan (RAT) called ResolverRAT is posing a serious threat to businesses around the world. It uses advanced in-memory execution and evasion methods to slip past traditional security tools. - [Microsoft Adds Antimalware Scan to Exchange & SharePoint Security](https://firsthackersnews.com/antimalware-scan/): Microsoft has added a major security upgrade to Exchange Server and SharePoint Server by integrating them with Windows Antimalware Scan Interface (AMSI). This helps protect these important systems, which are often targeted by cyberattacks. - [Critical Dell PowerScale Vulnerabilities Allow Account Takeover](https://firsthackersnews.com/powerscale-onefs/): Dell Technologies has released a critical alert about serious flaws in PowerScale OneFS that could let attackers gain control of high-level user accounts. The most dangerous bug, rated 9.8 on the CVSS scale, allows remote attackers to take over systems without needing to log in. - [ViperSoftX Malware Hidden in Cracked Software](https://firsthackersnews.com/vipersoftx-malware/): AhnLab Security Intelligence Center (ASEC) discovered a cyber attack targeting Korean users with ViperSoftX malware. - [New Email Attack Hits Office 365 Users and Delivers Malware](https://firsthackersnews.com/office-365/): Cybersecurity experts have found a new phishing attack that steals Office 365 credentials and installs malware, putting many organizations at risk. - [Windows Active Directory Flaw Leads to Unauthorized Privilege Escalation](https://firsthackersnews.com/cve-2025-29810/): Microsoft has released an urgent patch for a serious security flaw—CVE-2025-29810—affecting Windows Active Directory Domain Services (AD DS). This vulnerability allows attackers to escalate privileges and potentially take full control of a network domain. - [Ivanti RCE flaw affects over 5,000 devices](https://firsthackersnews.com/ivanti-rce-flaw/): More than 5,000 Ivanti Connect Secure devices remain exposed to a high-risk remote code execution (RCE) vulnerability, CVE-2025-22457, according to data from the Shadowserver Foundation. - [CISA Warns of Active CrushFTP Authentication Bypass Exploit](https://firsthackersnews.com/cve-2025-31161/): CISA has issued a warning about a critical vulnerability (CVE-2025-31161) in CrushFTP that is being actively exploited. This flaw allows attackers to bypass authentication, putting systems at serious risk. The agency has added it to the Known Exploited Vulnerabilities Catalog, urging organizations to patch immediately. - [Lazarus Hides Malicious npm Code Using Hex Encoding](https://firsthackersnews.com/lazarus-group/): North Korea’s Lazarus Group has ramped up its Contagious Interview campaign by using new npm packages with hex-encoded strings to evade detection. These packages deliver BeaverTail infostealers and RAT loaders, aiming to steal credentials, financial info, and crypto wallets. SecurityScorecard found 11 such packages with 5,600+ downloads tied to Lazarus tactics. - [NEPTUNE RAT: Windows Malware Steals Passwords from Over 270 Apps](https://firsthackersnews.com/neptune-rat/): A new cyber threat called Neptune RAT is raising concerns among Windows users, as it targets sensitive data and has advanced malicious features. - [New spyware tricks Android users for passwords](https://firsthackersnews.com/spyware/): A new Android spyware app uses a password prompt to prevent uninstallation, making it difficult for users to remove without the installer's password. - [Oracle Confirms Data Breach, Begins Notifying Clients](https://firsthackersnews.com/oracle-breach/): Oracle confirmed a data breach affecting its older Gen 1 servers, its second incident in weeks, highlighting legacy system vulnerabilities and data security concerns. - [Qilin Ransomware Attack: Fake ScreenConnect Login for Admin Access](https://firsthackersnews.com/qilin-ransomware-attack/): A ransomware attack targeted MSPs via phishing emails, deploying Qilin ransomware across customer environments. - [Trinda Malware: Android Attack Replaces Call Numbers](https://firsthackersnews.com/trinda-malware/): Kaspersky Lab has discovered a new version of the Triada Trojan targeting Android devices. This variant is pre-installed in counterfeit smartphones, often sold at discounted prices through unauthorized online stores. - [Cisco AnyConnect VPN Server Vulnerable to DoS Exploits](https://firsthackersnews.com/cisco-anyconnect-vpn-vulnerability/): Cisco has revealed a critical flaw (CVE-2025-20212) in its AnyConnect VPN Server for Meraki MX and Z Series devices, enabling authenticated attackers to cause denial-of-service (DoS). The issue arises from an uninitialized variable during SSL VPN session setup and impacts over 20 enterprise hardware models. - [Phishing Campaign Aims to Steal Investor Login Details](https://firsthackersnews.com/monex-securities/): Symantec has discovered a sophisticated phishing campaign targeting Monex Securities (マネックス証券), a leading online securities firm in Japan. Formed through the merger of Monex, Inc. and Nikko Beans, Inc., the company provides financial services to individual investors, making it an attractive target for cybercriminals. - [X (Twitter) Data Breach: 400GB Leak Exposes 2.8 Billion Records](https://firsthackersnews.com/x-twitter-data-breach/): A massive 400GB dataset with info from 2.87 billion X (formerly Twitter) users has appeared on hacker forums. Allegedly from January 2025, it's one of the biggest social media leaks ever. - [IRS-themed attacks are on the rise, targeting taxpayers’ mobile devices](https://firsthackersnews.com/irs-attacks/): With the U.S. tax deadline nearing, scammers are ramping up IRS-themed attacks. McAfee Labs reports a rise in mobile scams using fake IRS texts and websites to steal personal and financial data. - [Critical HP Vulnerability Allows Remote Code Execution and Authentication Bypass](https://firsthackersnews.com/hp-vulnerability/): A newly disclosed flaw in HPE’s Insight CMU v8.2, CVE-2024-13804, allows attackers to bypass authentication and execute remote commands, posing a major risk to HPC clusters. - [Earth Alux Hackers Deploy VARGIET Malware to Attack Organizations](https://firsthackersnews.com/vargiet-malware/): Recent cyberattacks by the APT group Earth Alux have exposed the use of advanced malware, including the VARGEIT backdoor, to breach critical industries. Active since 2023, the China-linked group has targeted organizations in the Asia-Pacific and Latin America, focusing on government, technology, logistics, manufacturing, telecommunications, IT services, and retail sectors. - [BlackSuit Ransomware: Fake Zoom Installer Warning](https://firsthackersnews.com/blacksuit-ransomware/): Cybersecurity analysts have identified a campaign using a fake Zoom installer to spread BlackSuit ransomware on Windows systems. DFIR experts report that attackers are tricking users into downloading malware disguised as legitimate software, leading to severe network disruptions. - [Microsoft tool fixes Windows boot issues](https://firsthackersnews.com/quick-machine-recovery/): Microsoft has introduced Quick Machine Recovery, a new tool designed to automatically detect, diagnose, and resolve critical boot failures in Windows devices. - [Mozilla Patches Windows Vulnerability Following Chrome Zero-Day](https://firsthackersnews.com/cve-2025-2857/): Mozilla has released an urgent update for Firefox on Windows to fix a critical vulnerability. This follows a similar issue found in Google Chrome, emphasizing the need for quick action. - [Tor Browser 14.0.8: Urgent Windows Release](https://firsthackersnews.com/tor-browser-14-0-8/): The Tor Project has quickly released an emergency update, Tor Browser 14.0.8, available only for Windows users. It can be downloaded from the Tor Browser download page and the Tor distribution directory. This update includes crucial security fixes based on Mozilla Firefox, enhancing user safety and privacy. - [Detecting Deep Learning Backdoors: The DeBackdoor Approach](https://firsthackersnews.com/detecting-deep-learning-backdoors-the-debackdoor-approach/): Researchers from Qatar Computing Research Institute and Mohamed bin Zayed University developed DeBackdoor, a framework to detect hidden backdoor attacks in deep learning models used in critical systems like self-driving cars and medical devices. - [SHELBY malware: GitHub C2, data theft](https://firsthackersnews.com/shelby-malware/): The SHELBY malware family includes two key components: SHELBYLOADER and SHELBYC2. - [Fake Snow White downloads spread malware to viewers](https://firsthackersnews.com/malicious-snow-white-downloads/): With no official streaming release for the new Snow White, many users are resorting to piracy, making them vulnerable to cyber threats. Veriti researchers uncovered a campaign where attackers distribute malware through torrent sites, exploiting eager viewers looking for unauthorized downloads. - [46 flaws: solar inverters open to attack](https://firsthackersnews.com/solar-inverters/): Forescout Vedere Labs found 46 vulnerabilities in solar inverters from Sungrow, Growatt, and SMA. Exploiting these flaws could disrupt power grids and compromise user privacy. Over 80% of solar vulnerabilities in the last three years were high or critical, with 30% allowing full system takeover. - [Cloudflare: password error, outage](https://firsthackersnews.com/cloudflare/): Cloudflare's 1-hour outage, affecting services like R2 storage and Cache Reserve, was caused by a faulty credential rotation in the R2 Gateway service. - [CrushFTP warns: unauthorized access via HTTP(S)](https://firsthackersnews.com/crushftp/): CrushFTP and Next.js face critical vulnerabilities, raising security concerns. Rapid7 warns these flaws could lead to data breaches and unauthorized access. - [Malicious AI tools up 200%, ChatGPT jailbreaks +52%](https://firsthackersnews.com/malicious-ai-tools/): In 2024, AI-related threats grew as cybercriminals increasingly targeted large language models (LLMs). - [Banking malware hits 248,000 mobile users via social engineering](https://firsthackersnews.com/banking-malware/): In 2024, mobile banking malware affected nearly 248,000 users, a 3.6x jump from 69,000 the previous year. The surge was most significant in the year's second half, highlighting growing threats in mobile finance. - [WordPress plugin vulnerability exposes websites to SQL injection](https://firsthackersnews.com/wordpress-plugin-vulnerability/): A critical vulnerability in the popular WordPress plugin GamiPress, identified as CVE-2024-13496, allows unauthenticated SQL injection attacks and carries a high CVSS 3.1 score of 7.5, highlighting its serious risk. - [Chinese ‘Web Shell Whisperer’ exploits shells and tunnels for stealthy access](https://firsthackersnews.com/web-shell-whisperer/): Sygnia uncovered a cyber espionage operation by a China-linked group, “Weaver Ant.” - [A recent update’s code error caused the Outlook Web outage, Microsoft reports](https://firsthackersnews.com/outlook-web-outage/): Microsoft experienced a major outage on March 19, 2025, affecting Outlook on the web. The issue was caused by a code error in a recent update, preventing many users from accessing their accounts and communication tools. - [Dragon RaaS leads crimeware with new attack tactics](https://firsthackersnews.com/dragon-raas/): Dragon RaaS, a ransomware group blending hacktivism and cybercrime, has become a key player in the “Five Families” syndicate, alongside ThreatSec, GhostSec, Blackforums, and SiegedSec. - [Zero-Hour Phishing Attacks Increase by 130%](https://firsthackersnews.com/zero-hour-phishing-attacks/): Menlo Security's annual Browser Security Report reveals a 130% increase in zero-hour phishing attacks and growing use of generative AI in cybercrime. The report analyzed over 752,000 browser-based phishing attacks, highlighting key trends in cybersecurity. - [New malware uses JPEG files to hide and spread infostealers](https://firsthackersnews.com/jpeg-files/): A new cyber threat hides malware in JPEG images to steal credentials. Users download seemingly harmless images, which extract sensitive data from browsers, emails, and FTP apps. The malware then downloads additional infostealers like Vidar, Raccoon, and Redline. - [Threat Actors Steal 3.2 Billion Credentials, Infect 23 Million Devices](https://firsthackersnews.com/billion-stolen-credentials/): Flashpoint's 2024 report reveals a sharp rise in cyber threats, with 3.2 billion stolen credentials — a 33% increase from last year — driving ransomware and data breaches. - [VPN Vulnerabilities Emerge as Key Target for Cyber Attacks on Organizations](https://firsthackersnews.com/vpn-vulnerabilities/): VPN vulnerabilities have become a major threat to organizations worldwide. Cybercriminals and state-sponsored hackers are increasingly exploiting these flaws to access sensitive networks. Key vulnerabilities like CVE-2018-13379 and CVE-2022-40684 are commonly used to steal credentials and gain control over VPN systems. - [Warning: Malware Found in Free Word-to-PDF Converters](https://firsthackersnews.com/word-to-pdf-converters/): The FBI warns that free file conversion tools are being used to spread malware. The FBI’s Denver Field Office calls this scam “rampant,” targeting users looking to convert files like Word documents to PDFs or videos to GIFs. - [Millions of RSA keys exposed: major flaws](https://firsthackersnews.com/rsa-keys/): A recent study revealed a major vulnerability in RSA keys, especially in IoT devices. Researchers found that about 1 in 172 keys share a factor with another, making them vulnerable to attack. This issue is mainly caused by poor random number generation during key creation, which is common in IoT devices with limited entropy sources. - [Wazuh SIEM vulnerability enables remote code execution](https://firsthackersnews.com/wazuh-siem/): A critical vulnerability, CVE-2025-24016, has been found in the Wazuh SIEM platform, affecting versions 4.4.0 to 4.9.0. - [RansomHub via SocGholish, compromised sites](https://firsthackersnews.com/socgholish-2/): Threat actors behind SocGholish are now using hacked websites to spread RansomHub ransomware. The attack starts with compromised sites delivering malicious JavaScript to visitors. - [SSRF Vulnerabilities Targeted by 400+ IPs in Coordinated Attack](https://firsthackersnews.com/ssrf-vulnerability/): GreyNoise has reported a coordinated wave of attacks exploiting Server-Side Request Forgery (SSRF) vulnerabilities across various platforms. According to the firm, over 400 IP addresses were identified actively targeting multiple SSRF-related CVEs simultaneously, suggesting a well-organized campaign. - [Juniper Junos OS Vulnerability Exploited, CISA Warns](https://firsthackersnews.com/juniper-junos-os-vulnerability/): CISA has warned about a Junos OS vulnerability (CVE-2025-21590) in Juniper Networks. This flaw allows high-privileged local attackers to inject code, risking system compromise. - [DCRat Malware Uses YouTube for Credential Theft](https://firsthackersnews.com/dcrat-malware/): In 2025, a new wave of DCRat backdoor attacks has emerged, using the Malware-as-a-Service (MaaS) model. Cybercriminals behind this campaign distribute the malware and offer technical support and infrastructure for hosting command-and-control (C2) servers. This resurgence shows the increasing sophistication of cybercrime targeting unsuspecting users. - [PHP XXE Vulnerability Exposes Config Files and Private Keys](https://firsthackersnews.com/php-xxe-vulnerability/): A newly discovered XML External Entity (XXE) injection vulnerability in PHP allows attackers to bypass security measures and access sensitive configuration files and private keys. - [CISA Warns of Windows Win32 Kernel Vulnerability](https://firsthackersnews.com/cve-2025-24983/): CISA has warned about a critical Windows Win32 kernel vulnerability, identified as CVE-2025-24983. This use-after-free flaw in the Win32k component could let authorized attackers gain elevated privileges. It falls under CWE-416, which relates to use-after-free issues that may enable unintended code execution. - [Android Zygote Flaw Enables Code Execution and Privilege Escalation](https://firsthackersnews.com/android-zygote-flaw/): A major vulnerability, CVE-2024-31317, has been discovered in Android, allowing attackers to exploit the Zygote process for system-wide code execution and privilege escalation. This flaw affects devices running Android 11 or earlier, presenting a serious security risk. - [New Rust Code in Linux Kernel Addresses Memory Bugs](https://firsthackersnews.com/rust-code/): Rust in the Linux kernel enhances memory safety, a key focus in development. Launched in 2021 by Miguel Ojeda, Rust for Linux aims to reduce vulnerabilities in new drivers and modules, not replace the entire kernel. - [iOS 18.4 Beta 3: New Features](https://firsthackersnews.com/ios-18-4-beta-3-release/): Apple released iOS 18.4 Beta 3 on March 10, 2025, for developers (build number 22E5222f). - [Critical Flaw in Microsoft’s Time Travel Debugging Tool Hides Attacker Activity](https://firsthackersnews.com/microsofts-time-travel-debugging-ttd-tool/): Microsoft’s Time Travel Debugging (TTD) tool, used to record and replay Windows programs, has critical bugs in how it handles CPU instructions, according to Mandiant. - [Microsoft Warns Silk Typhoon Hackers Target IT Supply Chain via Cloud](https://firsthackersnews.com/microsoft-says-silk-typhoon/): Microsoft says Silk Typhoon is now targeting remote management tools and cloud apps for access, showing a wide and fast exploitation strategy. - [LummaStealer Threat Hidden in Fake CAPTCHAs: Silent Installation Alert](https://firsthackersnews.com/lummastealer/): Cybersecurity researchers at G DATA have discovered a new malware campaign using fake booking websites to spread LummaStealer malware via fake CAPTCHA prompts. This shift in distribution, found in January 2025, moves the malware away from platforms like GitHub and Telegram to malvertising methods. - [Cisco Webex for BroadWorks Flaw Could Expose User Credentials](https://firsthackersnews.com/broadworks-flaw/): Cisco has disclosed a vulnerability in Webex for BroadWorks that could let attackers intercept user credentials and data in certain setups. The issue, tracked as CSCwo20742, affects Release 45.2 on Windows. Cisco released configuration fixes and recommends restarting affected systems. - [10,000+ WordPress sites exposed by donation plugin vulnerability](https://firsthackersnews.com/plugin-vulnerability/): A serious flaw in the popular GiveWP Donation Plugin has put over 10,000 WordPress sites at risk of remote code execution since March 3, 2025. - [Google’s Email Shield hides your real email from apps](https://firsthackersnews.com/googles-email-shield/): Google is developing Shielded Email, a tool that creates disposable email aliases to protect users’ real Gmail addresses when signing up for apps and services, helping to reduce spam. - [Android Phones Unlocked via Cellebrite Zero-Day Exploit](https://firsthackersnews.com/cellebrite-zero-day-exploit/): Amnesty International’s Security Lab discovered a cyber-espionage campaign in Serbia, where authorities used a zero-day exploit chain from Cellebrite to unlock a student activist's Android phone. - [Chinese Hackers Exploit Check Point VPN Zero-Day](https://firsthackersnews.com/check-point-vpn-flaw/): Chinese hackers exploited a patched Check Point VPN flaw (CVE-2024-24919) to target organizations in Europe, Africa, and the Americas, researchers say. - [Hackers Can Break Into Car Cameras in Minutes by Exploiting Security Flaws](https://firsthackersnews.com/dashcams/): At Black Hat Asia 2025, experts will reveal a major flaw in modern dashcams, showing how hackers can use these devices to steal data and invade privacy. - [Pass-the-Cookie attacks bypass MFA, granting full account access](https://firsthackersnews.com/pass-the-cookie-attacks/): Pass-the-Cookie attacks let hackers bypass MFA using stolen browser cookies, putting corporate accounts at risk across Office 365, Azure, and more. - [Cisco Nexus Vulnerability Allows Malicious Command Injection](https://firsthackersnews.com/cisco-nexus-vulnerability/): Cisco has released a critical advisory for a command injection vulnerability (CVE-2025-20161) affecting its Nexus 3000 and 9000 Series switches running in standalone NX-OS mode. - [The SafetyCore app from Google scans photos on Android devices](https://firsthackersnews.com/safetycore-app/): Recent reports show Google’s SafetyCore service, which scans content on devices, has been quietly installed on Android 9 and newer devices since October 2024. - [WordPress Plugin Flaw Exposes Millions to Script Injection](https://firsthackersnews.com/wordpress-plugin-flaw-2/): A critical flaw in the Essential Addons for Elementor plugin, affecting over 2 million WordPress sites, exposes them to script injection attacks through malicious URL parameters. - [GRUB2 Vulnerabilities Put Millions of Linux Devices at Risk](https://firsthackersnews.com/grub2-vulnerabilities/): GRUB2 vulnerabilities expose millions of Linux devices to secure boot bypass and remote code execution. Discovered during a security audit, these flaws impact filesystem parsing, memory management, and network settings. Patches released on February 18, 2025, address issues like heap overflows and memory corruption in UEFI environments. - [Updated TgToxic Malware Now Steals Login Credentials](https://firsthackersnews.com/tgtoxic-android-malware/): The TgToxic Android malware, first found in July 2022, has been updated to better steal login credentials and financial data. Initially targeting Southeast Asia through phishing and fake apps, it now also affects users in Europe and Latin America. - [Linux Systems Under Attack: New Auto-Color Malware Grants Remote Access](https://firsthackersnews.com/linux-malware-2/): Palo Alto Networks researchers have discovered a new Linux malware, "Auto-Color," which poses a serious threat due to its advanced evasion methods and ability to give attackers full remote access to infected systems. - [Google Warns of Phishing Attacks on Higher Education Institutions](https://firsthackersnews.com/phishing-attack/): Google and Mandiant warn of rising phishing attacks on U.S. higher education, exploiting academic schedules and institutional trust since August 2024. - [Sliver C2 Server Flaw Enables TCP Hijacking and Data Interception](https://firsthackersnews.com/sliver-c2-server-flaw/): A critical flaw (CVE-2025-27090) in the Sliver C2 server allows attackers to hijack TCP connections using SSRF, enabling traffic interception and manipulation. - [Cybercriminals Deploy XLoader Malware Using Eclipse Jarsigner in ZIP Archives](https://firsthackersnews.com/xloader-malware-2/): A malware campaign spreading XLoader malware uses DLL side-loading by exploiting a legitimate Eclipse Foundation tool, jarsigner, which is part of the IDE package. The malware is distributed via ZIP archives containing the executable and sideloaded DLLs to execute the attack. - [Phishing targets CEOs, CTOs, and top decision-makers](https://firsthackersnews.com/phishing-campaign-2/): A recent phishing campaign by Hackmosphere exposed vulnerabilities among top decision-makers, like CEOs and CTOs. The study highlights how cybercriminals use social engineering tactics to target high-ranking executives, stressing the importance of stronger security measures. - [Fake Chrome Update Drops DriverEasy Malware via Dropbox](https://firsthackersnews.com/drivereasy-malware/): Researchers discovered that the malware, disguised as a Chrome update, uses Dropbox’s API to steal credentials and is linked to North Korea’s “Contagious Interview” cyber-espionage campaign. - [PoC exploit released for vulnerabilities in Ivanti Endpoint Manager](https://firsthackersnews.com/ivanti-epm/): Researchers found four critical Ivanti EPM vulnerabilities allowing unauthenticated attackers to exploit machine credentials for relay attacks. Patched in January 2025 after discovery in October 2024. - [New LLM Vulnerability Puts AI Models Like ChatGPT at Risk](https://firsthackersnews.com/llm-vulnerability/): A newly discovered vulnerability in LLMs like ChatGPT raises concerns about adversarial attacks, where techniques like prompt injection can manipulate outputs or expose sensitive data. - [Researchers Seek to Strengthen MITRE ATT&CK Against New Threats](https://firsthackersnews.com/mitre-attck/): A recent study from the National University of Singapore and NCS Cyber Special Ops R&D examines how to improve the MITRE ATT&CK framework to address evolving cyber threats, based on insights from 417 peer-reviewed publications across areas like threat intelligence, incident response, and attack modeling. - [Obfuscated .NET sectopRAT mimics a Chrome extension](https://firsthackersnews.com/sectoprat/): SectopRAT (Arechclient2) is a highly obfuscated .NET-based Remote Access Trojan (RAT). Researchers recently found it posing as a fake Google Docs Chrome extension, enhancing its stealth and data-theft capabilities. - [Malware on WordPress sites lets hackers run remote code](https://firsthackersnews.com/wordpress/): Researchers found malware targeting WordPress sites, using backdoors for remote code execution. The attacks exploit vulnerabilities, highlighting the need for better security. - [RansomHub Now Targets Windows, ESXi, Linux, and FreeBSD](https://firsthackersnews.com/ransomhub-2/): RansomHub has rapidly emerged as a major cybercrime syndicate in 2024–2025, expanding its arsenal to target Windows, VMware ESXi, Linux, and FreeBSD in global attacks. - [Burp Suite 2025.2 Released with AI Integration](https://firsthackersnews.com/burp-suite-2025-2/): PortSwigger released Burp Suite 2025.2, adding AI integration to the Montoya API for smarter, AI-powered extensions. - [Chinese APT Group Actively Exploiting New Windows UI 0-Day Vulnerability](https://firsthackersnews.com/clearsky/): ClearSky Cyber Security has identified a UI vulnerability in Microsoft Windows exploited by Mustang Panda, a threat actor linked to Chinese state interests. The flaw manipulates file visibility during RAR archive extraction, causing extracted files to remain hidden in Windows Explorer, making folders appear empty. - [WordPress Plugin Flaw Allowed Hackers to Target 30,000 Websites](https://firsthackersnews.com/badpilot/): A subgroup of Russia’s state-backed hacker group Seashell Blizzard (Sandworm) has ramped up cyberattacks under a campaign called BadPilot. - [OpenAI Creating Its Own Chip to Cut Nvidia Dependence](https://firsthackersnews.com/openai/): OpenAI is advancing its efforts to reduce reliance on Nvidia by developing its first in-house AI chip. - [New York Bans DeepSeek Due to Potential Data Risks](https://firsthackersnews.com/deepseek-2/): New York Governor Kathy Hochul announced a ban on the use of the China-based AI startup DeepSeek on government devices and networks. - [Microsoft Patch Tuesday (Feb 2025): 61 Vulnerabilities, 25 RCE, 3 Zero-Day](https://firsthackersnews.com/microsoft-patch-tuesday-3/): Microsoft’s February 2025 Patch Tuesday fixes multiple vulnerabilities, including critical RCE and privilege escalation flaws. Users and organizations should update immediately to stay protected. - [Fortinet Zero-Day Exploited to Hijack Firewall & Gain Super Admin](https://firsthackersnews.com/fortinet-0-day-vulnerability/): Fortinet has issued an urgent warning about a critical zero-day vulnerability (CVE-2025-24472) in FortiOS and FortiProxy. The flaw allows remote attackers to bypass authentication and gain super-admin privileges by exploiting maliciously crafted CSF proxy requests. - [Microsoft SharePoint Connector flaw enables credential theft](https://firsthackersnews.com/microsoft-sharepoint-connector-flaw/): A critical SSRF flaw in Microsoft Power Platform’s SharePoint connector let attackers steal credentials and impersonate users across multiple services. The patched vulnerability posed major risks to organizations using SharePoint. - [Apple 0-Day Vulnerability Exploited in Highly Sophisticated Attacks](https://firsthackersnews.com/apple-0-day/): Apple released iOS 18.3.1 and iPadOS 18.3.1 to fix a zero-day vulnerability exploited in targeted attacks by bypassing USB Restricted Mode. - [Hackers are brute-forcing web login pages of popular firewalls](https://firsthackersnews.com/brute-force/): ShadowServer reports a surge in brute-force attacks on edge device logins, with up to 2.8 million IPs daily, mainly from Brazil, targeting firewalls, VPNs, and IoT systems from major vendors. - [New Malware Targets Indian Bank Users for Aadhar, PAN, and PIN Theft](https://firsthackersnews.com/fatboypanel/): Named "FatBoyPanel" by researchers, the malware is designed to deceive Android users and steal their financial and personal information, according to Zimperium analysts. - [MacOS password-stealing malware is spreading rapidly](https://firsthackersnews.com/macos-password-stealing-malware/): MacOS users are seeing a sharp rise in password-stealing malware, spread through fake apps and ads. Leading threats include “Atomic Stealer,” “Poseidon Stealer,” and “Cthulhu Stealer,” each using unique tactics, according to Palo Alto Networks’ Unit42. - [Critical IBM Cloud Pak Vulnerabilities Expose Systems to Remote Code Execution](https://firsthackersnews.com/cloud-pak/): IBM released critical updates for Cloud Pak for Business Automation, fixing vulnerabilities that could expose sensitive data, disrupt operations, or compromise systems. The updates apply to versions 21.0.3 and 24.0.0, affecting both old and current components. - [Zero-Day Flaws in Sysinternals Enable DLL Injection on Windows](https://firsthackersnews.com/sysinternals/): A zero-day vulnerability in Microsoft Sysinternals tools exposes Windows systems to DLL injection attacks, allowing attackers to execute malicious code and potentially compromise the system. - [BADBOX Botnet Infects 190,000+ Android Devices](https://firsthackersnews.com/badbox-botnet/): The BADBOX botnet has infected over 192,000 Android devices worldwide, expanding from low-cost brands to major ones like Yandex TVs and Hisense phones, exposing supply chain risks. - [1-Click RCE Flaw in Voyager PHP Lets Attackers Run Arbitrary Code](https://firsthackersnews.com/1-click-rce-flaw/): A newly found flaw in Voyager PHP, a Laravel management tool, risks RCE on affected servers. Discovered via SonarQube Cloud scans, it lets authenticated users execute code by clicking a crafted link. No patch is available yet. - [Android Update Fixes Linux Kernel RCE Flaw](https://firsthackersnews.com/linux-kernel/): On February 3, 2025, Google released the February Android Security Bulletin, fixing 47 vulnerabilities. One major flaw, CVE-2024-53104, in the Linux kernel’s UVC driver, could let attackers execute remote code and gain unauthorized access. - [Hackers Leverage AWS and Microsoft Azure for Massive Cyber Attacks](https://firsthackersnews.com/microsoft-azure/): Silent Push coined “infrastructure laundering” to describe cybercriminals exploiting cloud services for illegal activities. They rent IPs from AWS and Azure, then link them to criminal sites via CDNs like FUNNULL. - [Phishing Attack Hijacks X Accounts to Promote Scams](https://firsthackersnews.com/phishing-campaign/): A new phishing campaign is targeting high-profile X (formerly Twitter) accounts. - [Cybercriminals Use GitHub to Distribute Lumma Stealer](https://firsthackersnews.com/lumma-stealer-2/): Trend Micro’s Managed XDR team recently uncovered a malware campaign using GitHub’s release infrastructure to spread Lumma Stealer, SectopRAT, Vidar, and Cobeacon malware. This highlights how attackers are using trusted platforms to deliver harmful payloads. - [DeepSeek’s rise fuels more fraud and phishing attacks](https://firsthackersnews.com/deepseek/): DeepSeek, a fast-growing Chinese AI company, has shaken up the industry and caught cybercriminals' attention. - [Google blocked 2.28 million malicious apps from the Play Store](https://firsthackersnews.com/google-2/): Google announced it blocked a record 2.28 million policy-violating apps from the Play Store in 2023. It used advanced machine learning, stricter developer checks, and industry collaborations to fight cyber threats. - [New Apple SLAP & FLOP Attacks Can Steal Browser Login Details](https://firsthackersnews.com/slap-and-flop/): Researchers from Georgia Tech and Ruhr University Bochum discovered two new speculative execution attacks, SLAP and FLOP, affecting Apple Silicon chips (M2/A15 and later). These flaws exploit processor optimizations, allowing attackers to steal sensitive data like emails, locations, and browsing history. - [Apple Releases Security Update: Patches for iOS Zero-Day and macOS](https://firsthackersnews.com/apple-3/): Apple released security updates for iOS, macOS, and more to address a new zero-day vulnerability, reinforcing its commitment to user safety. - [Microsoft Introduces Phishing Protection for Teams Chat](https://firsthackersnews.com/phishing-protection-feature/): Microsoft has introduced a new phishing protection feature for Teams to enhance cybersecurity. - [Apache Solr Flaw Grants Attackers Write Access](https://firsthackersnews.com/apache-solr-flaw/): A new Apache Solr vulnerability, affecting versions 6.6 to 9.7.0, exposes Windows instances to risks of file manipulation and write access due to a Relative Path Traversal flaw. Tracked as SOLR-17543, the issue allows attackers to exploit the “configset upload” API using a maliciously crafted ZIP file. - [Android Kiosk Tablet Flaw Let Hackers Control AC and Lights](https://firsthackersnews.com/android-kiosk/): A flaw in Android kiosk tablets at luxury hotels let attackers remotely control room functions, risking guest privacy and security, according to LAC Co., Ltd. researchers. - [Mirai Botnet Launches Record-Breaking 5.6 Tbps DDoS Attack](https://firsthackersnews.com/mirai-botnet-2/): On October 29, 2024, the Mirai botnet launched a record-breaking DDoS attack, peaking at 5.6 terabits per second. The attack targeted a Cloudflare customer, an ISP in Eastern Asia, making it the largest DDoS attack ever recorded. - [Best Automated Patch Management Software in 2025](https://firsthackersnews.com/automated-patch-management-software/): Keeping systems and applications up to date is critical for security and performance in today’s rapidly evolving digital landscape. Automated patch management solutions have become essential for organizations to ensure timely updates without disrupting operations. - [Helldown Ransomware Exploits Zyxel Zero-Day Vulnerability](https://firsthackersnews.com/helldown-ransomware-2/): A new ransomware, "Helldown," is exploiting vulnerabilities in Zyxel firewalls to breach corporate networks. Researchers have linked the group to attacks targeting Zyxel devices, especially those using IPSec VPN for remote access. - [Windows File Explorer Privilege Escalation (CVE-2024-38100) Exploited](https://firsthackersnews.com/cve-2024-38100/): A critical Windows File Explorer flaw, CVE-2024-38100, has been exploited, allowing attackers to gain admin-level access through an Elevation of Privilege (EoP) vulnerability. - [SQL Injection Vulnerability in Microsoft DevBlogs Enables Malicious SQL](https://firsthackersnews.com/sql-injection-vulnerability/): A security researcher recently discovered a critical SQL injection vulnerability on Microsoft's DevBlogs site (https://devblogs.microsoft.com), allowing attackers to manipulate the database with malicious SQL queries, threatening platform security and data integrity. - [FunkSec Ransomware Leads December Attacks, Compromising 85 Victims](https://firsthackersnews.com/funksec-ransomware/): FunkSec, a RaaS operator, utilizes artificial intelligence to evolve threat actor strategies. While AI aids in scaling operations and generating ransomware, its sophistication remains limited. - [ChatGPT Crawler Flaw Enables DDoS Attacks on Websites](https://firsthackersnews.com/chatgpt-crawler-flaw/): A critical vulnerability in OpenAI's ChatGPT API allows attackers to launch DDoS attacks on arbitrary websites by exploiting how the API handles HTTP POST requests to the endpoint https://chatgptcom/backend-api/attributions. The issue lies in the processing of hyperlinks passed via the URLs parameter, posing significant risks to website availability and raising concerns for web administrators and enterprises. - [Azure DevOps flaws allow CRLF injection and DNS rebinding attacks](https://firsthackersnews.com/azure-devops-flaws/): Security researchers have uncovered multiple Azure DevOps vulnerabilities, enabling CRLF injection and DNS rebinding attacks. - [Apple is offering an Information Security Internship – Apply Now](https://firsthackersnews.com/apple-2/): Apple has announced an exciting Information Security Internship in London, designed for tech-savvy students passionate about starting a career in cybersecurity. - [Pumakit: Advanced Linux Rootkit Targets Critical Infrastructure](https://firsthackersnews.com/pumakit-2/): A highly sophisticated Linux rootkit, Pumakit, has been identified targeting critical infrastructure sectors like telecommunications, finance, and national security. - [Microsoft Teams now lets users customize notification banner positions](https://firsthackersnews.com/microsoft-teams-2/): Microsoft Teams now lets users customize banner notification positions to improve focus and productivity. This feature is available for Public Preview and Microsoft 365 Targeted Release members. - [AWS Addresses Security Flaws in WorkSpaces, AppStream 2.0, and DCV](https://firsthackersnews.com/aws/): AWS has issued a critical security advisory for vulnerabilities in certain versions of its clients for Amazon WorkSpaces, AppStream 2.0, and NICE DCV, identified as CVE-2025-0500 and CVE-2025-0501. These vulnerabilities pose significant risks, prompting AWS to recommend immediate updates to safeguard user data. - [New Tool Launched to Detect Hacking Content on Telegram](https://firsthackersnews.com/detect-hacking-content/): A Russian developer, supported by the National Technology Initiative, has launched the Apparatus Sapiens AI module to scan Telegram chats and groups, detecting malicious content swiftly to bolster RuNet security amid rising cybercrime and violence. - [‘Sneaky 2FA’ Phishing Kit Bypasses Microsoft 365 Authentication](https://firsthackersnews.com/sneaky-2fa/): Researchers have discovered "Sneaky 2FA," a phishing kit targeting Microsoft 365 accounts to steal credentials and bypass 2FA codes since October 2024. - [Exploit Enables NTLMv1 Despite Active Directory Limits](https://firsthackersnews.com/ntlmv1/): Researchers discovered a misconfiguration in on-premise applications that bypasses Active Directory Group Policy meant to disable NTLMv1, effectively rendering it ineffective, according to Silverfort's Dor Segal. - [Hackers Exploit YouTube Links and Microsoft 365 Themes to Steal Logins](https://firsthackersnews.com/youtube-links-and-microsoft-365/): Cybercriminals are running advanced phishing attacks on Microsoft 365 users using fake URLs that closely resemble real O365 domains, tricking victims into trusting them. - [Hackers Exploit Zero-Day in Fortinet Firewalls](https://firsthackersnews.com/fortinet/): Hackers are targeting Fortinet FortiGate firewalls with exposed management interfaces online. - [Microsoft Alerts Microsoft 365 Users to MFA Issue](https://firsthackersnews.com/microsoft-5/): Microsoft has warned of an MFA issue affecting some Microsoft 365 users, blocking access to certain applications and disrupting essential operations. - [Juniper Networks Flaw Allowed Remote Network Attacks](https://firsthackersnews.com/juniper-networks-flaw/): Juniper Networks disclosed CVE-2025-21598, a critical vulnerability in Junos OS and Junos OS Evolved, allowing remote attackers to exploit an out-of-bounds read in the routing protocol daemon (rpd), causing crashes and network disruptions when BGP is enabled. - [LDAP Exploit Delivers Info-Stealing Malware](https://firsthackersnews.com/ldap-vulnerabilities/): Cybercriminals are exploiting critical LDAP vulnerabilities (CVE-2024-49112 and CVE-2024-49113) by distributing fake proof-of-concept (PoC) exploits for “LDAPNightmare” (CVE-2024-49113). - [PriveShield: Advanced Privacy with Profile Isolation](https://firsthackersnews.com/priveshield/): The PRIVESHIELD browser extension automatically creates isolated profiles to group websites based on browsing habits and interactions, blocking cross-site tracking and cookie-matching used for targeted ads. - [Chrome Update: Fixes for Multiple Security Flaws](https://firsthackersnews.com/chrome-update/): Google has updated Chrome to version 131.0.6778.264/.265 for Windows and Mac, and 131.0.6778.264 for Linux, fixing critical security flaws. The update will roll out gradually, and users are urged to update promptly for enhanced security. - [Hackers breached Argentina’s airport security payroll system](https://firsthackersnews.com/argentinas-airport-security-payroll-system/): Hackers breached Argentina's Airport Security Police (PSA) payroll system, exposing sensitive employee information. They accessed salary records and altered pay slips, making unauthorized deductions between 2,000 to 5,000 pesos under fake labels like “DD mayor” and “DD seguro.” - [WordPress Plugin Exploits Websites to Steal Customer Payment Information](https://firsthackersnews.com/wordpress-plugin/): Cybercriminals created PhishWP, a malicious WordPress plugin, to mimic payment gateways like Stripe for phishing attacks on compromised sites. - [Android Security Update Fixes Critical RCE Vulnerabilities](https://firsthackersnews.com/android/): The January 2025 Android Security Bulletin highlights critical vulnerabilities affecting Android devices. Users should update to security patch level 2025-01-05 or later to stay protected. - [WordPress Plugin Flaw Puts 3 Million Sites at Risk of Injection Attacks](https://firsthackersnews.com/wordpress-plugin-flaw/): A critical vulnerability has been found in the UpdraftPlus: WP Backup & Migration Plugin, affecting over 3 million WordPress sites. - [Critical OpenSSH Vulnerability (CVE-2024-6387) Exploit Released](https://firsthackersnews.com/cve-2024-6387/): A PoC exploit for the critical OpenSSH vulnerability CVE-2024-6387 has been released, enabling remote attackers to execute arbitrary code on vulnerable servers, posing serious risks to users. - [Apple Settles Siri Privacy Lawsuit for $95M](https://firsthackersnews.com/apple/): Apple has agreed to pay $95 million to settle a class-action lawsuit claiming Siri violated users' privacy by recording conversations without consent. - [ASUS Vulnerabilities Allow Arbitrary Command Execution](https://firsthackersnews.com/asus-vulnerability/): ASUS warns of critical router flaws (CVE-2024-12912, CVE-2024-13062) allowing arbitrary command execution. Users are urged to update their devices immediately. - [Cyberhaven Chrome Extension Compromised, Potentially Impacting 400,000 Users](https://firsthackersnews.com/cyberhaven/): Cyberhaven, a cybersecurity company, revealed that its Chrome extension, with over 400,000 users, was targeted in a cyberattack on Christmas Eve 2024. The attack was part of a larger campaign affecting multiple Chrome extension developers. - [PoC Exploit Released for Oracle WebLogic Vulnerability](https://firsthackersnews.com/oracle-weblogic-vulnerability/): Researchers warn of a public PoC exploit for a critical Oracle WebLogic vulnerability. - [Microsoft warns of a Windows 11 24H2 issue blocking security updates](https://firsthackersnews.com/microsoft-4/): Microsoft has warned of an issue affecting Windows 11 version 24H2 that blocks critical security updates. - [New Botnet exploits D-Link routers for remote control](https://firsthackersnews.com/d-link-routers-2/): Researchers observed increased activity from the "FICORA" and "CAPSAICIN" variants, which exploit vulnerabilities in outdated D-Link routers like DIR-645, DIR-806, GO-RT-AC750, and DIR-845L. - [IBM AIX TCP/IP vulnerability allows Denial of Service attacks](https://firsthackersnews.com/ibm-aix-tcp-ip-vulnerability/): IBM has warned of two security flaws (CVE-2024-47102 and CVE-2024-52906) in its AIX operating system that could cause systems to crash (denial-of-service attacks). - [Adobe warns of ColdFusion file-reading vulnerability](https://firsthackersnews.com/coldfusion/): Adobe released a critical security update for ColdFusion to address a vulnerability that allows attackers to read arbitrary files. - [Araneida Scanner – Hackers Exploit Cracked Acunetix Scanner](https://firsthackersnews.com/araneida-scanner/): Threat analysts report the “Araneida Scanner,” based on a cracked Acunetix version, is used for illegal activities like data scraping and exploiting vulnerabilities. - [Node.js systeminformation Package Enables RCE Attacks](https://firsthackersnews.com/cve-2024-56334/): A critical command injection vulnerability in the systeminformation npm package, CVE-2024-56334, exposes millions of systems to RCE and privilege escalation attacks. - [Malicious Amazon Appstore apps record screens and intercept OTPs](https://firsthackersnews.com/amazon-app-store/): The “BMI CalculationVsn” app on the Amazon App Store secretly collects sensitive data, like app package names and SMS messages, posing a privacy risk. Its true intent appears to be data theft or other cyberattacks. - [Skuld Malware Exploits Windows Utilities Packages](https://firsthackersnews.com/skuld-malware/): Researchers uncovered a malware campaign in the npm ecosystem, where “k303903” used fake packages to spread the Skuld info stealer, compromising hundreds of machines before removal. - [BADBOX botnet hacked 74,000 Android devices with remote codes](https://firsthackersnews.com/badbox/): BADBOX is a cybercriminal operation that infects Android devices, like TV boxes and smartphones, with malware before they are sold. These devices, often sold through trusted retailers, pose a major threat due to their pre-installed malicious software, making detection difficult. - [Malicious supply chain attacks shift from npm to VSCode Marketplace](https://firsthackersnews.com/malicious-supply-chain-attacks/): Researchers have observed a rise in malicious activity on the VSCode Marketplace, exposing its vulnerability to supply chain attacks similar to those previously seen in the npm community. - [Careto: A Notorious Threat Group Targets Windows with Microphone Recording and File Theft](https://firsthackersnews.com/careto/): The attack used two frameworks, Careto2 and Goreto. Careto2, installed through a multi-stage process, employed COM hijacking for persistence and a virtual filesystem for storing plugins. Goreto, written in Golang, connected to Google Drive for command-and-control, enabling commands, keylogging, and screenshot capture. - [New VIPKeyLogger in Office Docs Steals Credentials](https://firsthackersnews.com/vipkeylogger/): VIPKeyLogger, similar to the Snake Keylogger, spreads through phishing campaigns via attachments disguised as archive or Microsoft 365 files. It uses malicious Office documents to connect to C2 servers and targets sensitive data like login credentials, financial details, and personal information, posing a major threat to affected systems. - [Hackers Exploit Windows Management Console for Backdoor Payloads](https://firsthackersnews.com/fluxconsole-campaign/): The FLUX#CONSOLE campaign exploits .MSC files to deploy backdoor malware, highlighting advanced phishing and Windows feature abuse. - [Malicious ads on CAPTCHA pages spread password stealers](https://firsthackersnews.com/malicious-ads-on-captcha-pages/): Cybercriminals are using fake CAPTCHA pages to spread password-stealing malware. These fake CAPTCHAs, often appearing as pop-ups, trick users into running harmful PowerShell commands through malicious ads, mimicking legitimate verification processes. - [Hackers exploit Apache Struts2 flaw to upload malware](https://firsthackersnews.com/apache-struts2-flaw/): Hackers are exploiting a new Apache Struts2 vulnerability (CVE-2024-53677) with a critical CVSS score of 9.5, posing severe risks. - [Hackers Exploit Microsoft Teams for Remote System Access](https://firsthackersnews.com/microsoft-teams/): Hackers used Microsoft Teams to trick victims into granting remote system access, showcasing advanced social engineering tactics, according to Trend Micro. - [Dell Security Update Patches Multiple Critical Vulnerabilities](https://firsthackersnews.com/dell/): Dell Technologies has issued a security advisory for critical vulnerabilities that could be exploited by attackers. - [Stealthy Linux Malware PUMAKIT Escalates Privileges](https://firsthackersnews.com/pumakit/): Researchers at Elastic Security Labs discovered PUMAKIT, a Linux malware using stealth and unique privilege escalation to persist on infected systems. - [Emoji Exploit Targets iOS Messenger Group Calls](https://firsthackersnews.com/emoji/): A new vulnerability in Facebook Messenger for iOS could disrupt group calls by exploiting emoji reactions. - [Skoda and Volkswagen car vulnerabilities allow hackers to track users remotely](https://firsthackersnews.com/skoda-and-volkswagen-car-flaw/): Researchers have found vulnerabilities in the infotainment systems of some Skoda and Volkswagen cars, which could let hackers track users and access sensitive data remotely. PCAutomotive, an automotive cybersecurity firm, revealed 12 security flaws in the latest Skoda Superb III sedan at Black Hat Europe. - [Microsoft 365 Services Affected: Web Apps and Admin Center Down](https://firsthackersnews.com/microsoft-365-2/): Microsoft is investigating a widespread outage that impacted access to Microsoft 365 web apps and the admin center. Users experienced issues connecting to services like Outlook, OneDrive, and other Office 365 apps via web browsers. - [Meeten Malware Targets macOS and Windows to Steal Logins](https://firsthackersnews.com/meeten-malware/): Cado Security Labs found a Windows version of Meeten malware, named MeetenApp.exe, which uses a stolen signature from Brys Software. The installer runs an Electron app that collects system information (HWID, IP, hostname, OS, users, RAM, etc.) and sends it to a remote server. - [Microsoft Patch Tuesday : 71 Vulnerabilities Fixed](https://firsthackersnews.com/71-vulnerabilities/): Microsoft’s final Patch Tuesday of 2024 addresses 71 vulnerabilities, including 16 critical ones and a zero-day. This update highlights Microsoft’s commitment to improving product security and safeguarding users from cyber threats. - [Critical Qlik Sense RCE vulnerability discovered](https://firsthackersnews.com/qlik-sense/): A critical vulnerability in Qlik Sense for Windows may allow remote code execution. It affects all versions up to the May 2024 Patch 9 release. - [Cipla Allegedly Hacked, Akira Ransomware Claims 70GB Data Stolen](https://firsthackersnews.com/cipla/): Cipla, an Indian pharmaceutical company, has reportedly been attacked by the Akira ransomware group. The hackers claim to have stolen 70GB of sensitive data. This breach has raised concerns about data security and patient privacy in the pharmaceutical industry. - [Google Launches Vanir: An open-source tool for validating security patches](https://firsthackersnews.com/vanir/): Google has launched Vanir, an open-source tool to simplify and automate security patch validation. - [SonicWall Flaws Enable Remote Code Execution](https://firsthackersnews.com/sonicwall/): SonicWall warns of critical flaws in SMA 100 series appliances, enabling remote code execution, authentication bypass, and system compromise. - [HCL DevOps Deploy & Launch Vulnerable to HTML Injection](https://firsthackersnews.com/cve-2024-42195/): A newly discovered vulnerability in HCL Software's DevOps Deploy and Launch platforms, CVE-2024-42195, allows attackers to insert arbitrary HTML tags into the web UI, which could expose sensitive information. - [ChatGPT Next Web Vulnerability Allows SSRF Exploits via Endpoint](https://firsthackersnews.com/chatgpt-next-web-vulnerability/): Researchers reported CVE-2023-49785, a critical ChatGPT Next Web (NextChat) vulnerability, raising cybersecurity concerns over its SSRF exploitation potential. - [ElizaRAT Uses Google, Telegram, & Slack for C2 Communications](https://firsthackersnews.com/elizarat/): APT36, a Pakistani cyber-espionage group, now uses ElizaRAT, a Windows RAT with advanced evasion and C2 features, to target Indian government, diplomats, and military. - [Hackers Exploit Windows Event Logs for Manipulation and Data Theft](https://firsthackersnews.com/wevtutil-exe/): Hackers exploit wevtutil.exe for LOLBAS attacks, enabling command execution, payload downloads, and persistence while bypassing security. - [Apple Safari JavaScriptCore RCE Vulnerability Actively Exploited ](https://firsthackersnews.com/cve-2024-44308/): CVE-2024-44308, a critical Safari vulnerability, has been actively exploited, impacting iOS, visionOS, and macOS. - [Amazon GuardDuty Gains AI/ML Threat Detection for Cloud Security](https://firsthackersnews.com/amazon-guardduty/): Users can access these new AI/ML features through the Amazon GuardDuty console, where additional widgets appear on the Summary page. - [HPE IceWall Flaw Enabled Unauthorized Data Changes](https://firsthackersnews.com/hpe-icewall-flaw/): HPE has released a security alert about a critical flaw in its IceWall product, CVE-2024-11856, which lets attackers remotely modify data without permission. - [Uniswap Labs Announces $15.5M Bug Bounty](https://firsthackersnews.com/uniswap-labs/): Uniswap Labs has launched a $15.5 million bug bounty to secure its new protocol, Uniswap v4—the largest bounty in DeFi history. - [Matrix Orchestrates Global DDoS Attack Campaign](https://firsthackersnews.com/matrix/): Cybersecurity researchers have uncovered a large-scale DDoS campaign attributed to a threat actor known as "Matrix." Despite the actor's low technical skills, the campaign demonstrates how easily accessible tools are enabling less experienced attackers to launch significant global attacks. - [Beware of PixPirate Malware Targeting WhatsApp Users](https://firsthackersnews.com/pixpirate-malware-2/): PixPirate malware is targeting users in Brazil, India, Italy, and Mexico, posing as a fake authentication app to steal banking data. - [NVIDIA Vulnerability Enables Data Tampering and Privilege Escalation](https://firsthackersnews.com/nvidia-vulnerability/): NVIDIA has issued a critical security update for a major vulnerability in its Unified Fabric Manager (UFM) products. - [Exploitation of ProjectSend Authentication Vulnerability Discovered in the Wild](https://firsthackersnews.com/projectsend-authentication/): ProjectSend, an open-source file-sharing web app, is actively being exploited after CVE-2024-11680 was assigned on November 25, 2024. Despite a patch being available for over a year, many instances remain vulnerable due to low adoption rates. - [New Stealthy GodLoader Malware Targets Multiple Platforms](https://firsthackersnews.com/godloader-malware/): GodLoader malware, discovered by Check Point, stealthily infects Windows, macOS, Linux, Android, and iOS, using the Godot Engine to evade antivirus detection. - [RomCom Hackers Exploit Windows Zero-Days & Firefox Vulnerability](https://firsthackersnews.com/romcom/): The Russian-aligned group RomCom exploited two critical zero-day vulnerabilities in Mozilla Firefox and Windows in a sophisticated cyber-espionage campaign, allowing attackers to execute malicious code without user interaction. - [Huge Credit Card Breach: Database of Over 1.2 Million Cards Found on Dark Web](https://firsthackersnews.com/credit-cards/): A major data breach has caused widespread concern, as a database with sensitive financial details of over 1.2 million credit cards was leaked on the dark web. - [Meta has taken down 2 million malicious accounts](https://firsthackersnews.com/pig-butchering/): Meta has removed over 2 million accounts involved in malicious activities, including complex fraud schemes like "pig butchering." - [Python NodeStealer Targets Facebook Business Accounts for Credential Theft.](https://firsthackersnews.com/nodestealer-2/): The Python-based NodeStealer has evolved, now targeting Facebook Ads Manager budgets, stealing credit card info, and browser credentials. It uses Windows Restart Manager to unlock databases and employs obfuscation techniques like junk code to bypass security. - [Helldown Ransomware Targets ESXi and Linux](https://firsthackersnews.com/helldown-ransomware/): Helldown, a new ransomware group, has been exploiting vulnerabilities to breach networks and compromise victims since August 2024, with 28 breaches reported so far. They have been leaking stolen data on a dedicated website. - [Two Malicious PyPi Packages Mimicking ChatGPT & Claude Steal Developer Data](https://firsthackersnews.com/pypi-package/): Two malicious Python packages pretending to be tools for ChatGPT and Claude were found on PyPI, the official Python library repository. They went undetected for over a year, compromising developer systems and stealing sensitive data. - [Trend Micro Deep Security Flaw Allows Remote Code Execution](https://firsthackersnews.com/cve-2024-51503/): The vulnerability, identified as CVE-2024-51503, was discovered on November 18, 2024, and has a high severity rating with a CVSS 3.0 score of 8.0. - [Hackers Exploit Misconfigured Servers to Stream Live Sports](https://firsthackersnews.com/hackers-exploit-misconfigured-servers/): Recent threat analysis examined outbound traffic and binaries in container environments. Researchers, using honeypot data and threat intelligence, flagged unusual network events involving the tool ffmpeg. While not malicious itself, its use in this context raised concerns about potential misuse. - [Apache Kafka Vulnerability Enables Privilege Escalation](https://firsthackersnews.com/apache-kafka-vulnerability-enables-privilege-escalation/): A new vulnerability, CVE-2024-31141, was found in Apache Kafka Clients, allowing attackers to escalate privileges and gain unauthorized file access. Rated as Moderate, it affects several versions and is a concern for environments exposed to untrusted users, like SaaS products. - [Citrix Virtual Apps & Desktops Zero-Day Actively Exploited](https://firsthackersnews.com/citrix-virtual-apps-and-desktops/): A critical unpatched vulnerability has been found in Citrix Virtual Apps and Desktops, now being actively exploited. The flaw, revealed by Watchtowr Labs, poses a significant risk, especially in remote work environments like call centers. - [Zohocorp ADAudit Plus SQL Injection Vulnerability](https://firsthackersnews.com/cve-2024-49574/): Zoho released a security update for a critical SQL injection flaw in ADAudit Plus (CVE-2024-49574), fixed in version 8123 on November 8, 2024. - [CISA Warns of Exploited Palo Alto Networks Vulnerabilities](https://firsthackersnews.com/cisa-3/): CISA issued an urgent alert for two Palo Alto Networks vulnerabilities, CVE-2024-9463 and CVE-2024-9465, which are actively being exploited by cybercriminals. These vulnerabilities pose serious risks, especially to federal systems. - [Chinese SilkSpecter hackers targeting Black Friday shoppers](https://firsthackersnews.com/silkspecter/): Chinese hacker group SilkSpecter launched a phishing campaign targeting Black Friday shoppers in Europe and the USA, using Stripe to steal card data while allowing legitimate transactions. - [4M+ WordPress Sites Vulnerable After Plugin Flaw](https://firsthackersnews.com/cve-2024-10924/): Critical flaw found in 'Really Simple Security' WordPress plugin, risking 4M+ sites. CVE-2024-10924 allows potential remote attacks and unauthorized admin access. - [Windows 0-Day Exploited with Single Right Click](https://firsthackersnews.com/cve-2024-43451/): A recently discovered zero-day vulnerability, CVE-2024-43451, is being actively exploited, targeting Windows systems across multiple versions. Identified by the ClearSky Cyber Security team in June 2024, this vulnerability has been used in attacks primarily targeting Ukrainian organizations. The exploit enables attackers to take control of a system with a simple right-click on a malicious file. - [Google to Issue CVEs for Major Cloud Security Flaws](https://firsthackersnews.com/google-cloud/): Google Cloud will start issuing CVEs for critical vulnerabilities in its services, aiming to boost transparency and security. This step highlights Google’s commitment to helping organizations guard against threats and builds trust in its security practices, even when no customer action is needed. - [Critical Flaw Found in Dell SONiC](https://firsthackersnews.com/sonic/): Dell Technologies has revealed critical vulnerabilities in its Enterprise SONiC OS (versions 4.1.x and 4.2.x), which could allow attackers to take control of affected systems. Users are urged to upgrade to the latest versions to address the issue. - [Amazon Confirms Employee Data Breach Through Third-Party Vendor](https://firsthackersnews.com/amazon/): Amazon confirmed that employee data was exposed due to a breach at a third-party vendor, which exploited a critical vulnerability in MOVEit file transfer software. - [Hackers Use Google Ads to Distribute Fakebat Malware](https://firsthackersnews.com/fakebat-malware-2/): Researchers have found that Fakebat malware is again being spread through malicious Google Ads, targeting users searching for popular productivity software. Malwarebytes flagged an ad impersonating the app Notion. - [Roblox Devs Targeted with Malicious npm Packages](https://firsthackersnews.com/roblox/): Researchers found five malicious npm packages targeting Roblox developers, stealing credentials and personal data. These packages, including autoadv, ro.dll, node-dlls, and two rolimons-api versions, mimic legitimate modules commonly used by the Roblox community. - [Hackers Use Malicious Excel Files to Deliver Remcos RAT to Windows Users](https://firsthackersnews.com/remcos-rat/): Fortinet researchers recently found that hackers are targeting Windows users with malicious Excel files to deploy Remcos RAT. FortiGuard Labs identified one such phishing attack when they received an email containing an Excel file disguised as an order document. - [Watch Out for Fake Copyright Claims Spreading Rhadamanthys Stealer](https://firsthackersnews.com/rhadamanthys-stealer/): CheckPoint security experts recently warned about fake copyright claims spreading Rhadamanthys stealer malware. - [Cisco Vulnerability Allowed Attackers to Execute Commands as Root](https://firsthackersnews.com/cve-2024-20418/): Tracked as CVE-2024-20418, this flaw allows unauthenticated remote attackers to inject commands and execute arbitrary commands as the root user on affected devices. - [ToxicPanda Malware Targets Bank Users](https://firsthackersnews.com/toxicpanda-malware/): Recent research has identified a new Android malware strain, initially mistaken for TgToxic, now called ToxicPanda. - [Threat Actor Leaks Alleged Nokia Source Code](https://firsthackersnews.com/nokia/): The threat actor known as IntelBroker, along with EnergyWeaponUser, has claimed responsibility for a major data breach involving Nokia’s proprietary source code. - [ClickFix Malware Targets GMeet, Zoom Pages](https://firsthackersnews.com/clickfix-2/): The “ClickFix” tactic exploits fake Google Meet and Zoom pages to deliver advanced malware, mimicking legitimate video conferencing platforms used for business and personal communication. - [Hackers Bypass Endpoints with EDRSandBlast](https://firsthackersnews.com/edrsandblast/): An extortion probe revealed two outdated Cortex XDR endpoints testing an AV/EDR bypass tool called “disabler.exe”—a modified “EDRSandBlast” used to disable security hooks in user-mode libraries and kernel-mode callbacks. - [Spectre Flaw Persists in AMD, Intel CPUs](https://firsthackersnews.com/spectre-flaw/): Researchers have shown an exploit for the Spectre Flaw, targeting the Indirect Branch Predictor Barrier (IBPB) vulnerability. This issue affects modern AMD and Intel CPUs and may result in data leaks. - [SYS01 InfoStealer Malware Targets Meta Business Page](https://firsthackersnews.com/sys01-infostealer-malware/): The Meta malvertising campaign, active for over a month, spreads SYS01 InfoStealer by disguising it within ElectronJs apps, presented as legitimate tools like video editors, productivity software, and streaming services. - [Evasive Panda Targets Cloud Services with New Toolkit to Steal Data](https://firsthackersnews.com/evasive-panda-2/): Evasive Panda deployed a new C# tool, CloudScout, in early 2023 to target a Taiwanese government entity. CloudScout uses modules to hijack web sessions, accessing services like Google Drive, Gmail, and Outlook by stealing browser cookies to bypass 2FA and IP tracking. - [Critical Chrome Security Vulnerabilities Fixed](https://firsthackersnews.com/chrome/): Google has released a Chrome update addressing critical vulnerabilities, safeguarding millions of users. The latest Stable version, 130.0.6723.91/.92, is now rolling out for Windows, Mac, and Linux, with Extended Stable version 130.0.6723.92 available for Windows and Mac. - [Hackers Exploit SonicWall VPNs with Fog Ransomware](https://firsthackersnews.com/sonicwall-vpn/): Recent cyberattacks by Akira and Fog threat actors have targeted multiple industries by exploiting a vulnerability (CVE-2024-40766) in SonicWall SSL VPN devices, using malicious VPN logins from VPS-hosted IP addresses early in the attack chain. - [WrnRAT Delivered as Gambling Games](https://firsthackersnews.com/wrnrat-malware/): WrnRAT is a new malware that cybercriminals deploy by disguising it as popular gambling games like Badugi, Go-Stop, and Hold'em. - [Realtek SD Card Driver Flaw Impacts Laptops](https://firsthackersnews.com/realtek-sd-card-driver/): Multiple vulnerabilities in the Realtek SD card reader driver, RtsPer.sys, affect laptops from major brands like Dell and Lenovo. - [Critical Authentication Flaw in WhatsUp Gold Exposes Organizations to Attack](https://firsthackersnews.com/whatsup-gold/): WhatsUp Gold, a popular network monitoring tool, has a critical vulnerability in versions before 2024.0.0, exposing organizations to potential cyber attacks and unauthorized data access. - [Cisco ASA SSH Flaw Leaves Devices Vulnerable](https://firsthackersnews.com/cve-2024-20329/): Cisco issued a critical advisory for a vulnerability in its Adaptive Security Appliance (ASA) Software that could let remote attackers execute commands with root privileges. The flaw, CVE-2024-20329, affects devices with the CiscoSSH stack enabled. - [Roundcube Webmail Vulnerability Exploited in Attacks](https://firsthackersnews.com/roundcube-webmail-vulnerability/): Stored XSS vulnerability in Roundcube Webmail is exploited in attacks on ex-USSR government agencies. Researchers identified the attack but cannot determine the perpetrators - [GitLab Patches Critical HTML Injection Flaw Allowing XSS Attacks](https://firsthackersnews.com/gitlab/): GitLab released patches (17.5.1, 17.4.3, and 17.3.6) for both Community and Enterprise Editions, fixing a critical HTML injection vulnerability in the Global Search feature that could lead to XSS attacks, along with other security and bug fixes. - [Lazarus APT Hackers Exploit Chrome Zero-Day via Crypto Game](https://firsthackersnews.com/lazarus-apt/): Lazarus APT exploited a Chrome zero-day using a crypto-themed game as bait, showcasing the group’s evolving financial tactics and social engineering. - [Critical Vulnerabilities Found in VMware vCenter Server](https://firsthackersnews.com/vmware-vcenter-server/): Broadcom has issued critical security updates for severe vulnerabilities in VMware vCenter Server that allow remote code execution and privilege escalation. The flaws, CVE-2024-38812 and CVE-2024-38813, impact multiple versions of vCenter Server and VMware Cloud Foundation. - [Callback Phishing Targets Login Credentials via Google Groups](https://firsthackersnews.com/callback-phishing-2/): Phishing attacks trick individuals into revealing sensitive info by impersonating trusted entities, often through urgent emails with malicious links or attachments. Trustwave analysts recently warned of Callback Phishing attacks using Google Groups to steal login details. - [Over 10 million personal and corporate devices hit by information stealers](https://firsthackersnews.com/10-million-personal-and-corporate-devices/): Kaspersky reports nearly 10 million personal and corporate devices were compromised by data-stealing malware in 2023, a 643% rise in three years. Information stealers, which collect sensitive data like login credentials and financial info, are increasingly common and often spread through methods like malvertising on adult sites and YouTube comment spam, making detection and prevention harder. - [GHOSTPULSE Malware Leverages PNG Pixel Structure for Evasion](https://firsthackersnews.com/ghostpulse-malware/): Recently, researchers at Elastic Security Labs discovered that GHOSTPULSE malware hides within the pixel structure of PNG files to avoid detection. - [Hackers Impersonate ESET to Distribute Wiper Malware](https://firsthackersnews.com/wiper-malware/): Hackers posed as ESET to spread wiper malware via phishing emails starting October 8, 2024. The emails, claiming to be from “ESET’s Advanced Threat Defense Team,” warned of state-sponsored attacks and provided a fake download link for a tool called "ESET Unleashed." - [Hackers use Bumblebee malware to infiltrate corporate networks](https://firsthackersnews.com/bumblebee-malware-2/): Bumblebee malware has reemerged, threatening corporate networks globally, following its first sighting since Europol’s May 2024 Operation Endgame. - [Hackers Reportedly Selling Stolen Data from Cisco](https://firsthackersnews.com/cisco/): A group of hackers reportedly sells sensitive data stolen from Cisco, allegedly by IntelBroker in collaboration with EnergyWeaponUser and zjj, raising concerns in the tech industry. - [ErrorFather hackers remotely attack and control Android devices](https://firsthackersnews.com/errorfather/): The ErrorFather campaign, a new variant of the Cerberus banking trojan, emerged in September 2024. It uses a multi-stage dropper to spread and has seen a rise in activity, posing risks to Android users. - [PureLogs, a low-cost infostealer, is targeting Chrome browsers](https://firsthackersnews.com/purelogs-infostealer/): Infostealer malware, like the recently identified PureLogs, poses significant risks due to its low cost and ease of use, making it accessible to even low-level hackers. PureLogs is a 64-bit information stealer developed in C#, utilizing multiple stages by bundling its assemblies with the commercial .NET Reactor packer. - [Hackers exploited a zero-day vulnerability in Qualcomm chips, targeting Android users](https://firsthackersnews.com/qualcomm-chips/): Hackers exploit a zero-day vulnerability (CVE-2024-43047) in Qualcomm chipsets, risking millions of Android users globally. The flaw stems from memory corruption in DSP Services. - [Foxit PDF Reader vulnerability allows attackers to execute arbitrary code](https://firsthackersnews.com/foxit-pdf-reader-vulnerability/): Researchers revealed six new vulnerabilities, including a critical one in Foxit PDF Reader that allows arbitrary code execution. Three flaws were also found in Veertu's Anka Build, threatening CI/CD environments for macOS and iOS testing. - [Mozilla warns of a Firefox zero-day vulnerability actively exploited in cyberattacks](https://firsthackersnews.com/firefox-zero-day/): A critical use-after-free vulnerability in Firefox and Firefox Extended Support Release (ESR) is being actively exploited in cyberattacks. - [CISA warns of active exploitation of Microsoft zero-day vulnerabilities](https://firsthackersnews.com/cisa-2/): CISA warns of two critical Microsoft zero-day vulnerabilities, CVE-2024-43572 and CVE-2024-43573, actively exploited in the wild. - [Hackers breached the president’s account of a Japanese aerospace company](https://firsthackersnews.com/japanese-aerospace-company/): Hackers infiltrated JAXA, compromising top officials' accounts, including President Hiroshi Yamakawa, in a series of cyberattacks since June 2023. - [LemonDuck malware targets Windows servers by exploiting SMB vulnerabilities](https://firsthackersnews.com/lemonduck-malware/): Attackers used the EternalBlue vulnerability to access the observatory farm, create a hidden admin share, and run a malicious batch file named p.bat, which opened firewall ports, set up port forwarding, and scheduled tasks for persistence. - [Cacti vulnerability allows attackers to execute remote code](https://firsthackersnews.com/cacti-vulnerability-3/): A critical vulnerability in the Cacti network monitoring tool, discovered in version 1.2.28, could allow attackers to execute remote code on affected systems. - [CVE-2024-30052: RCE vulnerability in Visual Studio via dump files](https://firsthackersnews.com/cve-2024-30052/): A researcher identified a method to exploit Visual Studio by executing arbitrary code during the debugging of managed dump files, without needing memory corruption or specific PDB file components. By analyzing libraries used in these sessions, they uncovered vulnerabilities that could be exploited, emphasizing the need to address security flaws in debugging tools to prevent potential attacks. - [WarmCookie malware spreads via fake update campaign in France](https://firsthackersnews.com/warmcookie/): FakeUpdate, a fake browser update scam, is now targeting users in France, aiming to deploy the WarmCookie backdoor malware. - [Perfctl malware targets millions of Linux servers](https://firsthackersnews.com/perfctl-malware/): To detect Perfctl malware, check for unexpected CPU spikes, system slowdowns, and suspicious files in /tmp, /usr, and /root directories. Also, monitor network traffic for TOR communication and connections to cryptomining or proxy-jacking services, according to the report. - [Arc Browser Launches Bug Bounty Program After RCE Vulnerability](https://firsthackersnews.com/arc-browser/): The Browser Company has launched a Bug Bounty Program for its Arc Browser after quickly resolving a remote code execution (RCE) vulnerability, as announced by CEO Josh, highlighting their commitment to transparency and security. - [Chrome vulnerabilities enable attackers to run arbitrary code](https://firsthackersnews.com/chrome-vulnerabilities/): Google released a Chrome update fixing critical vulnerabilities that could allow arbitrary code execution. Version 129.0.6668.89/.90 is now available for Windows, Mac, and Linux. - [New XWorm variant spreads via Windows script files](https://firsthackersnews.com/xworm-variant/): XWorm is a malware known for its obfuscation techniques and ability to evade detection, posing a significant cybersecurity threat. NetSkope recently found a new variant delivered via a Windows script file. Originally discovered in 2022, XWorm has evolved to version 5.6. - [Hackers targeting Docker Swarm, Kubernetes, and SSH servers in large-scale attacks](https://firsthackersnews.com/large-scale-server-exploits/): Hackers are exploiting Docker Swarm, Kubernetes, and SSH servers, targeting Docker API vulnerabilities as the entry point in a widespread malware campaign, according to DataDog researchers. - [Linux CUPS has multiple vulnerabilities that allow remote code execution](https://firsthackersnews.com/linux-cups/): Developers of the Linux printing system CUPS recently disclosed several vulnerabilities that could allow attackers to execute arbitrary code. Although these flaws require specific conditions to be exploited, their high volume raises concerns about potential real-world exploitation prior to the announcement. - [GorillaBot reigns as DDoS king with 300,000+ commands](https://firsthackersnews.com/gorillabot/): The GorillaBot trojan, a variant of Mirai, supports multiple architectures and connects randomly to one of five C&C servers for commands. - [North Korean Hackers Tried to Steal Military Data](https://firsthackersnews.com/north-korean-hacker/): North Korean hacker group Kimsuky, working for military intelligence, used phishing to send fake job offers loaded with spyware to steal sensitive information. - [HTML smuggling enables hackers to deliver convincing phishing attacks](https://firsthackersnews.com/html-smuggling/): Phishing attackers used an HTML smuggling technique to deliver malware. The attack began with a phishing email that looked like an American Express notification, leading to several redirects. - [NIST Recommends New Password Security Rules](https://firsthackersnews.com/nist/): NIST released new password security guidelines in Special Publication 800-63B, improving cybersecurity and user experience. - [Watch out for fake “verify you’re human” prompts that can deliver malware](https://firsthackersnews.com/fake-verify-youre-human/): CAPTCHAs, or Completely Automated Public Turing tests, are used online to verify users are human, not bots. They usually present challenges like distorted text, image recognition tasks, or audio prompts that require human cognitive skills. - [TeamViewer Privilege Escalation Vulnerability](https://firsthackersnews.com/teamviewer-vulnerability-flaw/): A critical vulnerability in TeamViewer’s Windows Remote client, CVE-2024-7479 and CVE-2024-7481, allows attackers to elevate privileges on affected systems across various versions. - [Google Warns of North Korean IT Workers Infiltrating U.S. Workforce](https://firsthackersnews.com/google-alerts-about-north-korean-it-workers/): Recently, Google alerted organizations about North Korean IT workers acting on behalf of hackers. - [0-day flaws in Automated Tank Gauge systems threaten critical infrastructure.](https://firsthackersnews.com/0-day-flaws-in-automated-tank-gauge/): Researchers at BitSight TRACE found multiple 0-day vulnerabilities in ATG systems used to manage fuel storage tanks, posing risks to public safety and economic stability. These flaws could lead to physical damage, environmental hazards, and financial loss. - [Cisco Smart Licensing Vulnerability Allows Attackers to Control Devices](https://firsthackersnews.com/cve-2024-20439/): Cisco revealed a critical vulnerability, CVE-2024-20439, in its Smart Licensing Utility, allowing unauthorized access due to a hardcoded static password found by an independent researcher. - [macOS Sequoia update disrupts multiple security tools](https://firsthackersnews.com/macos-sequoia-update/): According to TechCrunch, several companies quickly responded to the issues caused by the macOS Sequoia update. - [Fake CAPTCHA sites install Lumma Stealer malware](https://firsthackersnews.com/lumma-stealer-malware/): A new malware campaign is gaining traction online, using fake CAPTCHA sites to trick users into installing Lumma Stealer (also known as Lumma C2). Users are asked to press specific key combinations to prove they're not a robot, but this action triggers the installation of the malware. - [Disney to End Use of Slack After Hack Exposes Company Data](https://firsthackersnews.com/disney/): The Walt Disney Company will stop using Slack for internal communication following a hack that leaked over a terabyte of company data. - [MediaTek Wi-Fi Zero-Click RCE Vulnerability](https://firsthackersnews.com/mediatek-cve-2024-20017/): A critical 0-click RCE vulnerability (CVE-2024-20017) in MediaTek Wi-Fi 6 chipsets, used by devices like Ubiquiti, Xiaomi, and Netgear, allows remote attacks without user interaction. - [Hacker stole data from Federal Bank customers](https://firsthackersnews.com/federal-bank/): A threat actor has allegedly claimed a breach of Federal Bank, exposing sensitive data of hundreds of thousands of customers. - [New macOS malware allows attackers to control devices remotely](https://firsthackersnews.com/macos-malware-hz-rat/): HZ RAT, a remote access trojan (RAT) that has targeted Windows devices since 2020, has recently been upgraded to also attack Mac users. A RAT allows attackers to gain remote control of a target computer with full administrator privileges. - [Threat actors claim to have compromised Dell’s employee database](https://firsthackersnews.com/dell-employee-database/): A hacking group has claimed responsibility for breaching the Dell employee database, asserting access to sensitive information of around 10,800 employees and partners on a prominent hacking forum. - [CISA Issues Six Advisories for Industrial Control Systems](https://firsthackersnews.com/cisa/): CISA has issued six advisories highlighting vulnerabilities in various industrial control systems. The advisories cover: - [Researchers Uncover Raptor Train Botnet with 60,000+ Devices](https://firsthackersnews.com/raptor-train-botnet/): The Raptor Train botnet is a three-tier network managed by "Sparrow" nodes. In Tier 1, compromised SOHO/IoT devices are infected with the custom Mirai variant "Nosedive," using exploitation and payload servers in Tier 2. - [Threat Actor Claims to Be Selling Bharat Petroleum Database](https://firsthackersnews.com/bharat-petroleum-database/): A threat actor is reportedly selling a database from Bharat Petroleum Corporation Limited (BPCL). DarkWebInformer first reported this on X, raising serious cybersecurity concerns for the corporation and its stakeholders. - [Scams and Fake Websites during Amazon Prime Day](https://firsthackersnews.com/scams-and-fake-websites/): Amazon Prime Day scams refer to fraudulent schemes that exploit the retailer's sell-off day. While the event is a big opportunity for retailers, scammers also use it to target unsuspecting shoppers. Networks of fake websites mimicking Amazon are created, and this article will explain what they are and how to avoid them. - [Apple releases iOS 18, fixing 32 security vulnerabilities](https://firsthackersnews.com/ios-18/): Apple has released iOS 18, fixing 32 security vulnerabilities. The update is available for iPhone XS and later, along with iPad Pro (13-inch, 12.9-inch 3rd gen and newer), iPad Pro 11-inch (1st gen and newer), iPad Air (3rd gen and newer), iPad (7th gen and newer), and iPad mini (5th gen and newer). - [North Korean hackers spread RustDoor Malware on LinkedIn](https://firsthackersnews.com/rustdoor-malware/): The attacks use RustDoor malware, often disguised as coding challenges or pre-employment tests. Victims receive seemingly legitimate projects, like Visual Studio tasks, which contain hidden malicious scripts that activate when the project is built. - [Hackers leverage Selenium Grid for malicious activity](https://firsthackersnews.com/hackers-leverage-selenium-grid-for-malicious-activity/): Threat actors are exploiting Selenium Grid's default lack of authentication in two active campaigns, deploying exploit kits, cryptominers, and proxyjackers. - [Critical Vulnerabilities Impact Millions of D-Link Routers — Patch Now!](https://firsthackersnews.com/d-link-routers/): Millions of D-Link routers are vulnerable to critical security flaws. Urgent firmware updates have been released, and users are advised to patch their devices immediately to prevent exploitation. - [Windows MSHTML zero-day actively exploited](https://firsthackersnews.com/windows-mshtml-zero-day/): Adobe's September 2024 updates fixed 28 vulnerabilities, including a critical ColdFusion flaw (CVSS 9.8). Other affected products include Photoshop, Illustrator, Premiere Pro, After Effects, Audition, and Media Encoder. These updates are crucial due to the high risk of exploitation. - [Apache Patches Critical OFBiz RCE Vulnerability](https://firsthackersnews.com/cve-2024-45195/): Hackers are exploiting a critical Apache OFBiz vulnerability (CVE-2024-45195) that allows unauthenticated remote code execution, threatening organizations using OFBiz. - [Kali Linux 2024.3 Launches with New Hacking Tools](https://firsthackersnews.com/kali-linux-2024-3/): Kali Linux 2024.3, the latest version of Offensive Security's Debian-based distribution for ethical hacking, has been released. This update introduces 11 new tools and includes key behind-the-scenes improvements. The Kali team noted several complex migrations happening simultaneously in this release. - [New Loki Backdoor Targets macOS Systems](https://firsthackersnews.com/loki-backdoor/): Cody Thomas created Apfell in 2018, an open-source macOS post-exploitation framework that later evolved into Mythic, a cross-platform framework addressing the limits of existing tools. - [New Android Spyware Posing as TV Streaming App Steals Data](https://firsthackersnews.com/android-spyware-2/): Recent research has uncovered new Android Spyware targeting mnemonic keys, vital for cryptocurrency wallet recovery. Disguised as legitimate apps, the malware scans devices for images containing mnemonic phrases and steals personal data such as text messages, contacts, and images. - [CosmicBeetle Targets SMBs Worldwide Using Old Vulnerabilities](https://firsthackersnews.com/cosmicbeetle/): ESET researchers confirmed that the CosmicBeetle group has been deploying ScRansom ransomware worldwide. - [Zyxel NAS Devices Prone to Command Injection Attacks](https://firsthackersnews.com/cve-2024-6342/): CVE-2024-6342, found in the export-cgi program of Zyxel NAS326 and NAS542 devices, allows an unauthenticated attacker to execute OS commands by sending a specially crafted HTTP POST request. - [Hackers Exploit GeoServer RCE to Deploy Malware](https://firsthackersnews.com/geoserver-rce-vulnerability/): Cybersecurity researchers at Fortinet recently discovered that hackers have been exploiting GeoServer RCE vulnerability to deploy malware, and the vulnerability is tracked as “CVE-2024-36401.” - [Vulnerabilities in IBM WebSphere Integration Server could let attackers execute commands.](https://firsthackersnews.com/vulnerabilities-in-ibm-websphere-integration/): IBM’s webMethods Integration Server, a widely used platform for connecting and integrating different applications and services, is impacted by three major vulnerabilities. These issues could potentially allow unauthorized access or manipulation of system functions, posing serious security risks. - [Akira Ransomware Targets SonicWall Firewall RCE Flaw](https://firsthackersnews.com/akira-ransomware-2/): Akira ransomware affiliates recently exploited vulnerabilities in SonicWall SSLVPN devices, targeting local accounts without MFA to gain unauthorized access. - [Predator Spyware leverages “one-click” and “zero-click” exploits](https://firsthackersnews.com/predator-spyware/): Recent research shows Predator spyware has resurfaced with improved evasion techniques, despite US sanctions. It's still active in countries like the DRC and Angola, targeting high-profile individuals with harder-to-track infrastructure, highlighting the need for stronger cybersecurity. - [Tor Browser 13.5.3 Released: What’s New?](https://firsthackersnews.com/tor-browser-13-5-3/): The Tor Project has released Tor Browser 13.5.3, featuring important security updates and usability improvements. You can download the latest version from the official Tor Browser website. - [Lazarus Hackers Targeting Job Seekers with JavaScript Malware](https://firsthackersnews.com/lazarus-hackers-3/): Lazarus Group, a notorious North Korean-linked hacker group active since 2010, has intensified its attacks in 2024. Group-IB researchers found Lazarus abusing Contagious Interview campaigns using BeaverTail malware and the InvisibleFerret backdoor. - [ToddyCat APT Exploits SMB and IKEEXT RCE to Deploy ICMP Backdoor](https://firsthackersnews.com/toddycat-apt-2/): ToddyCat is an APT group active since December 2020, targeting government and military entities in Europe and Asia. Known for sophisticated cyber-espionage, Kaspersky Lab found ToddyCat exploiting SMB, IKEEXT, and Exchange RCE to deploy an ICMP backdoor. - [New Emansrepo Malware Targets Windows via HTML Files](https://firsthackersnews.com/new-emansrepo-malware/): Emansrepo, a Python infostealer, is spread through phishing emails with fake purchase orders. The attack has evolved, now involving multiple stages. Stolen data is zipped and sent to the attacker, posing a significant threat to Windows users. - [RCE Vulnerability in D-Link WAP Allows Remote Access by Attackers](https://firsthackersnews.com/d-link/): The D-Link DAP-2310 Wireless Access Point is vulnerable to remote code execution, allowing attackers to gain unauthorized remote access. Discovered by Dark Wolf Solutions, this guide covers the details of the vulnerability, the models affected, and the steps users should take to protect themselves. - [New ManticoraLoader Malware Targets Citrix Users for Data Theft](https://firsthackersnews.com/manticoraloader-malware/): DeadXInject, the group behind AresLoader and AiDLocker ransomware, is now offering ManticoraLoader, a new Malware-as-a-Service (MaaS) targeting Windows systems. Available on underground forums and Telegram since August 8th, 2024, this C-based tool is designed to steal information such as IP addresses, usernames, and installed antivirus software. - [Snake Keylogger Targets Windows via Malicious Excel Files](https://firsthackersnews.com/snake-keylogger/): Researchers have identified a sophisticated phishing campaign using a .NET-based Snake Keylogger variant. This attack uses weaponized Excel files to compromise Windows systems, posing serious risks to data security. - [Voldemort Hackers Exploit Google Sheets to Target Windows Users](https://firsthackersnews.com/voldemort-campaign/): Proofpoint researchers have uncovered a cyberattack campaign, "Voldemort," using Google Sheets as a C2 platform. Targeting Windows users, the campaign employs a unique attack chain with both common and rare techniques to deliver custom malware, highlighting significant cybersecurity challenges. - [AutoIT Malware Steals Gmail Login Credentials](https://firsthackersnews.com/autoit-malware/): A malicious AutoIT executable opens Gmail login pages and steals clipboard data, captures keystrokes, and controls system behavior. It can evade detection by blocking user input. Users should be cautious with files from untrusted sources. - [Watch Out for Fake Palo Alto Tool Spreading Advanced Malware](https://firsthackersnews.com/fake-palo-alto-tool/): A sophisticated malware is threatening organizations in the Middle East by disguising itself as the legitimate Palo Alto GlobalProtect tool. - [Critical Vulnerability in Perl Installer Enables Traffic Interception](https://firsthackersnews.com/cve-2024-45321/): A critical vulnerability in App::cpanminus (cpanm), a popular tool for installing Perl modules, has been identified. Known as CVE-2024-45321, it allows attackers to intercept and manipulate traffic during module installation, posing significant cyber risks. - [Research Uncovers Eight Android and iOS Apps Leaking Users’ Sensitive Data](https://firsthackersnews.com/android-and-ios-apps/): The eight Android and iOS apps fail to protect user data by transmitting sensitive information, such as device details, geolocation, and credentials, over HTTP instead of HTTPS. This exposes data to theft, eavesdropping, and man-in-the-middle attacks, highlighting poor implementation of encryption. - [EDR Killer Malware Disables Security Tools on Windows Machines](https://firsthackersnews.com/edr/): Poortry and Stonestop, a sophisticated EDR wiper, work together in a multi-phased approach to disable security defenses. The loader, Stonestop, checks for the Poortry driver in the same directory and initiates a handshake via DeviceIoControl. Poortry then disables EDR products by altering kernel notify routines and patching callback functions linked to security drivers. - [Apache Vulnerability Exposed Unix Systems to Data Theft](https://firsthackersnews.com/apache-vulnerability/): A recently disclosed vulnerability in the Apache Portable Runtime (APR) library, identified as CVE-2023-49582, could expose sensitive application data on Unix platforms. - [Microsoft 365 Flags Image Emails as Malware](https://firsthackersnews.com/microsoft-365/): Microsoft 365 users report emails with images being wrongly flagged as malware and quarantined, identified as Issue ID: EX873252. This issue has raised significant concerns among businesses and individual users relying on Exchange Online for daily communication. - [Ransomware Hits Patelco Credit Union, Steals Customer and Employee Data](https://firsthackersnews.com/patelco-credit-union/): Patelco Credit Union revealed a ransomware attack compromising member and employee data, raising concerns about security and privacy. - [BeaverTail Malware Hits Windows Users via Games](https://firsthackersnews.com/beavertail-malware/): Researchers discovered a new malware campaign called BeaverTail, targeting job seekers in a North Korean cyber espionage operation. - [Active Exploitation of Chrome Zero-Day Vulnerability](https://firsthackersnews.com/chrome-zero-day/): Google has released Chrome 128 (128.0.6613.84 for Linux and 128.0.6613.84/.85 for Windows and Mac) to address a critical zero-day vulnerability actively exploited in the wild. The update includes 38 security fixes, with contributions from external researchers. - [Caution: Malicious Slack Ads Deliver Harmful Payloads](https://firsthackersnews.com/slack/): Cybercriminals are using Google search ads to distribute malware disguised as legitimate ads for Slack. This advanced tactic shows how threat actors are getting better at avoiding security measures and detection. - [Ngate malware steals card funds on Android devices](https://firsthackersnews.com/ngate-malware/): ESET researchers recently identified new Android malware called “Ngate” that allows hackers to withdraw money from victims’ payment cards. - [Log4j Vulnerability Exploited Again to Deploy Crypto-Mining Malware](https://firsthackersnews.com/log4j-vulnerability/): Recent Log4j attacks use obfuscated LDAP requests to execute malicious scripts, establish persistence, and exfiltrate data. Multiple backdoors and encrypted channels maintain control, emphasizing the ongoing threat of the Log4j vulnerability, initially discovered in November 2021 with a CVSS score of 10. - [Backdoor in MIFARE Smart Cards Reveals User-Defined Keys](https://firsthackersnews.com/mifare-smart-cards/): Researchers uncover new attack vectors in MIFARE Classic cards by analyzing the CRYPTO-1 algorithm and vulnerabilities, demonstrating how to extract data, clone cards, and compromise both new and old card generations. - [New UULoader Malware Spreads Gh0st RAT and Mimikatz](https://firsthackersnews.com/uuloader-malware/): UULoader malware delivers payloads like Gh0st RAT and Mimikatz, targeting Korean and Chinese speakers through malicious installers. - [Dell SupportAssist Vulnerability Enables Privilege Escalation on PCs](https://firsthackersnews.com/dell-supportassist-vulnerability/): A critical security vulnerability affects Dell SupportAssist for Home PCs, specifically in installer version 4.0.3. - [Unauthenticated RCE in WordPress Plugin Exposes 100K Sites](https://firsthackersnews.com/cve-2024-5932/): A critical vulnerability (CVE-2024-5932) in the GiveWP plugin exposes over 100,000 WordPress sites to remote code execution (RCE) attacks, as disclosed by researcher villu164 through the Wordfence Bug Bounty Program. - [MegaMedusa: A Powerful Web DDoS Tool Used by Hackers](https://firsthackersnews.com/megamedusa/): RipperSec, a pro-Palestinian Malaysian hacktivist group that started on Telegram in June 2023, has quickly grown to over 2,000 members. They carry out cyberattacks like data breaches, defacements, and DDoS attacks, mainly using MegaMedusa, a simple but effective DDoS tool that evades detection with 10 randomization techniques. Despite its lack of advanced CAPTCHA-solving abilities, MegaMedusa, paired with RipperSec's large and motivated community, represents a serious cyber threat. - [Urgent: Windows TCP/IP Vulnerability Discovered, Update Now](https://firsthackersnews.com/windows-tcp-ip-vulnerability/): A critical vulnerability in the Windows TCP/IP stack enables unauthenticated remote code execution (RCE) through specially crafted IPv6 packets. This flaw affects all supported versions of Windows and Windows Server, allowing attackers to execute arbitrary code remotely. - [Vulnerability in Microsoft Apps Let Hackers Spy on Mac Users](https://firsthackersnews.com/microsoft-apps/): A critical vulnerability in Microsoft apps for macOS allowed hackers to surreptitiously spy on Mac users' activities. Security researchers from Cisco Talos revealed how attackers could exploit this flaw to bypass macOS security measures and gain unauthorized access to sensitive data and resources. - [New Styx Stealer Targets Users to Steal Login Passwords](https://firsthackersnews.com/styx-stealer/): A new threat called Styx Stealer has emerged, targeting users by stealing sensitive data like saved passwords, cookies, and autofill details from popular web browsers. - [Google Pixel Devices Shipped with Flawed App](https://firsthackersnews.com/google-pixel/): Recent research revealed a vulnerability in the Android package of many Google Pixel smartphones. Devices shipped globally since September 2017 could be at risk of malware due to a pre-installed app named “Showcase.apk,” commonly used on showroom devices. - [Lazarus Group Exploited Windows Zero-day](https://firsthackersnews.com/cve-2024-38193/): The notorious Lazarus hacker group exploited a zero-day vulnerability in Microsoft Windows, targeting the Ancillary Function Driver for WinSock (AFD.sys), identified as CVE-2024-38193. Discovered by researchers Luigino Camastra and Milanek in June 2024, the flaw allowed unauthorized access to sensitive system areas, posing a global threat. - [New Exploit BYOVDLL Bypasses LSASS Protection](https://firsthackersnews.com/new-exploit-byovdll-bypasses-lsass-protection/): In July 2022, Microsoft patched a PPL bypass flaw, but a new exploit called "BYOVDLL" has been discovered, allowing attackers to bypass LSASS protection. - [Malspam Targets AnyDesk and Microsoft Teams](https://firsthackersnews.com/malspam-campaign/): Cybersecurity researchers have uncovered a sophisticated malspam campaign targeting users via email and phone. Attackers are exploiting AnyDesk and Microsoft Teams to gain unauthorized access to victims' computers, highlighting evolving cybercriminal tactics. - [Ransomware Group Introduces New EDR Killer Tool](https://firsthackersnews.com/edrkillshifter/): A ransomware group, RansomHub, has introduced EDRKillShifter, a tool designed to disable EDR systems. This advancement highlights the group's evolving tactics to bypass security measures and execute attacks. Although a recent attack was stopped, the threat from such groups remains significant. - [Critical IBM QRadar Flaws Enable Remote Arbitrary Code Execution](https://firsthackersnews.com/ibm-qradar-flaws/): IBM recently revealed critical vulnerabilities in QRadar Suite Software and IBM Cloud Pak for Security. Exploitation of these flaws could let attackers execute arbitrary code remotely, posing serious security risks. IBM has released a fix and urges users to update their systems right away. - [0.0.0.0 Day – 18-Year-Old Flaw Bypasses Browser Security](https://firsthackersnews.com/0-0-0-0-day/): Threat actors frequently exploit browser flaws to gain unauthorized access and conduct various illicit activities. Recently, Oligo Security discovered a critical 18-year-old vulnerability, dubbed "0.0.0.0 day," which bypasses all browser security measures. - [Update Now: Critical SAP Auth Bypass and SSRF Vulnerabilities Fixed](https://firsthackersnews.com/sap-auth-bypass-ssrf-vulnerabilities/): SAP has issued a major security update addressing critical authentication bypass and server-side request forgery vulnerabilities, with CVSS scores of 9.8 and 9.1. The company advises all users to install the updates promptly, as these issues impact many customers. - [1Password macOS Vulnerability Leads to Credentials Leak](https://firsthackersnews.com/1password-macos-vulnerability/): A critical vulnerability in 1Password for macOS allows attackers to bypass security measures and access vault items. This issue affects every version of the macOS app. A patch is now available, and users are strongly advised to update their software as soon as possible. - [Apache OFBiz RCE Vulnerability Found, Patch Immediately](https://firsthackersnews.com/apache-ofbiz-rce-vulnerability/): A vulnerability, CVE-2024-38856, has been found in Apache OFBiz, allowing unauthenticated remote code execution. A patch is available, and developers strongly recommend installing it immediately due to the high risk of exploitation. - [Beware: Fake AI Editor Stealing Logins](https://firsthackersnews.com/fake-ai-editor/): Recently, Trend Micro researchers uncovered a sophisticated malvertising campaign targeting social media users with a multi-step deception to steal login credentials. - [New Spyware Targeting Android Users](https://firsthackersnews.com/lianspy-spyware/): Cybersecurity experts have uncovered sophisticated Android spyware, LianSpy, targeting users to steal sensitive data. It uses advanced evasion techniques, posing a significant threat to Android users globally. - [Russia-linked APT used a car ad to phish diplomats with Headlace malware.](https://firsthackersnews.com/headlace-malware/): Earlier this May, APT28 targeted European networks with HeadLace malware and credential-harvesting web pages. - [Critical Flaw in Voice Over Wi-Fi Allows Eavesdropping](https://firsthackersnews.com/voice-over-wi-fi/): Voice Over Wi-Fi (VoWiFi) is commonly used for making voice calls over Wi-Fi, improving call quality and reliability. Recently, cybersecurity researchers discovered a vulnerability in VoWiFi that allows attackers to eavesdrop on calls and SMS. - [Ubiquiti G4 Vulnerability Discovered, Enabling DDoS Attacks](https://firsthackersnews.com/ubiquiti-g4-vulnerability/): Researchers found a flaw in Ubiquiti G4 Wi-Fi cameras that exposes critical data. They believe a similar vulnerability was used in 2019 for DoS attacks on many cameras. Despite Ubiquiti's claims of a fix, many devices remain vulnerable. - [Hackers Exploit WordPress Plugin File Upload Flaw](https://firsthackersnews.com/cve-2024-6220/): Hackers are exploiting a critical vulnerability (CVE-2024-6220) in the WordPress plugin 简数采集器 (Keydatas) that allows unauthenticated users to upload arbitrary files, risking remote code execution and full site takeover. - [Microsoft Patches Critical Edge Flaw Enabling Code Execution](https://firsthackersnews.com/microsoft-3/): Improper Data Validation in Dawn (CVE-2024-7256): This vulnerability in Microsoft Edge’s Dawn component allows attackers to execute arbitrary code using crafted HTML content, leading to potential system compromise. - [Hackers Exploiting GeoServer RCE Flaw, 6,635 Servers at Risk](https://firsthackersnews.com/cve-2024-36401/): A critical flaw in GeoServer, an open-source Java software, exposes thousands of servers to risk. The vulnerability, CVE-2024-36401, allows unauthenticated remote code execution, threatening global geospatial data infrastructures. - [Phishing Campaign Exploited Proofpoint for Email Spoofing](https://firsthackersnews.com/proofpoint/): Guardio Labs recently identified "EchoSpoofing," a critical vulnerability in Proofpoint's email protection service used by 87% of Fortune 100 companies. - [New Specula Tool Turns Outlook into a C2 Server via Registry Exploit](https://firsthackersnews.com/spectra-tool/): Cybersecurity firm TrustedSec has introduced a new tool named Specula, which leverages a longstanding vulnerability in Microsoft Outlook to turn it into a Command and Control (C2) server. This discovery has raised significant concerns within the cybersecurity community, exposing a critical vulnerability in many corporate networks. - [Microsoft 365 and Azure Outage Disrupts Multiple Services](https://firsthackersnews.com/microsoft-365-and-azure-outage/): Microsoft is investigating a global outage affecting access to some Microsoft 365 and Azure services. - [Chinese Users Targeted by Gh0st RAT Malware Through Fake Chrome Page](https://firsthackersnews.com/gh0st-rat-trojan/): Attackers are using Gh0stGambit to spread Gh0st RAT malware to Chinese users via a fake Google Chrome download page, mimicking the legitimate site. - [Progress Patches New Privilege Escalation Flaw in MOVEit File Transfer](https://firsthackersnews.com/cve-2024-6576/): Progress, the company behind MOVEit Transfer, has issued a critical security alert for a newly discovered vulnerability in its product. The flaw, CVE-2024-6576, is classified as high-severity with a CVSS score of 7.3, indicating significant user risk. - [Malicious Python Package Targets macOS Developers for Google Cloud Login Theft](https://firsthackersnews.com/malicious-python-package/): Hackers exploit malicious Python packages to attack developer environments, inject harmful code, and steal sensitive information or install malware. This method leverages popular repositories for broad impact with minimal effort. - [RaspAP Vulnerability Allows Hackers to Gain Privileges on Raspberry Pi Devices](https://firsthackersnews.com/raspap-vulnerability/): A critical local privilege escalation vulnerability (CVE-2024-41637) was found in RaspAP, an open-source project for turning Raspberry Pi devices into wireless access points or routers. Rated 9.9 (Critical) on the CVSS scale, it affects versions before 3.1.5 and was publicly disclosed on July 27, 2024, after unsuccessful attempts to reach the RaspAP security team. - [Phishing Attack Hits Indian Mobile Users via India Post Scams](https://firsthackersnews.com/india-post-scams/): Indian iPhone users are inundated with SMS phishing scams posing as India Post delivery notifications, aimed at stealing credentials for future scams. - [Threat Actors Claim Leak of 250M IOC Data; CrowdStrike Responds](https://firsthackersnews.com/crowdstrikes-response/): CrowdStrike, a prominent cybersecurity firm, responded to the claims, stating that while USDoD has been involved in legitimate breaches, their credibility in this case is questionable. The history of exaggeration, inconsistencies in the leaked data, and CrowdStrike’s response cast doubt on the authenticity and severity of the claimed leak. - [Google Chrome Issues Warnings for Malicious Downloads](https://firsthackersnews.com/google-chrome-2/): Google Chrome now has a new download system with alerts for potentially harmful files, enhancing user security. - [Jellyfish Loader Malware Discovered, Poses Threat to 2024 Olympics](https://firsthackersnews.com/jellyfish-loader-malware/): A new threat, Jellyfish Loader, has been identified as a .NET-based shellcode downloader disguised as a Windows shortcut. Despite its unusual features suggesting it may still be in development, it is capable of deploying various other types of malware. - [Alert: Krampus Loader Gaining Popularity on the Dark Web](https://firsthackersnews.com/krampus-loader/): Krampus Loader is a type of malware designed to facilitate the delivery and execution of additional malicious payloads on compromised systems. - [Watch Out for Malicious Python Packages That Steal Sensitive Data](https://firsthackersnews.com/python-packages/): Malicious Python packages uploaded by "dsfsdfds" to PyPI stole sensitive data from user systems and sent it to a Telegram bot likely associated with Iraqi cybercriminals. Active since 2022, the bot has over 90,000 Arabic messages and serves as both a command-and-control center and an underground marketplace for social media manipulation tools. - [Attackers Exploit Swap File to Steal Credit Card Information](https://firsthackersnews.com/swap-file/): Researchers at Sucuri recently discovered that website swap files can be exploited to install a persistent credit card skimmer on Magento e-commerce platforms. Swap files, which store overflow data from RAM, can contain critical information like passwords and encryption keys, making them a key target for hackers. - [Flaw in Cisco VPN routers enables remote code execution by attackers](https://firsthackersnews.com/cisco-vpn/): Cisco disclosed a significant flaw in the upload module of RV340 and RV345 VPN routers, allowing remote, authenticated attackers to run arbitrary code. Tracked as CVE-2024-20416 with a CVSS score of 6.5, it results from insufficient boundary checks in HTTP requests. - [Watch out for fake browser updates installing malicious BOINC software.](https://firsthackersnews.com/socgholish/): Since July 4, 2024, SocGholish (FakeUpdates) has shown new behavior. The infection chain starts with a compromised website prompting a fake browser update. Downloading the update triggers malicious code that retrieves additional malware. - [SonicOS IPSec VPN Vulnerability Allows Attackers to Cause DoS Condition](https://firsthackersnews.com/cve-2024-40764/): SonicWall has disclosed a critical heap-based buffer overflow vulnerability in SonicOS IPSec VPN, identified as CVE-2024-40764, which can allow remote attackers to cause a DoS condition. - [BadPack Malware for Android Infects APK Installers](https://firsthackersnews.com/badpack-malware/): The detailed paper on BadPack malware reveals an unusual tactic for evading analysis. Attackers manipulate the internals of APK files, rendering debug and reverse engineering tools ineffective and blocking real-time analysis. Despite these modifications, the file retains its ZIP archive capabilities, carrying a set of compressed files that remain intact and ready for the attack. - [Hackers Claim Dettol Data Breach Affects 453,646 Users](https://firsthackersnews.com/dettol-data-breach/): Threat actor ‘Hana’ claims to have breached Dettol India, affecting 453,646 users, according to a FalconFeedsio post on X. - [CrowdStrike Update Leads to Widespread Windows BSOD Crashes](https://firsthackersnews.com/crowdstrike/): A recent CrowdStrike update has caused widespread Blue Screen of Death (BSOD) errors on Windows machines. The issue affects multiple versions of the company’s sensor software, prompting an urgent investigation and quick response from CrowdStrike's engineering team. Reports on Reddit confirm that this update is linked to numerous Windows crashes. - [New TE.0 HTTP Request Smuggling Vulnerability Affects Google Cloud Websites](https://firsthackersnews.com/http-request-smuggling/): The TE.0 HTTP Request Smuggling vulnerability affected numerous targets, including those protected by Google’s Identity-Aware Proxy (IAP), and was prevalent among Google Cloud-hosted websites using HTTP/1.1 by default. - [ShadowRoot Ransomware Targets Businesses with Weaponized PDFs](https://firsthackersnews.com/shadowroot-ransomware/): X-Labs identified ransomware targeting Turkish businesses through PDF attachments in emails from the internetru domain. These PDFs contain links that download exe payloads, encrypting files with the ".shadowroot" extension. This ransomware is affecting global organizations, including healthcare and e-commerce sectors. - [Poco RAT uses 7zip files via Google Drive for attacks](https://firsthackersnews.com/poco-rat/): In early 2024, Cofense researchers discovered Poco RAT, a malware specifically targeting Spanish-speaking individuals in the mining industry. It spreads through Google Drive-hosted 7zip archives, effectively masking its malicious activities. By Q2 2024, Poco RAT had expanded its reach to multiple sectors, with a predominant focus remaining on mining. - [HardBit Ransomware Evades Detection with Passphrase Protection](https://firsthackersnews.com/hardbit-ransomware/): In 2022, HardBit Ransomware 4.0 emerged, differing from typical groups by avoiding leak sites and double extortion. Their tactics include data theft, encryption, and ransom demands with additional threats. Cybereason researchers found HardBit actively using passphrase protection to evade security measures. - [Pinterest Data Leak: Hackers Claim Access to 60M Records](https://firsthackersnews.com/pinterest/): Pinterest, with over 518 million users, faces a potential data leak. Hacker "Tchao1337" claims to have leaked 60 million rows of user data on a forum. The 1.59 GB database reportedly contains 6 million records, including email addresses, usernames, user IDs, and IP addresses. - [Juniper Junos Flaw Allows Full ‘Root’ Access to Attackers](https://firsthackersnews.com/juniper-junos-flaw/): Hackers target Juniper Junos due to its extensive use in business networking, making it a prime target for accessing valuable systems. Its prominence in large organizations means successful breaches can lead to significant data loss or operational disruption, benefiting threat actors. - [FishXProxy amplifies phishing attacks with cunning and deceptive tactics](https://firsthackersnews.com/fishxproxy/): Imagine receiving an email that appears completely legitimate. This is the deceptive capability of the new FishXProxy Phishing Kit, an advanced toolkit emerging from underground cybercrime circles. - [Hackers Using ClickFix Tactics to Deploy Malware](https://firsthackersnews.com/clickfix/): McAfee Labs researchers have identified a sophisticated malware delivery method, "ClickFix," using advanced social engineering to trick users into executing malicious scripts, leading to severe security breaches. This article explores the intricacies of ClickFix, its implications, and protective measures. - [Microsoft Patches 3 Critical Vulnerabilities in July Update](https://firsthackersnews.com/microsoft-2/): Microsoft's July security update addresses 142 vulnerabilities, including one already being exploited. This update is part of Microsoft's regular "Patch Tuesday" release. - [Chinese APT40 Exploits New Vulnerabilities Within Hours](https://firsthackersnews.com/chinese-apt40/): International cybersecurity agencies have issued a warning about APT40, a PRC state-sponsored cyber group linked to the Ministry of State Security. Based in Hainan Province, APT40 has targeted global organizations, prompting Australian authorities to release an advisory with case studies to aid cybersecurity practitioners in detecting and mitigating their attacks. - [Eldorado Ransomware Targets Windows and Linux Systems](https://firsthackersnews.com/eldorado-ransomware/): Group-IB researchers recently discovered the new Eldorado ransomware targeting both Windows and Linux systems. - [Jenkins Script Console used for cryptocurrency mining attacks by hackers](https://firsthackersnews.com/jenkins-script-console/): Researchers discovered that attackers can exploit improperly configured Jenkins Script Console for criminal activities like cryptocurrency mining. - [Ghostscript Rendering Platform Flaw Enables Remote Code Execution](https://firsthackersnews.com/ghostscript-vulnerabilit/): A critical vulnerability, CVE-2024-29510, has been discovered in the Ghostscript rendering platform. This format string flaw affects versions up to 10.03.0, allowing attackers to bypass the -dSAFER sandbox and execute remote code. The vulnerability poses significant risks for web applications and services that utilize Ghostscript for document conversion and previews. - [Info-Stealing Malware Posing as Accessibility Tools and Chrome Extensions](https://firsthackersnews.com/info-stealing-malware/): The first half of 2024 has witnessed a notable surge in info-stealing malware masquerading as AI tools and Chrome extensions. This trend underscores cybercriminals' growing sophistication and adaptability, leveraging emerging technologies and popular platforms to target unsuspecting victims. - [Orcinius Trojan Targets Users Through Dropbox & Google Docs](https://firsthackersnews.com/orcinius/): A new multi-stage trojan, "Orcinius," exploits Dropbox and Google Docs. - [ScreenConnect Remote Access Client Exploited by Hackers to Deploy AsyncRAT](https://firsthackersnews.com/asyncrat/): eSentire’s Threat Response Unit (TRU) has uncovered a sophisticated campaign in which threat actors exploit the ScreenConnect remote access client to deliver the AsyncRAT trojan, revealing the evolving tactics of cybercriminals and emphasizing the critical need for robust cybersecurity measures. - [Hackers Exploit Twilio API to Verify MFA Phone Numbers](https://firsthackersnews.com/twilios-authy-app/): An unauthenticated endpoint in Twilio’s Authy app allowed malicious actors to identify user phone numbers. While no evidence suggests a broader system intrusion or sensitive data exposure, Twilio urges all Authy users to update their Android and iOS apps to mitigate the risk of phishing and smishing attacks exploiting the exposed phone numbers. - [FakeBat Malware Targets AnyDesk, Zoom, Teams & Chrome](https://firsthackersnews.com/fakebat-malware/): Cybersecurity researchers at Sekoia have identified FakeBat malware actively exploiting these widely used applications. - [RegreSSHion OpenSSH Vulnerability Enables RCE](https://firsthackersnews.com/regresshion/): A newly discovered OpenSSH vulnerability, dubbed regreSSHion, allows remote attackers to gain root privileges on Linux systems using the glibc library. This flaw lets unauthenticated attackers execute arbitrary code and obtain root access. Given OpenSSH's extensive use, this flaw's impact could be as significant as the infamous Log4Shell. - [CapraRAT Mimics Popular Apps to Attack Android Users](https://firsthackersnews.com/caprarat/): Transparent Tribe (aka APT36), active since 2016, uses social engineering to target Indian government and military personnel. Recently, their CapraRAT has been mimicking popular Android apps to attack Android users, showing adaptability and expanding their espionage efforts against Indian targets. - [Google Offers $250,000 for Full VM Escape Zero-Day Vulnerability](https://firsthackersnews.com/google/): Google has launched kvmCTF, a new vulnerability reward program targeting the Kernel-based Virtual Machine (KVM) hypervisor. - [Malware Spreading via Binance Smart Contracts Blockchain](https://firsthackersnews.com/binance-smart-contracts/): Cybercriminals are exploiting Binance smart contracts as intermediary C2 servers, favoring them due to their resilience against takedowns. Initially used for deploying infostealers, these smart contracts have potential applications for distributing various types of malware. - [New GrimResource Attack Technique Exploits MMC and DLL Flaw](https://firsthackersnews.com/grimresource-attack-technique/): A new malicious code execution technique, GrimResource, targets Microsoft Management Console. Attackers exploit an old cross-site scripting vulnerability to bypass defenses and deploy malware to endpoints. - [Critical OpenSSH Flaw Puts Millions of Linux Servers at Risk](https://firsthackersnews.com/critical-openssh-flaw/): A critical vulnerability in OpenSSH, affecting versions 8.5p1 to 9.7p1, has been discovered, potentially exposing millions of Linux systems to arbitrary code execution attacks. This flaw in the sshd(8) component has sparked major concerns in the cybersecurity community due to its widespread implications. - [Beware of the “TRANSLATEXT” Chrome Extension from North Korean Hackers](https://firsthackersnews.com/translatext-chrome-extension/): They used a malicious Chrome extension called “TRANSLATEXT” to steal sensitive data, including email addresses, credentials, and browser screenshots. - [Xeno RAT is actively targeting users via GitHub repositories and .gg domains.](https://firsthackersnews.com/xeno-rat/): Threat actors leverage RATs for sustained access to compromised systems, facilitating prolonged espionage and exploitation. - [PoC Released for SQL Injection in Fortra FileCatalyst](https://firsthackersnews.com/cve-2024-5276/): A PoC exploit for the SQL Injection vulnerability CVE-2024-5276 in Fortra FileCatalyst Workflow has been released, affecting versions up to 5.1.6 Build 135. - [Critical Vulnerability in MOVEit Transfer Allowed Hackers to Access Files](https://firsthackersnews.com/moveit-transfer/): A critical vulnerability, CVE-2024-5806, in MOVEit Transfer software poses severe risks to organizations relying on it for secure data transfers. This flaw, found in versions 2023.0.0 to 2023.0.10, 2023.1.0 to 2023.1.5, and 2024.0.0 to 2024.0.1, allows attackers to bypass authentication and gain administrative access by sending specially crafted requests due to improper validation of user input during authentication. - [Threat Actor Claims Zero-Day Sandbox Escape and RCE in Chrome Browser](https://firsthackersnews.com/chrome-browser/): A threat actor has publicly claimed a zero-day vulnerability in the widely-used Google Chrome browser. The account MonThreat, known for credible cybersecurity disclosures, made this claim via a tweet. - [Linux LPE Zero-Day Exploit via GRUB Bootloader](https://firsthackersnews.com/linux-lpe-zero-day-exploit/): A new threat actor has surfaced, claiming a zero-day vulnerability in the Linux GRUB bootloader for local privilege escalation (LPE). This has sparked considerable concern in the cybersecurity community, with Dark Web Intelligence recently tweeting about the claim. - [SneakyChef and SugarGhost, newly identified RAT malware strains](https://firsthackersnews.com/sneakychef/): Talos Intelligence has uncovered a sophisticated cyber campaign orchestrated by the threat actor SneakyChef. This operation utilizes the SugarGh0st RAT and other malware to target government agencies, research institutions, and organizations globally. - [Microsoft Power BI Vulnerability Exposes Organizations’ Sensitive Data](https://firsthackersnews.com/microsoft-power-bi-vulnerability/): A Microsoft Power BI vulnerability allows unauthorized access to sensitive data in reports, affecting tens of thousands of organizations and exposing employee, customer, and confidential information. Attackers can exploit this flaw to retrieve hidden data attributes, records, and details beyond what the reports display. - [New Linux Variant of RansomHub Targets ESXi Systems](https://firsthackersnews.com/ransomhub/): Hackers frequently target ESXi systems due to their extensive use in managing enterprise virtualized infrastructure, making them attractive targets. Exploiting security flaws in ESXi, threat actors can deploy ransomware and carry out other malicious activities, greatly impacting affected organizations. Recorded Future recently identified a new Linux variant of RansomHub actively attacking ESXi systems. - [New Security Flaw Enables Access to Microsoft Corporate Email Accounts](https://firsthackersnews.com/microsoft/): A new security flaw allows attackers to impersonate Microsoft corporate email accounts, increasing phishing risks. Discovered by researcher Vsevolod Kokorin (Slonser), the bug remains unpatched by Microsoft. - [Hackers Use Progressive Web Apps to Steal Passwords](https://firsthackersnews.com/phishing-progessivewebapps/): Hackers are increasingly exploiting Progressive Web Apps (PWAs) for sophisticated phishing attacks to steal user credentials, as highlighted by security researcher mr.d0x. PWAs, built using HTML, CSS, and JavaScript, offer a user experience similar to native apps, including features like push notifications and offline capabilities. - [Hackers Use Windows Installer (MSI) Files to Spread Malware](https://firsthackersnews.com/windows-installer-msi-files/): Cybersecurity researchers have uncovered a sophisticated malware campaign by the Void Arachne group, targeting Chinese-speaking users with malicious Windows Installer (MSI) files. - [Chrome Security Update: Fixes for Six Vulnerabilities](https://firsthackersnews.com/chrome-browser-update/): Google has released a new Chrome browser update, version 126.0.6478.114/115 for Windows and Mac, and 126.0.6478.114 for Linux. This update, rolling out over the coming days and weeks, addresses multiple security vulnerabilities. - [Hackers are using new techniques to target Docker API](https://firsthackersnews.com/docker-api/): This campaign targets Docker API endpoints lacking authentication and shares tactics, techniques, and procedures (TTPs) with Spinning YARN, suggesting a connection. Analysis of payload specifics is crucial to tracking the evolution of these campaigns, which recycle names for updated or replaced payloads. - [Hidden Backdoor in D-Link Routers Lets Attackers Log in as Admin](https://firsthackersnews.com/backdoor-in-d-link-routers/): A critical vulnerability in several D-Link wireless router models allows unauthenticated attackers to gain administrative access. The CVE-2024-6045 vulnerability has a high severity CVSS score of 8.8. - [Lumma Stealer Spreads Through Fake Browser Updates Using ClearFake](https://firsthackersnews.com/lumma-stealer/): Recent research uncovered websites deploying Lumma Stealer disguised as browser updates. These sites, posing as tutorial pages with legitimate-looking guides, open a malicious JS iframe using the ClearFake framework. Some have been active for weeks. - [Microsoft Patches Critical MSMQ Flaw](https://firsthackersnews.com/msmq-rce-vulnerability/): On Patch Tuesday, June 11, 2024, Microsoft fixed numerous flaws, including a remote code execution vulnerability in Microsoft Message Queuing (MSMQ) affecting various Windows and Windows Server versions, even those at end of life. No exploitation has been detected yet, but it's likely only a matter of time. - [Beware: WARMCOOKIE Backdoor Knocking at Your Inbox](https://firsthackersnews.com/warmcookie-backdoor/): WARMCOOKIE is a new Windows backdoor delivered via a phishing campaign called REF6127. It can take screenshots, deliver additional payloads, and fingerprint systems. "This malware is a serious threat, enabling access to target environments and deployment of more malware," Elastic Security Labs told Cyber Security News. - [0-Day Vulnerability in 10,000 Web Apps Exploited with XSS Payloads](https://firsthackersnews.com/xss-vulnerability/): A significant vulnerability, CVE-2024-37629, has been discovered in SummerNote 0.8.18, allowing Cross-Site Scripting (XSS) via the Code View function. - [Hackers Exploit Linux SSH Services to Deploy Malware](https://firsthackersnews.com/linux-ssh-services/): SSH and RDP provide remote server access (Linux and Windows respectively) for administration. Both protocols are vulnerable to brute-force attacks if strong passwords and access controls are not used. - [Critical Flaw in Apple Ecosystems Allows Unauthorized Access](https://firsthackersnews.com/apple-ecosystems/): Hackers target Apple due to its large user base and wealthy customers, including business people and managers with important information. - [SSLoad Malware Utilizes MSI Installer to Initiate Delivery Chain](https://firsthackersnews.com/ssload-malware-2/): Recently, cybersecurity researchers at Intezer found that SSLoad malware utilizes MSI installers to initiate its delivery chain. - [Biometric Terminal Exposed to QR Code SQL Injection Vulnerability](https://firsthackersnews.com/biometric-terminal/): A popular ZKTeco biometric terminal has critical vulnerabilities, including an SQL injection flaw via QR codes. This discovery raises serious concerns about the security of widely used biometric access control systems. - [EmailGPT Vulnerability Exposes Sensitive Data to Attackers](https://firsthackersnews.com/emailgpt-vulnerability/): A new prompt injection vulnerability, CVE-2024-5184, has been found in EmailGPT, the service and Chrome plugin that assists Gmail users in composing emails with OpenAI's GPT model. This vulnerability allows attackers to manipulate the model's inputs, potentially executing malicious actions with a CVSS base score of 6.5, indicating a medium severity level. - [PoC Exploit Released for Veeam Authentication Bypass Flaw](https://firsthackersnews.com/cve-2024-29849/): A PoC exploit has been released for the critical Veeam Backup Enterprise Manager authentication bypass vulnerability, CVE-2024-29849, with a CVSS score of 9.8. This article explores the vulnerability, exploit, and potential implications for organizations using Veeam software. - [Muhstik Malware Attacks Apache RocketMQ for Remote Code Execution](https://firsthackersnews.com/muhstik-malware/): Cybersecurity researchers at Aqua Nautilus recently discovered that Muhstik malware has been actively attacking the Apache RocketMQ platform to execute remote code. - [Fog Ransomware Targets Windows Servers Admins for RDP Logins](https://firsthackersnews.com/fog-ransomware/): Arctic Wolf Labs began tracking the Fog ransomware variant on May 2, 2024. All victims were US-based, with 80% in education and 20% in recreation. - [Cisco Webex Meetings Flaw Enables Unauthorized Access](https://firsthackersnews.com/cisco-webex-meetings-flaw/): The vulnerability in Cisco Webex Meetings, found during targeted security research, allowed unauthorized access to sensitive meeting details. Cisco fixed the issue globally on May 28, 2024. - [Caution: Phishing Emails Urging Execution via Paste (CTRL+V)](https://firsthackersnews.com/phishing/): Phishing attackers distribute email attachments with malicious HTML files designed to exploit users into running the code by prompting them to paste and execute it, leveraging social engineering. - [Security Vulnerability in Zyxel NAS Devices Enables Remote System Takeover](https://firsthackersnews.com/zyxel-flaw/): Zyxel has identified and released security patches for critical vulnerabilities affecting their NAS326 and NAS542 devices. These vulnerabilities, known as command injection and remote code execution, could allow attackers to gain unauthorized access and potentially take control of your NAS device remotely. - [Hackers Use Cracked MS Office Versions to Deliver Malware](https://firsthackersnews.com/ms-office/): Malicious actors are using file-sharing platforms to distribute malware disguised as cracked MS Office. During infection, the malware retrieves the download URL and target platform, potentially enabling tailored attacks and evasion of detection. - [CarnavalHeist Uses Word Documents to Steal Login Credentials](https://firsthackersnews.com/carnavalheist/): Hackers exploit the widespread use and trust of Word documents, easily deceiving users into opening them. These documents can contain macros or exploits that run malicious code, enabling data theft, malware installation, or remote system control. Cisco Talos researchers recently discovered that the malware “CarnavalHeist” is using Word documents to steal login credentials. - [FlyingYeti Uses WinRAR Flaw for Malware Attacks](https://firsthackersnews.com/flyingyeti/): Since Russia's invasion of Ukraine on February 24, 2022, tensions have been high globally. Following the invasion, Ukraine imposed a moratorium on utility service evictions and terminations for unpaid debt, which ended in January 2024. During this time, a threat actor known as "FlyingYeti" exploited the situation. - [Citrix Workspace App Lets Attackers Elevate Privileges from User to Root](https://firsthackersnews.com/citrix-workspace-app/): A critical vulnerability in the Citrix Workspace app for Mac, tracked as CVE-2024-5027, could allow attackers to elevate privileges from a local authenticated user to root. This poses a significant risk to users and organizations relying on Citrix Workspace for virtual app and desktop access. - [Cybercriminals are Using Microsoft Office Documents to Spread Malware in Business Environments](https://firsthackersnews.com/microsoft-office/): Microsoft Office provides tools for creating professional reports, college essays, CVs, and notes on Office 365. It offers text and data editing features, including macros and Python scripting in Excel, facilitating automatic data updates. - [Foxit PDF Reader and Editor Flaw Enables Privilege Escalation](https://firsthackersnews.com/foxit-pdf-reader-and-editor-flaw/): A new privilege escalation vulnerability (CVE-2024-29072, severity 8.2 High) has been discovered in multiple versions of Foxit PDF Reader for Windows. Foxit has fixed the issue and published a security advisory. - [New Embargo Ransomware Discovered, Potential ALPHV Rebirth](https://firsthackersnews.com/embargo-ransomware/): A new ransomware strain called Embargo, written in Rust, has surfaced with its Darknet infrastructure. Using double extortion tactics, it resembles the recently seized ALPHV group. The novice gang already claims four victims from different countries. - [TP-Link Archer C5400X Router Flaw Allows Remote Hacking](https://firsthackersnews.com/tp-link-archer/): Cybersecurity researchers at OneKey recently discovered a flaw in the TP-Link Archer C5400X router that allows attackers to hack devices remotely. - [Hackers Can Exploit Apple’s Wi-Fi Positioning System to Track Users Globally](https://firsthackersnews.com/apples-wi-fi/): A recent study by University of Maryland security researchers revealed a major privacy vulnerability in Apple’s Wi-Fi Positioning System (WPS). This flaw allows hackers to globally track Wi-Fi access points and their owners. The findings show that an unprivileged attacker can exploit Apple's crowdsourced location system to build a worldwide database of Wi-Fi access point locations and monitor device movements over time. - [PoC Exploit Out for Critical Git RCE Vulnerability](https://firsthackersnews.com/cve-2024-32002/): A critical vulnerability in Git, known as CVE-2024-32002, has recently emerged, posing substantial risks to users of this popular version control system. This vulnerability facilitates remote code execution (RCE) during repository cloning with submodules, and the release of proof-of-concept (PoC) exploits has heightened concerns within the cybersecurity community, as noted in a tweet by ThreatMon. - [GHOSTENGINE Malware Exploits Drivers to Terminate EDR Agents](https://firsthackersnews.com/ghostengine-malware/): Researchers discovered REF4578, an intrusion set that exploits vulnerable drivers to disable EDRs for crypto mining and deploys the GHOSTENGINE malware. - [Microsoft Reveals New Windows 11 Features for Enhanced Security](https://firsthackersnews.com/windows-11-features/): Microsoft is focusing on security in Windows, introducing Secured-Core PCs against hardware to cloud attacks and expanding passwordless options with passkeys for better identity protection. Passkeys are safeguarded by Windows Hello tech, and Microsoft's Secure Future Initiative (SFI) aims to ensure secure product and service delivery by adding new security features in Windows 11 and enabling more security features by default. - [Zabbix SQL Injection Vulnerability Leads to Remote Code Execution](https://firsthackersnews.com/zabbix-sql-vulnerability/): Zabbix, a widely used network monitoring tool in corporate IT infrastructure globally, is susceptible to SQL injection attacks. The vulnerability, identified as CVE-2024-22120, affects all versions from 6.0 onwards and can potentially lead to remote code execution. The researcher who discovered the flaw has already published a proof-of-concept exploit, suggesting that exploitation may occur imminently. - [Recent Linux Backdoor Targets Linux Users](https://firsthackersnews.com/linux-backdoor/): Recently, cybersecurity researchers at Symantec uncovered a fresh Linux backdoor actively targeting users through installation packages. - [Apple Safari Zero-Day Flaw Exploited at Pwn2Own: Urgent Patch Required](https://firsthackersnews.com/apple-safari-zero-day-flaw/): Apple has rolled out security updates to tackle a zero-day vulnerability in its Safari web browser, exploited during this year's Pwn2Own Vancouver hacking contest. - [Wireshark 4.2.5 Release: What’s New!](https://firsthackersnews.com/wireshark-4-2-5/): A key addition in Wireshark 4.2.5 is the support for the QUIC protocol. As the internet evolves, QUIC (Quick UDP Internet Connections) stands out as a promising transport layer protocol aimed at enhancing web application performance. - [Millions of IoT Devices Vulnerable to Attacks, Posing Risk of Full Takeover](https://firsthackersnews.com/iot-devices-vulnerability/): Researchers have uncovered four significant vulnerabilities in the ThroughTek Kalay Platform, utilized by 100 million IoT-enabled devices. ThroughTek Kalay's widespread influence underscores the need to safeguard homes, businesses, and integrators. Affected cameras include the Roku Indoor Camera SE, Wyze Cam v3, and Owlet Cam v1 and v2. - [New Google Chrome Zero-day Being Exploited in the Wild—Patch Immediately!](https://firsthackersnews.com/google-chrome-zero-day/): This vulnerability arises from an out-of-bounds write in V8, Google Chrome's JavaScript engine. Attackers can exploit this flaw to remotely execute arbitrary code on a victim’s machine, potentially resulting in unauthorized access or control over the affected system. - [Hackers Utilize Word Files to Distribute DanaBot Malware](https://firsthackersnews.com/danabot-malware/): Recent email campaigns distribute DanaBot malware through two document types: those exploiting equation editor and those with external links. Attackers send emails disguised as job applications with a malicious Word document attached. However, the document itself doesn't contain malware; it tricks the user into clicking an external link, initiating the DanaBot infection process. - [iTunes for Windows Vulnerability Enables Malicious Code Execution](https://firsthackersnews.com/itunes-windows-vulnerability/): iTunes has an arbitrary code execution vulnerability, potentially enabling attackers to execute malicious code. Apple has issued a security advisory to address this. The company stated it won't discuss or confirm security issues until investigations are complete and patches are available. - [Proof-of-Concept (PoC) Released for Critical PuTTY Private Key Recovery Vulnerability](https://firsthackersnews.com/proof-of-concept/): Security researchers have published a Proof-of-Concept (PoC) exploit for a critical vulnerability in the widely used PuTTY SSH and Telnet client. - [Microsoft Edge Zero-Day Exploit Detected in Live Attacks](https://firsthackersnews.com/microsoft-edge-zero-day/): A zero-day vulnerability in Microsoft Edge, identified as CVE-2024-4671, has been actively exploited by malicious organizations, as reported. This security flaw originates from the Chromium engine, which powers the browser. Chromium serves as the foundation for Google Chrome and various similar browsers as well. - [Critical Cacti Vulnerability Enables Remote Code Execution by Attackers](https://firsthackersnews.com/cacti-vulnerability-2/): Cacti, a widely used network monitoring tool, has released a critical security update addressing various vulnerabilities, notably CVE-2024-25641, rated with a high severity score of 9.1 on the CVSS scale, highlighting its significant potential impact on affected systems. - [New F5 Next-Gen Manager Vulnerability Enables Attackers to Obtain Full Admin Control](https://firsthackersnews.com/f5-next-gen-manager-vulnerability/): Two critical vulnerabilities in F5 Next-Gen Big IP have been uncovered, enabling threat actors to attain full administrative control of the device and establish accounts on any F5 assets. These attacker-created accounts remain invisible to the Next Central Manager, providing persistent access for various malicious activities. - [Dell Breached: Attackers Acquire Personal Information of 49 Million Customers](https://firsthackersnews.com/dell-breached-personal-information/): Dell Technologies recently disclosed a data breach involving a company portal containing limited customer information related to purchases, exposing names, physical addresses, and detailed order information such as service tags, item descriptions, order dates, and warranty details. - [CrushFTP vulnerability exploited in the wild to execute remote code](https://firsthackersnews.com/crushftp-vulnerability/): A critical vulnerability, CVE-2024-4040, has been actively exploited in the wild in CrushFTP. This flaw permits attackers to execute unauthenticated remote code on vulnerable servers. - [Cyber attackers use weaponized shortcut files to distribute CHM malware](https://firsthackersnews.com/chm-malware/): ASEC cybersecurity researchers recently unearthed hackers' active exploitation of weaponized shortcut files to disseminate CHM malware. - [MorLock Ransomware Targets Organizations, Stealing Business Data](https://firsthackersnews.com/morlock-ransomware/): The MorLock ransomware group has escalated its assaults on Russian businesses, resulting in disruptions and financial setbacks. Identified at the start of 2024, this group has already infiltrated nine medium to large Russian companies. - [XSS Vulnerability in Yoast SEO Plugin Endangers Over 5 Million WordPress Websites](https://firsthackersnews.com/xss-vulnerability-wordpress/): Security researcher Bassem Essam uncovered a critical cross-site scripting (XSS) vulnerability in the widely-used Yoast SEO WordPress plugin, potentially jeopardizing over 5 million websites. - [Trend Micro Antivirus One Allowed Malicious Code Injection by Attackers](https://firsthackersnews.com/trend-micro-antivirus/): A major update for Trend Micro's Antivirus One software has been launched. - [MITRE Exposes Chinese Hackers’ Employment of ROOTROT Webshell in Network Breach](https://firsthackersnews.com/mitre-exposes-chinese-hackers/): The MITRE Corporation, a non-profit organization managing research and development centers for the U.S. government, has revealed a recent infiltration by sophisticated nation-state hackers into one of its internal research and development networks. - [A novel Cuckoo malware strain is targeting macOS users](https://firsthackersnews.com/cuckoo-malware/): Cuckoo malware conducts a locale check to avoid infecting devices in specific regions: Armenia (hy_AM), Belarus (be_BY), Kazakhstan (kk_KZ), Russia (ru_RU), and Ukraine (uk_UA). If the check is successful, the malware proceeds with its malicious activities. It utilizes a fake application bundle to trick users into downloading and executing the malware. - [ShadowSyndicate hackers exploit Aiohttp vulnerability for sensitive data theft](https://firsthackersnews.com/aiohttp-vulnerability/): A directory traversal vulnerability (CVE-2024-23334) in aiohttp versions before 3.9.2 permits remote attackers to access sensitive files on the server by bypassing file reading validation within the root directory when 'follow_symlinks' is enabled. - [ArubaOS Critical Vulnerability Allows Remote Code Execution by Attackers](https://firsthackersnews.com/arubaos-critical-vulnerability/): Multiple vulnerabilities in ArubaOS affect HPE Aruba Networking devices, including Mobility Conductor, Mobility Controllers WLAN Gateways, and SD-WAN Gateways managed by Aruba Central. These vulnerabilities involve Unauthenticated Buffer Overflow (CVE-2024-26305, CVE-2024-26304, CVE-2024-33511, CVE-2024-33512, and CVE-2024-33518) and Unauthenticated Denial-of-Service (CVE-2024-33513, CVE-2024-33514, CVE-2024-33515, CVE-2024-33516, CVE-2024-33517, and CVE-2024-33518). - [‘Cuttlefish’ Zero-Click Malware Pilfers Private Cloud Data](https://firsthackersnews.com/cuttlefish-malware/): Cuttlefish is a recently discovered malware platform that has been active since at least July 2023. It specifically targets networking equipment such as enterprise-grade small office/home office routers. - [Gemini 1.5 Pro: Your Exclusive New AI Malware Analyst](https://firsthackersnews.com/gemini-1-5-pro/): Gemini 1.5 Pro represents the latest iteration of the Gemini AI malware analysis platform, poised to revolutionize the cybersecurity landscape. Boasting innovative features, it empowers security teams to detect, investigate, and respond to malware threats with unparalleled efficiency and accuracy. - [New Android Malware Mimics Social Media Apps to Steal Sensitive Data](https://firsthackersnews.com/android-malware/): A new RAT malware targeting Android devices has been discovered, capable of executing additional commands compared to other RAT malware. It can also conduct phishing attacks by masquerading as legitimate applications such as Snapchat, Instagram, WhatsApp, Twitter, and Google, to harvest credentials from victims. - [Darkgate Malware Utilizes Autohotkey to Track Teams](https://firsthackersnews.com/autohotkey/): This script would subsequently download and execute the AutoHotkey utility, alongside a malicious script, culminating in the execution of the DarkGate payload. - [LightSpy Malware Targets MacOS Devices](https://firsthackersnews.com/lightspy-malware-attack/): BlackBerry initially reported a new iOS LightSpy malware, but Huntress researchers discovered it as a macOS variant targeting Intel or Apple Silicon with Rosetta 2-enabled devices. - [New Android Trojan executes malicious commands on your phone](https://firsthackersnews.com/new-android-trojan-executes-malicious-commands-on-your-phone/): XLab researchers uncover "Wpeeper," a new Android malware infiltrating systems to execute various malicious commands, posing a serious threat to users. - [Grafana Tool Vulnerability Enables SQL Injection by Attackers](https://firsthackersnews.com/grafana-tool-vulnerability/): A severe SQL injection vulnerability has been discovered in Grafana, a popular open-source platform extensively used for monitoring and observability. This flaw enables attackers with valid user credentials to execute arbitrary SQL commands, posing risks such as data leakage and security breaches. - [PlugX USB Worm Infects Over 2.5 Million Devices](https://firsthackersnews.com/plugx-usb-worm/): A new threat has surfaced, impacting millions of devices globally. The PlugX USB worm, a sophisticated malware, has infected over 2.5 million devices, posing a significant cybersecurity threat worldwide. - [SSLoad Malware Combined with Tools Hijacks Entire Network Domain](https://firsthackersnews.com/ssload-malware/): The FROZEN#SHADOW attack campaign employs SSLoad malware alongside Cobalt Strike Implants to seize control of the entire network. Additionally, threat actors utilize Remote Monitoring and Management (RMM) software like ScreenConnect for enhanced control. - [Cactus Ransomware Exploits Vulnerability in Qlik Servers](https://firsthackersnews.com/qlik-sense-servers/): Since November 2023, the Cactus ransomware gang has been exploiting vulnerable Qlik Sense servers, leveraging multiple vulnerabilities including CVE-2023-41266 (Path Traversal), CVE-2023-41265 (HTTP Request Tunneling), and CVE-2023-48365 (Unauthenticated Remote Code Execution). - [Hackers exploit Autodesk Drive to host weaponized PDF files](https://firsthackersnews.com/autodesk-drive/): Autodesk Drive serves as a cloud-based data-sharing platform for organizations, facilitating document and file sharing. It accommodates various file formats, including 2D and 3D data files such as PDFs, accessible with a subscription to other Autodesk products. - [GuptiMiner Exploits eScan to Distribute Miners and Backdoors](https://firsthackersnews.com/guptiminer-exploits/): Avast researchers recently uncovered GuptiMiner, an aged malware. It leverages the eScan antivirus update system to surreptitiously implant backdoors and cryptocurrency mining software into users’ computers and extensive corporate networks. This discovery underscores cybercriminals' efforts to circumvent contemporary security protocols. Let’s delve deeper into this development. - [Urgent: GitLab Flaw Allows Account Takeover – Act Now](https://firsthackersnews.com/gitlab-flaw/): GitLab has issued security patches (16.11.1, 16.10.4, and 16.9.6) for both Community and Enterprise Editions, emphasizing the importance of upgrading to these versions to mitigate vulnerabilities. - [CrushFTP Zero-Day Enables Attackers to Gain Complete Server Access](https://firsthackersnews.com/crushftp-zero-day-enables-attackers-to-gain-complete-server-access/): CrushFTP disclosed a zero-day vulnerability (CVE-2024-4040) affecting versions below 10.7.1 and 11.1.0, allowing remote attackers with low privileges to bypass the VFS sandbox and read arbitrary files on the underlying filesystem. - [OpenMetadata Vulnerabilities to Target Kubernetes](https://firsthackersnews.com/openmetadata-vulnerability/): The OpenMetadata platform has critical vulnerabilities reported by Microsoft Security Blog, enabling attackers to exploit Kubernetes workloads for crypto mining. - [Critical Oracle VirtualBox vulnerability now has a PoC exploit released](https://firsthackersnews.com/poc-exploit/): Oracle VirtualBox had a critical vulnerability (CVE-2024-21111) allowing Privilege Escalation and Arbitrary File Move/Delete, rated 7.8 (High). Oracle promptly patched it and issued a security advisory. - [Watch Out for Weaponized Zip Files Distributing WINELOADER Malware](https://firsthackersnews.com/wineloader-malware/): Russian threat group APT29 targeted German political parties with a new backdoor, WINELOADER, via spear-phishing emails containing malicious links to ZIP files on compromised websites. - [PyPI Package Malware Targets Discord Users for Credential Theft](https://firsthackersnews.com/pypi-package-malware/): Hackers frequently exploit PyPI packages to inject malicious code into widely-used Python libraries, seeking vulnerabilities. - [Cerber Linux Ransomware Targets Atlassian Servers](https://firsthackersnews.com/cerber-linux-ransomware/): Cybercriminals frequently deploy Linux ransomware in server environments, targeting organizations with critical data for potentially higher payouts. Cado Security Labs' cybersecurity analysts recently examined the Linux version of Cerber ransomware, exploiting Confluence servers through CVE-2023-22518, following recent reports. - [Active Directory Security: 5 Critical Vulnerabilities to Monitor](https://firsthackersnews.com/active-directory/): Microsoft’s Active Directory (AD) acts as the backbone of your organization's network, regulating access to network and database sections to authorized users. - [Tor Browser 13.0: What’s New](https://firsthackersnews.com/tor-browser-13-0-14/): Tor Browser 13.0.14 is now available, featuring crucial security enhancements for the widely-used privacy-centric web browser. - [Surge in Zero-click Vulnerabilities: The Rise of ‘Mobile NotPetya’](https://firsthackersnews.com/mobile-notpetya/): The cybersecurity community warns of the rising threat of a "mobile NotPetya" event, a self-propagating mobile malware outbreak with potentially devastating consequences. - [Hackers Customize LockBit 3.0 Ransomware for Global Organization Attacks](https://firsthackersnews.com/lockbit-3-0-ransomware/): Hackers exploit LockBit 3.0 ransomware for its advanced encryption, successfully locking victims' files for ransom. Its stealthiness aids in unauthorized system access, enhancing deployment chances. - [Recent SharePoint Method Enables Hackers to Evade Security Measures](https://firsthackersnews.com/sharepoint-technique/): Two recently discovered SharePoint techniques empower malicious actors to circumvent conventional security measures and extract sensitive data covertly, evading detection mechanisms. - [LightSpy: Malware Threatening Android and iOS Users](https://firsthackersnews.com/lightspy-malware/): A recently discovered malware dubbed LightSpy has been found to target both Android and iOS users. - [Critical PAN-OS Command Injection Vulnerability Exploited](https://firsthackersnews.com/pan-os-command-injection/): Palo Alto Networks alerts customers to a critical command injection vulnerability in PAN-OS GlobalProtect feature, scoring the maximum 10/10 on CVSS. Fixes are underway, the company reports. - [Hackers deploy malware-driven scans to uncover vulnerabilities](https://firsthackersnews.com/malware-driven-scanning-attacks/): Hackers are employing malware-infected devices for scanning target networks rather than conducting direct scans. This strategy allows them to obscure their identity, circumvent geographical restrictions (geofencing), and expand their botnets. - [Critical vulnerabilities in LG TVs enable command execution](https://firsthackersnews.com/lg-tvs-vulnerability/): Users should promptly update their LG TVs to the latest firmware version and restrict external access to the device to mitigate potential security risks. - [Microsoft’s latest Patch Tuesday addresses 149 security vulnerabilities](https://firsthackersnews.com/microsoft-patch-3/): On April Patch Tuesday, Microsoft addressed 149 bugs, one of its largest security updates, spanning various products including Microsoft Office and SQL Server, with most vulnerabilities found in Windows and nine in Azure. - [XZ Utils Backdoor Uncovered, Poses Threat to Linux Servers](https://firsthackersnews.com/xz-backdoor/): Andres Freund discovered a backdoor in the liblzma library, part of the XZ data compression tool. The maintainer noticed a half-second delay in the updated version, leading to the flaw's discovery. The sophisticated supply chain attack appears to be the work of one of the new XZ maintainers. - [Attackers Utilize Obfuscation Tools for Multi-Stage Malware Delivery via Invoice Phishing](https://firsthackersnews.com/multi-stage-malware-delivery/): Cybersecurity researchers uncover a complex multi-stage attack employing invoice-themed phishing decoys to distribute various malware, including Venom RAT, Remcos RAT, XWorm, NanoCore RAT, and a crypto wallet stealer. - [Two Zero-Day Android Flaws Exploited in Google Pixel](https://firsthackersnews.com/zero-day-android-flaws/): Google has revealed the detection of two Android zero-day security vulnerabilities in its Pixel smartphones, with patches already available as per the recent Pixel Update Bulletin. Even more concerning, the flaw is already being exploited in targeted attacks. - [New E-Shopping Attack: Hijacking Users’ Banking Credentials](https://firsthackersnews.com/e-shopping-attack/): Since 2021, a fake e-shop scam campaign has targeted Southeast Asia, with increased activity observed by CRIL in September 2022, expanding from Malaysia to Vietnam and Myanmar. - [Critical OS Command Injection Vulnerability Discovered in Progress Flowmon](https://firsthackersnews.com/progress-flowmon/): Progress Flowmon is a network monitoring and security solution developed by Progress, a software company. It is designed to provide visibility into network traffic, detect anomalies, and enhance network security by identifying potential threats and vulnerabilities. Flowmon helps organizations monitor their network infrastructure, analyze traffic patterns, and respond to security incidents effectively. - [Hackers are exploiting YouTube channels to steal your data](https://firsthackersnews.com/hackers-exploiting-youtube/): Cybercriminals are exploiting YouTube, a platform adored by millions, to orchestrate advanced malware attacks. - [StrelaStealer targets users to steal logins from Outlook and Thunderbird](https://firsthackersnews.com/strelastealer/): A sophisticated variant of StrelaStealer malware, tailored for Spanish-speaking users, is targeting popular email clients Outlook and Thunderbird to pilfer email account credentials. - [Microsoft introduces 5 new AI tools to be integrated with Azure AI.](https://firsthackersnews.com/microsoft-new-azure-ai/): Microsoft has rolled out new tools in Azure AI Studio to aid generative AI app developers in addressing quality and safety concerns linked with AI. These tools are either currently accessible or will soon assist developers in crafting high-quality and secure AI applications. - [Patch immediately: Bitdefender Security Privilege Escalation Vulnerability](https://firsthackersnews.com/bitdefender-vulnerability/): Bitdefender has patched a vulnerability across its popular products like Internet Security, Antivirus Plus, Total Security, and Antivirus Free, addressing potential privilege escalation issues. This vulnerability could grant attackers system access, enabling data theft, root access, malware installation, and system interference. - [Microsoft SharePoint vulnerability detected. Update now!](https://firsthackersnews.com/microsoft-sharepoint-vulnerability/): In late March 2024, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) issued an alert concerning the exploitation of a flaw in Microsoft SharePoint. Although detected in September 2023, active exploitation has only recently come to light. Thankfully, Microsoft provides updates to address the vulnerability. - [iPhone users, beware! Darcula phishing service targeting iMessage](https://firsthackersnews.com/iphone-darcula-phishing-attack/): Recently, cybersecurity analysts at Netcraft uncovered threat actors actively exploiting the Dracula phishing service to target USPS and global postal services via iMessage. - [Wireshark 4.2.4 is now available: What’s New!](https://firsthackersnews.com/wireshark-4-2-4/): Wireshark continues to reign supreme, providing unmatched tools for troubleshooting, analysis, development, and education. - [Apple Silicon Unveils GoFetch Vulnerability](https://firsthackersnews.com/gofetch-attack/): Researchers have revealed a vulnerability in Apple Silicon processors called GoFetch, enabling attackers to extract secret keys from Mac computers during extensive cryptographic operations. Importantly, patching the flaw is virtually impossible as it originates from the processor's microarchitecture. - [Apple ID Push Bombing Attack: Targeting Apple Users to Steal Passwords](https://firsthackersnews.com/apple-id-bombing-attack/): Apple users are being targeted by a sophisticated phishing campaign aimed at seizing control of their Apple IDs through a method known as "push bombing" or "MFA fatigue" attack. - [Hackers deploy weaponized PDF files to distribute Mispadu banking malware](https://firsthackersnews.com/mispadu-banking-malware/): Originally focused on Latin America, the banking trojan Mispadu has broadened its scope to Europe, employing phishing emails and malicious URLs to pilfer credentials. The attackers leverage these stolen credentials to conduct subsequent phishing campaigns, rendering Mispadu a notable threat. - [Watch out for free Android VPN apps that transform your device into proxies](https://firsthackersnews.com/android-vpn-proxylib/): The Satori Threat Intelligence team at HUMAN, a cybersecurity company, has pinpointed a collection of VPN apps that enlist user devices into a proxy network using a Golang library named PROXYLIB. - [Threat actors employ Tycoon 2FA kits to pilfer your data through deceptive login pages](https://firsthackersnews.com/tycoon-2fa-attacks/): In October 2023, through proactive threat detection, Sekoia analysts uncovered a newly pervasive Adversary-in-The-Middle (AiTM) phishing kit named Tycoon 2FA. - [Attention Linux admins: Fake PuTTY client installing Rhadamanthys stealer detected!](https://firsthackersnews.com/linux-admin-rhadamanthys-stealer/): A malvertising campaign distributing a fake PuTTY client has been discovered, aiming to deploy the dangerous Rhadamanthys stealer malware. - [Patch Now: Exploits Targeting 2 Firefox Zero-Days Unveiled at Pwn2Own](https://firsthackersnews.com/firefox-zero-days/): Mozilla has swiftly responded to two zero-day vulnerabilities exploited during the recent Pwn2Own Vancouver 2024 hacking contest in the Firefox web browser. - [New Sysrv Botnet Abuses Google Subdomain to Spread XMRig Miner](https://firsthackersnews.com/sysrv-botnet/): First identified in 2020, the Sysrv botnet leverages a Golang worm to infect devices, deploying cryptominers through network vulnerability exploits. - [Over 170,000 GitHub accounts of Python developers hacked in supply chain attack.](https://firsthackersnews.com/supply-chain-attack/): Over 170,000 users have been affected by a sophisticated attack targeting the Python software supply chain. - [DHCP Exploited for Privilege Escalation in Windows Domains](https://firsthackersnews.com/dhcp-privilege-escalation/): Security researchers have discovered a sophisticated method, named "DHCP Coerce," that exploits the Dynamic Host Configuration Protocol (DHCP) administrators group to escalate privileges within Windows domains. - [New Acoustic Keyboard Side Channel Attack Allows Theft of Sensitive Data](https://firsthackersnews.com/acoustic-keyboard-side-channel-attack/): Cybersecurity researchers Alireza Taheritajar and Reza Rahaeimehr from Augusta University recently uncovered a novel acoustic keyboard side-channel attack enabling hackers to pilfer sensitive data. - [Microsoft announces a significant domain change for Teams](https://firsthackersnews.com/microsoft-domain-change-teams/): In April 2023, Microsoft announced a multi-year initiative to unify authenticated, user-facing Microsoft 365 apps and services under a single domain: cloud.microsoft. - [Androxgh0st exploits SMTP services to steal critical data](https://firsthackersnews.com/androxgh0st-exploits-smtp/): AndroxGh0st targets Laravel applications, scanning and extracting login credentials for AWS and Twilio from .env files. - [Operation PhantomBlu: Attackers Exploit Weaponized MS Office Doc to Breach Windows](https://firsthackersnews.com/operation-phantomblu/): Researchers at Perception Point have discovered a new malware campaign dubbed PhantomBlu, which targets US organizations. The campaign utilizes innovative methods to deploy the NetSupport RAT (Remote Access Trojan) by exploiting legitimate features of Microsoft Office document templates through OLE manipulation. - [Critical RCE Vulnerability in Fortra FileCatalyst](https://firsthackersnews.com/fortra-filecatalyst/): A PoC has been published for a critical RCE vulnerability found in Fortra's FileCatalyst software. - [Discontinued WordPress Plugin Vulnerability Puts Websites at Risk of Cyber Attacks](https://firsthackersnews.com/cve-2024-2172-wordpress-plugin/): A critical vulnerability was found in miniOrange's Malware Scanner and Web Application Firewall plugins, allowing unauthenticated attackers to gain admin access to WordPress sites. This highlights ongoing challenges for website administrators in securing their digital assets against cyber threats. - [Google Chrome will soon introduce real-time phishing protection features](https://firsthackersnews.com/google-chrome-phishing-protection/): Google has announced an upgrade to its Safe Browsing technology, enhancing Chrome users' protection against phishing, malware, and other malicious sites in real-time. - [A critical flaw in Zoom Clients allows attackers to escalate privileges](https://firsthackersnews.com/critical-flaw-zoom/): A vulnerability categorized as improper input validation was discovered in Zoom Clients for Windows, Zoom VDI Client for Windows, and Zoom Meeting SDK for Windows. This flaw could potentially enable an authenticated attacker to access sensitive information on the system via the network. - [GitHub Campaign Targets Users to Steal Login Credentials](https://firsthackersnews.com/github-campaign/): Threat actors frequently target GitHub users because of the abundance of valuable code repositories and sensitive information stored on the platform. However, GitHub's collaborative nature also makes it an exceptional target for surveillance by threat actors seeking to gather intelligence on organizations and their development practices. - [Hackers weaponize LNK files to deploy AutoIt malware](https://firsthackersnews.com/lnk-malware-infection/): Hackers are using weaponized LNK files to deploy AutoIt malware, causing concern in the cybersecurity community. - [Hackers deploy TMChecker RAT to target popular VPN and mail servers](https://firsthackersnews.com/tmchecker-rat/): TMChecker, recently uncovered by ReSecurity, is engineered to target remote-access services and prominent e-commerce applications, blending login checking capabilities with a brute-force attack toolkit. - [PixPirate, an Android banking malware](https://firsthackersnews.com/pixpirate-malware/): PixPirate, an Android banking malware, is pioneering stealth techniques to evade detection. IBM Trusteer researchers have unveiled its sophisticated methods, posing significant threats to financial institutions, especially in Brazil. - [Adobe Reader Infostealer Spreads Through Email in Brazil](https://firsthackersnews.com/infostealer-spreads-adobe-reader/): A recent email spam campaign is distributing infostealer malware disguised as an Adobe Reader Installer. The spam emails contain forged PDF documents prompting recipients to install Adobe Reader, which in turn triggers the downloading and installation of malware. This malicious activity primarily targets users in Portugal and Brazil, judging by the language used in the documents. - [The SSRF flaw in ChatGPT-Next-Web allowed attackers to gain unauthorized access.](https://firsthackersnews.com/chatgpt-next-web-ssrf-vulnerability/): In addition to ChatGPT and Gemini AI, two of the most popular publicly available Artificial Intelligence systems, there are numerous other standalone chatbot applications users can deploy and customize for personal use. - [BianLian Exploits TeamCity Vulnerability to Install Backdoors](https://firsthackersnews.com/bianlian-exploits-teamcity-vulnerabilities/): The cybercriminal group BianLian, recognized for their ransomware assaults, has garnered attention from the information security community. Exploiting vulnerabilities within the JetBrains TeamCity platform, they executed multistage cyberattacks. Their modus operandi begins with deploying a Golang-based backdoor, progressing through various stages until reaching the ransomware payload. - [Vulnerability in Over 150,000 Fortinet Devices Enables Remote Execution of Arbitrary Code by Hackers](https://firsthackersnews.com/cve-2024-21762/): A critical security flaw, identified as CVE-2024-21762, has been uncovered in Fortinet's FortiOS and FortiProxy secure web gateway systems, potentially affecting approximately 150,000 devices worldwide. - [Analysis and Description of Win32/Softcnapp Detection](https://firsthackersnews.com/puawin32-softcnapp/): PUA:Win32/Softcnapp is a generic detection name used by Microsoft Defender to identify unwanted programs. It can occasionally trigger false positive detections on legitimate applications, such as the desktop Viber client, NZXT Cam app, and others. However, is it truly hazardous? Let's delve into that question. - [CHAVECLOAK Malware Exploits Windows Through Weaponized PDF File](https://firsthackersnews.com/chavecloak-malware-exploits-windows/): CHAVECLOAK is a type of malware, specifically a banking trojan, known for targeting users, particularly in Brazil, with the intent of stealing sensitive financial information. - [Gitlab Authorization Bypass Vulnerability Enables Theft of Protected Variables](https://firsthackersnews.com/gitlab-authorization-bypass-vulnerability/): GitLab has released updated versions for its Community Edition (CE) and Enterprise Edition (EE) platforms, addressing critical vulnerabilities that enable attackers to bypass authorization mechanisms and access protected variables. - [Web Server Compromised by Hackers for z0Miner Malware Deployment](https://firsthackersnews.com/z0miner-malware-deployment/): The malicious actor, known as "z0miner," has been discovered targeting Korean WebLogic servers to disseminate various forms of malware, including miners, network utilities, and scripts for launching additional attacks. This threat actor has a track record of exploiting vulnerable servers, including those running Atlassian Confluence, Apache ActiveMQ, Log4j, and numerous others. - [Cybercriminals Exploiting iOS 0-day Vulnerability to Target iPhones – Update Immediately!](https://firsthackersnews.com/ios-0-day/): Two zero-day vulnerabilities have been uncovered in iOS and iPadOS 17.4 versions, enabling threat actors to circumvent memory protections and execute arbitrary kernel read and write operations on affected devices. - [WogRAT Malware Leverages Notepad Service to Target Windows & Linux Systems](https://firsthackersnews.com/wograt-malware-leverages-notepad-service-to-target-windows-linux-systems/): WogRAT malware, named after the "WingOfGod" string used by its creators, is a type of backdoor trojan that poses a serious threat to both Windows and Linux systems. It spreads through online notepad services like aNotepad and is designed to exploit system vulnerabilities, allowing unauthorized access and the execution of malicious code. WogRAT is capable of infecting systems in both PE (Portable Executable) format for Windows and ELF (Executable and Linkable Format) format for Linux, making it a versatile and dangerous malware variant. - [TeamCity On-Premises Vulnerabilities Pose Risks to Supply Chains](https://firsthackersnews.com/teamcity-on-premises-vulnerabilities/): Two fresh security vulnerabilities have surfaced in JetBrains TeamCity On-Premises, a prevalent CI/CD solution. Designated as CVE-2024-27198 and CVE-2024-27199, these vulnerabilities were first reported to JetBrains in February 2024 and have now been disclosed publicly. - [Cybercriminals Employing Innovative DNS Hijacking Technique for Investment Scams](https://firsthackersnews.com/dns-hijacking-technique/): A recently identified DNS threat actor known as Savvy Seahorse is employing advanced tactics to lure victims into fraudulent investment platforms and pilfer their funds. - [SMS Bombing: The Risks and Dangers of Text Message Attacks](https://firsthackersnews.com/sms-bombing/): In the realm of cybersecurity, SMS Bomber attacks are emerging as a modern threat with significant and concerning consequences. Many of us have experienced receiving SMS or calls from unknown numbers on our phones, often from businesses, sales companies, or illegal betting sites that obtain SMS permission from their customers. - [Beware: Business Email Compromise (BEC) Attacks Threaten Organizations](https://firsthackersnews.com/business-email-compromise/): Business Email Compromise (BEC) is a type of cybercrime where attackers gain unauthorized access to a business email account and then use it to deceive employees, customers, or partners into taking actions that benefit the attacker. This typically involves tricking individuals into transferring funds, providing sensitive information, or performing other actions that can result in financial loss or data compromise. - [New Bifrost malware for Linux mimics VMware domain for evasion](https://firsthackersnews.com/bifrost-malware/): A new Linux variant of Bifrost, called Bifrose, was detected employing a clever evasion tactic by utilizing a deceptive domain resembling the official VMware domain to avoid detection. - [Emerging Phishing Kit Exploits SMS and Voice Calls to Target Cryptocurrency Users](https://firsthackersnews.com/phishing-kits/): A newly discovered phishing kit has been observed impersonating the login pages of prominent cryptocurrency services as part of an attack cluster aimed primarily at mobile devices. - [Hackers Exploit SVG Image Files for GUloader Malware Distribution](https://firsthackersnews.com/guloader-malware-distribution/): Cybercriminals are leveraging the flexibility of SVG (Scalable Vector Graphics) files for the dissemination of the GUloader malware. - [Cybercriminals Exploit Weaponized ZIP Files to Acquire NTLM Hashes](https://firsthackersnews.com/exploit-weaponized-zip-files/): Cyber adversaries utilize ZIP files as a means to weaponize them, leveraging the ease of concealing malicious payloads within compressed archives. This tactic poses a challenge for security systems, as detecting and analyzing the contents of such files becomes increasingly complex. - [Malicious npm Packages: North Korean Hackers Targeting Developers](https://firsthackersnews.com/malicious-npm-packages-3/): Recent discoveries by Phylum indicate that a series of counterfeit npm packages identified on the Node.js repository are associated with state-sponsored actors from North Korea. - [SSH-Snake Malware: Stealing SSH Keys to Expand Network Spread](https://firsthackersnews.com/ssh-snake-malware/): It actively seeks out credentials and shell history to target its next victims, with threat actors presently leveraging the SSH-Snake malware. - [LiteSpeed Plugin Vulnerability Exposes 5 Million WordPress Sites to Risk](https://firsthackersnews.com/litespeed-vulnerability/): Researchers at Patchstack have issued a warning regarding an unauthenticated site-wide stored XSS vulnerability, identified as CVE-2023-40000, affecting the LiteSpeed Cache plugin for WordPress. - [Xeno RAT Exploits Windows DLL Search to Evade Detection](https://firsthackersnews.com/xeno-rat-exploits-windowsdll/): A newly identified, sophisticated malware coded in C# has emerged. Dubbed Xeno RAT, this malware boasts advanced features such as evasion tactics, payload generation, and an additional layer of threat due to its open-source availability on GitHub. - [Compromised PyPI Package Deploys NovaSentinel Stealer on Windows](https://firsthackersnews.com/compromised-pypi-package/): NovaSentinel, initially documented by Sekoia in November 2023, has been disseminated via counterfeit Electron applications on websites providing video game downloads. This recent compromise of a PyPI package signifies an endeavor at a supply chain attack, exploiting the trust inherent within the developer community to propagate malware. - [LockBit Returns, Unveiling Fresh Claims and Victims](https://firsthackersnews.com/lockbit-is-back/): The narrative surrounding the takedown of the LockBit ransomware on February 19 is still evolving. Following nearly a week of silence and downtime, the notorious gang has resurfaced on a new Onion domain, showcasing fresh breaches. Adding to the intrigue, LockBitSupp, a notorious figure, has issued a detailed statement addressing the events and future plans. - [Microsoft Initiates Wi-Fi 7 Testing in Windows 11](https://firsthackersnews.com/wi-fi-7-testing-windows-11/): Microsoft has commenced testing Wi-Fi 7 compatibility within the Windows 11 Insider Preview Build 26063. Initially available only in the Canary Channel, a potential expansion to Dev Channel users could transpire in the coming weeks. - [Analysts Expose Apple’s Latest Zero-Click Shortcuts Vulnerability](https://firsthackersnews.com/apple-shortcut-vulnerability/): Information has surfaced regarding a recently patched high-severity security vulnerability in Apple's Shortcuts app, allowing a shortcut to access sensitive device information without user consent. - [Multiple Cross-Site Scripting (XSS) Flaws in Joomla Could Result in Remote Code Execution](https://firsthackersnews.com/xss-flaws-joomla/): Five vulnerabilities have been discovered within the Joomla content management system that could be exploited to execute arbitrary code on vulnerable websites. - [MrB Ransomware (.mrB Files) – Analysis & File Recovery](https://firsthackersnews.com/mrb-ransomware/): MrB ransomware, a variant of Dharma ransomware, was identified on February 21, 2024. It encrypts files with the extension ".mrB" and targets small businesses, demanding ransom solely for file decryption without engaging in double extortion tactics. Jakub Kroustek was the initial discoverer and reporter of this ransomware strain. - [New Wi-Fi Authentication Bypass Vulnerabilities Pose Threat to Home and Enterprise Networks](https://firsthackersnews.com/wi-fi-authentication-vulnerability/): Two recently discovered Wi-Fi authentication bypass vulnerabilities in open-source software could potentially expose numerous enterprise and home networks to attacks. - [Critical Vulnerabilities in ConnectWise ScreenConnect, PostgreSQL JDBC, and VMware EAP](https://firsthackersnews.com/critical-vulnerabilities-in-connectwise/): ConnectWise has remedied a critical vulnerability rated CVSS 10 in its ScreenConnect product, a desktop and mobile support software that offers fast and secure remote access solutions. - [Migo Malware: Targeting Redis Servers for Cryptocurrency Mining](https://firsthackersnews.com/migo-malware/): Migo Malware is a type of malicious software that targets Redis servers for initial access, primarily aiming to mine cryptocurrency on compromised Linux hosts. It is a novel malware campaign observed in cybersecurity research, indicating a new threat actor or malware variant in the cyber landscape. - [Mastodon Security Flaw Enables Account Takeover](https://firsthackersnews.com/mastodon-account-vulnerability/): Cybersecurity experts have uncovered a critical vulnerability in the decentralized social network Mastodon, potentially enabling unauthorized access and account takeover. Fortunately, a fix is already available for this flaw. - [Meta Warns of 8 Spyware Companies Targeting iOS, Android, and Windows Devices](https://firsthackersnews.com/meta-warns-8-spyware-firms/): Meta Platforms announced it has taken measures to combat malicious activities originating from eight firms in Italy, Spain, and the United Arab Emirates (UAE) engaged in the surveillance-for-hire industry. - [SYSDF Ransomware: Analysis, .SYSDF File Recovery, and Removal Guide](https://firsthackersnews.com/sysdf-ransomware/): SYSDF ransomware is another variant of the Dharma ransomware family, which has been active since 2016. Initially identified on February 16, it adds a unique ".SYSDF" extension to encrypted files, along with a complex mask containing attack details such as victim ID and contact email for the hackers. After encryption, affected files exhibit the following pattern: - [Ov3r_Stealer: Targeting Cryptocurrency and Credentials via Facebook Job Ads](https://firsthackersnews.com/ov3r_stealer-abuses-facebook-job-ads/): "A recent report by Trustwave SpiderLabs reveals the emergence of Ov3r_Stealer, a Windows malware propagated through deceptive Facebook job advertisements. This malware is engineered to pilfer sensitive data and cryptocurrency wallets from its victims. Let's explore the workings of these fraudulent ads and the Ov3r_Stealer malware." - [Malicious ‘SNS Sender’ Script Exploits AWS for Mass Smishing Campaigns](https://firsthackersnews.com/sns-sender-script-exploits/): A malicious Python script named SNS Sender is being promoted as a tool for threat actors to distribute bulk smishing messages by exploiting Amazon Web Services (AWS) Simple Notification Service (SNS). - [Shim Bootloader Vulnerability Detected in Linux Systems](https://firsthackersnews.com/shim-bootloader/): Security researchers have uncovered a critical vulnerability in Shim, a commonly used Linux bootloader. This flaw has the potential to enable attackers to execute malicious code and take control of target systems even before the kernel is loaded. Given its ability to bypass standard security measures typically enforced by the kernel and operating system, this vulnerability poses significant concerns. - [Zoom patched seven vulnerabilities across Windows, iOS, and Android, including one critical flaw (CVE-2024-24691)](https://firsthackersnews.com/zoom-vulnerability-cve-2024-24691/): Zoom, the well-known video conferencing platform, recently patched 7 security vulnerabilities in a recent update. These vulnerabilities range in severity from medium to critical, and they affect a variety of systems: Windows, iOS, and Android. The critical vulnerability (CVE-2024-24691) addressed in this update could potentially allow attackers to execute arbitrary code on vulnerable systems, highlighting the importance of promptly applying security patches. - [Beware of Malicious Fake ChatGPT Apps](https://firsthackersnews.com/fakechatgpt-sites/): The public release of ChatGPT caused a sensation back in 2022, and it's fair to say it's been a game-changer. However, scammers often target platforms with large user bases. Fake ChatGPT services have started appearing, and this trend continues today. So, what exactly is the ChatGPT virus, and how dangerous are these scams? Let's delve into some of the most prominent examples. - [HijackLoader Malware Introduces Fresh Evasion Techniques](https://firsthackersnews.com/hijackloader-malware/): The HijackLoader malware has incorporated additional defense evasion tactics. Increasingly, other threat actors are leveraging this malware for delivering payloads and tooling. The developer employed a standard process hollowing technique alongside a trigger to enhance the stealthiness of defense evasion. - [New Fortinet VPN RCE Vulnerability Uncovered: Apply Patch Immediately](https://firsthackersnews.com/fortinet-vpn-rce-vulnerability/): Fortinet has issued a warning regarding a critical vulnerability found in its FortiOS SSL VPN system, which could be actively exploited by attackers. This vulnerability within Fortinet's network security solutions poses a significant threat to organizations, as it enables unauthenticated attackers to obtain remote code execution (RCE) capabilities through maliciously crafted requests. - [GitLab Security Flaw (CVE-2024-0402) Raises Concerns of File Overwrite Risk](https://firsthackersnews.com/gitlab-security-flaw/): In a recent security update, GitLab has released a patch addressing a critical vulnerability that could permit unauthorized users to overwrite files. This poses a risk of data corruption or the execution of arbitrary code. The vulnerability affects GitLab CE/EE across multiple versions. - [A critical vulnerability in Apple iOS and macOS has been discovered and exploited](https://firsthackersnews.com/critical-apple-vulnerability/): The Cybersecurity and Infrastructure Security Agency has identified a security flaw in Apple operating systems, specifically iOS and macOS, and has included it in the agency’s Known Exploited Vulnerabilities catalog. This vulnerability could enable attackers to circumvent Pointer Authentication, leading to unauthorized read and write access to the system. - [Kasseika Ransomware Exploits Vulnerable Antivirus Drivers](https://firsthackersnews.com/kasseika-ransomware/): A recently discovered ransomware, named "Kasseika," employs Bring Your Own Vulnerable Driver tactics to incapacitate antivirus software prior to encrypting files. It is suspected that Kasseika may have been developed by former members of the BlackMatter group or experienced ransomware actors who acquired its code. - [Discovery of Authentication Bypass Vulnerability in GoAnywhere MFT](https://firsthackersnews.com/goanywhere-mft-vulnerability/): Fortra has revealed a critical vulnerability in its GoAnywhere MFT (Managed File Transfer) software—an authentication bypass that poses a significant security risk. Exploiting this vulnerability successfully could enable attackers to create a new admin user, potentially opening the door for further malicious actions. - [Apple resolves the first zero-day bug exploited in attacks this year](https://firsthackersnews.com/apple-zero-day-2/): Apple has issued security updates to tackle the first zero-day vulnerability of the year, which has been exploited in attacks and could affect iPhones, Macs, and Apple TVs. - [GitHub Developer SSH Keys Targeted Through Malicious npm Packages](https://firsthackersnews.com/github-developer/): Security researchers recently discovered two new malicious packages on the npm open source package manager. These packages utilized GitHub to store stolen Base64-encrypted SSH keys taken from developer systems. - [Active Exploitation of 2 Citrix Remote Code Execution (RCE) Vulnerabilities, CISA Issues Notification](https://firsthackersnews.com/active-exploitation-of-2-citrix/): CISA has set a deadline of one to three weeks for addressing three vulnerabilities associated with Citrix NetScaler and Google Chrome. These zero-day vulnerabilities have been actively exploited in cyber attacks. - [New Godzilla Web Shell Attacks Exploit Apache ActiveMQ Flaw](https://firsthackersnews.com/godzilla-web-shell-attacks/): Cybersecurity researchers caution about a significant rise in threat actor activity exploiting a recently patched flaw in Apache ActiveMQ. This exploitation aims to deliver the Godzilla web shell on compromised hosts. - [LockBit Ransomware Uses Resume Word Files to Spread](https://firsthackersnews.com/lockbit-ransomware-2/): An ASEC investigation has uncovered the latest tactics employed by the notorious LockBit ransomware. Under the guise of "post-paid pentesters," the ransomware now adopts the strategy of appearing as harmless summaries within Word documents. Interestingly, this tactic echoes its historical modus operandi. This shrewd approach enables the ransomware to discreetly infiltrate systems without detection. - [Latest Docker Malware: CPU Theft for Crypto and Fake Website Traffic Generation](https://firsthackersnews.com/docker-malware/): A recently launched campaign aimed at vulnerable Docker services installs both an XMRig miner and the 9hits viewer app on compromised hosts, enabling a dual monetization approach. - [Critical Vulnerability: 178,000 SonicWall Firewalls at Risk of DoS and RCE](https://firsthackersnews.com/sonicwall-firewalls/): The high number of vulnerable firewalls is concerning, especially considering SonicWall's extensive customer base of over 500,000 businesses in 215+ countries. The identified vulnerabilities in 178,000+ SonicWall firewalls can lead to severe consequences. - [Atlassian’s Confluence Data Center and Server Affected by Critical RCE Vulnerability](https://firsthackersnews.com/atlassian-vulnerability/): Atlassian recommends that its customers update their Confluence Data Center and Server to safeguard against the exploitation of a critical vulnerability that has the potential to lead to Remote Code Execution (RCE). - [AzorUlt Stealer Resurfaces, Employing Email Phishing Tactics](https://firsthackersnews.com/azorult-stealer/): Cybersecurity experts have rediscovered the eight-year-old Azorult malware, known for stealing information and harvesting sensitive data. The malware had been inactive since late 2021, prompting the question of whether this seasoned threat will adopt new tactics. - [New Google Chrome 0-day Vulnerability Exploited](https://firsthackersnews.com/new-google-chrome-0-day/): In the latest release notes, Google discloses a newly discovered 0-day vulnerability already being exploited in the wild. Although the update addresses the issue, the fact that it is actively exploited underscores the urgency of its implementation. This marks the first 0-day exploit reported in the Chrome browser for the year 2024. - [Can Patches Prevent Zero-Day Attacks?](https://firsthackersnews.com/zero-day-attack/): In recent years, zero-day exploits and attacks have emerged as prominent threats. Leveraging unknown vulnerabilities within software, these attacks are nearly impossible to detect and prevent. Zero-day attacks can result in severe consequences, enabling attackers to gain control of systems, pilfer data, or install malware. - [GitLab Zero-Click Account Hijack Vulnerability Revealed](https://firsthackersnews.com/gitlab-zero-click-vulnerability/): On January 11, 2024, GitLab issued an update containing a crucial security fix for a vulnerability. This flaw enables a user to send the account password reset form to an unverified email address, potentially granting unauthorized access to the repository. Nearly all versions in the 16.x series of their software package are vulnerable to this exploit. - [Windows SmartScreen Bypass Exploited by Information Stealer](https://firsthackersnews.com/windows-smartscreen-bypass/): The malicious campaign leverages the CVE-2023-36025 vulnerability in Microsoft Windows Defender SmartScreen to propagate Phemedrone Stealer. Employing sophisticated evasion techniques, it evades conventional security measures to target sensitive user information. - [Researchers identify FBot hacking tool hijacking cloud and payment services.](https://firsthackersnews.com/fbot-hacking-tool-hijacking-cloud/): The tool, named FBot, possesses the capability for credential harvesting in spamming attacks, AWS account hijacking, and facilitates assaults against PayPal and various SaaS accounts. - [High Severity Vulnerability in Cisco Unity Connection Could Enable Root Privileges (CVE-2024-20272)](https://firsthackersnews.com/cisco-unity-connection-vulnerability/): Cisco has successfully addressed a high-severity security vulnerability in Unity Connection. This flaw had the potential to allow unauthenticated attackers to upload malicious files, execute arbitrary commands, and acquire root privileges on the affected devices. - [Volexity detects Chinese hackers exploiting zero-day vulnerabilities in Ivanti VPN.](https://firsthackersnews.com/zero-day-vulnerabilities-ivanti-vpn/): On Wednesday, cybersecurity researchers at Volexity issued a warning, revealing that suspected Chinese nation-state hackers are currently exploiting two unauthenticated remote zero-day vulnerabilities in Ivanti Connect Secure VPN devices. - [Water Curupira Hackers Spreading PikaBot Loader Malware](https://firsthackersnews.com/pikabot-loader-malware/): In 2023, the threat actor known as Water Curupira has been actively disseminating the PikaBot loader malware through spam campaigns. - [Two Adobe ColdFusion Vulnerabilities Exploited in The Wild](https://firsthackersnews.com/coldfusion-vulnerabilities/): Two vulnerabilities in Adobe ColdFusion have been targeted in real-world attacks, as cautioned by the Cybersecurity & Infrastructure Security Agency (CISA). These vulnerabilities stem from inadequate validation of deserialized data, leading to the potential for arbitrary code execution. Adobe addressed these issues by releasing patches in mid-July 2023, promptly after their initial detection. - [SMTP Smuggling Emerges as a Fresh Email Security Concern](https://firsthackersnews.com/smtp-smuggling/): An innovative SMTP Smuggling technique has been reported with the capability to circumvent current security protocols. Additionally, it empowers attackers to send forged emails that appear to originate from authentic addresses. This could inject renewed vitality into email spam, as its effectiveness has not waned over the recent period. - [Ivanti Released a Patch in Endpoint Manager Solution (EPM) for a Critical Vulnerability](https://firsthackersnews.com/ivanti-vulnerability/): Ivanti has resolved a critical vulnerability in its Endpoint Manager (EPM) solution, designated as CVE-2023-39336, carrying a severity score of 9.6/10. - [New ‘SpectralBlur’ macOS Backdoor Linked to North Korea](https://firsthackersnews.com/spectralblur-macos-backdoor/): Security researchers have delved into the intricacies of SpectralBlur, an emerging macOS backdoor believed to be associated with the recently discovered North Korean malware family known as KandyKorn. - [3 Malicious PyPI Packages Target Linux with Crypto Miners](https://firsthackersnews.com/malicious-pypi-packages/): Fortinet researchers identified three malicious packages in the PyPI repository—modularseven, driftme, and catme. These packages, attributed to the same author, "sastra," were specifically crafted to target Linux systems and install crypto mining software. Notably, the author created a PyPI account shortly before uploading these packages. - [CISA Issues Alert for Juniper Secure Analytics Vulnerabilities](https://firsthackersnews.com/juniper-secure-analytics-vulnerabilities/): In a recent alert, the Cybersecurity and Infrastructure Security Agency (CISA) highlighted that Juniper has issued security updates to resolve several vulnerabilities in the Juniper Secure Analytics Virtual Appliance. This Security Information and Event Management (SIEM) system compiles extensive event data in near real-time, designed specifically for virtualized IT and cloud environments. - [Google accounts may be susceptible to a new hack, and changing the password won’t provide a solution.](https://firsthackersnews.com/google-accounts/): A purportedly new method allows hackers to exploit the OAuth2 authorization protocol to compromise Google accounts. This enables them to maintain valid sessions by regenerating cookies, regardless of IP or password reset attempts. - [Microsoft Disables MSIX App Installer Protocol](https://firsthackersnews.com/msix-installer/): Microsoft has disabled the MSIX installer protocol in Windows in response to its exploitation in real-world cyberattacks. Hackers discovered a method to abuse the protocol, allowing them to install malicious software and bypass detection by anti-malware software. - [Misconfigurations in Google Kubernetes Engine (GKE) Lead to a Privilege Escalation Exploit Chain](https://firsthackersnews.com/google-kubernetes-engine-gke/): A recent Unit 42 investigation uncovered a dual privilege escalation chain affecting Google Kubernetes Engine (GKE). Stemming from misconfigurations in GKE's FluentBit logging agent and Anthos Service Mesh (ASM), this exploit chain could enable attackers with existing Kubernetes cluster access to escalate privileges. - [Xamalicious Trojan Hits Over 327K Android Devices](https://firsthackersnews.com/xamalicious-malware/): Researchers uncovered a novel Android backdoor named Xamalicious at the end of 2023. This malware demonstrates significant capabilities to carry out malicious actions on compromised devices, leveraging Android's accessibility permissions to access diverse sources of user data. - [Remote Encryption Attacks -Explanation & Mitigation](https://firsthackersnews.com/remote-encryption-attacks/): The digital landscape is witnessing a rise in sophisticated ransomware attacks, specifically remote encryption attacks. While the technology itself is not novel, it resembles a YouTube video uploaded a decade ago that is currently gaining recommendations. This article delves into the intricacies, evolution, and effective countermeasures against these attacks. - [Microsoft Word Documents Used as Lures to Distribute Nim-Based Malware](https://firsthackersnews.com/nim-based-malware/): Nim-based malware has traditionally been uncommon in the threat landscape, but this trend is gradually shifting. Attackers are increasingly either creating custom tools from scratch using the language or porting existing versions of their malicious programs to Nim. - [Cryptocurrency Scams on Twitter Exploit Post Features](https://firsthackersnews.com/cryptocurrency-scams/): Scammers exploit a feature of Twitter posts, deceiving users and putting digital assets at risk. This deceptive tactic relies on Twitter's URL structure, enabling hackers to entice individuals into various scams. Primarily, these campaigns are employed to promote various cryptocurrency scams. - [GOOGLE ADDRESSED A NEW ACTIVELY EXPLOITED CHROME ZERO-DAY](https://firsthackersnews.com/google-addresses-zero-day/): Google has issued emergency updates to address yet another Chrome zero-day vulnerability that has been actively exploited in the wild. This marks the eighth zero-day vulnerability patched since the beginning of the year. - [Microsoft Alerts of RCE and DoS Vulnerabilities in Perforce Server](https://firsthackersnews.com/rce-dos-vulnerabilities-perforce-server/): The Perforce Helix Core Server, commonly referred to as 'Perforce Server,' functions as a widely adopted source code management platform employed across various industries, including gaming, government, military, technology, and retail. - [Comcast’s Xfinity Breach Exposes Data of 35.8 Million Users](https://firsthackersnews.com/comcasts-xfinity-breach-exposes/): Comcast has officially acknowledged a significant security breach affecting its Xfinity division, with approximately 36 million customers of the world's largest telecom provider exposed due to the CitrixBleed exploitation. - [Kinsta Alerts About Phishing Campaign on Google Ads](https://firsthackersnews.com/kinsta-alerts-phishing-campaign/): Kinsta, a leading WordPress hosting provider, has alerted its customers to a troubling cybersecurity development. - [Qbot malware resurfaces in a new campaign focusing on the hospitality sector.](https://firsthackersnews.com/qbot-malware-resurfaces/): QakBot malware has re-emerged in phishing campaigns, following a disruption of the botnet by law enforcement during the summer. - [FortiGuard Releases Security Updates for Critical Vulnerabilities](https://firsthackersnews.com/fortiguard-releases-security-updates/): FortiGuard unveiled security updates on December 12, 2023, to mitigate multiple critical vulnerabilities present in its FortiOS, FortiPAM, FortiMail, FortiNDR, FortiRecorder, FortiSwitch, and FortiVoice products. Exploiting these vulnerabilities could potentially grant cyber threat actors control over compromised systems. - [Google Will Block Third-Party Cookies for All Chrome Users by the Second Half of 2024](https://firsthackersnews.com/google-will-block-third-party-cookies/): On Thursday, Google declared its plans to initiate testing of a new feature named "Tracking Protection" from January 4, 2024. This testing phase will involve 1% of Chrome users and is part of Google's broader initiative to phase out third-party cookies in the web browser. - [116 Malicious Packages Detected in PyPI Repository, Targeting Windows and Linux Operating Systems](https://firsthackersnews.com/malicious-packages-pypi-repository/): Security experts have uncovered a collection of 116 malicious packages within the Python Package Index (PyPI) repository, specifically crafted to compromise Windows and Linux systems through a tailored backdoor. - [Enhancing Android Security: Google Implements Clang Sanitizers to Safeguard Against Cellular Baseband Vulnerabilities](https://firsthackersnews.com/clang-sanitizers/): Google Emphasizes Clang Sanitizers in Strengthening Android's Cellular Baseband Security and Mitigating Vulnerabilities - [APPLE RELEASED IOS 17.2 TO ADDRESS A DOZEN OF SECURITY FLAWS](https://firsthackersnews.com/apple-released-ios-17-2/): Apple has also rolled out Safari 17.2, featuring resolutions for two WebKit vulnerabilities—CVE-2023-42890 and CVE-2023-42883—capable of triggering arbitrary code execution and a denial-of-service (DoS) situation. This update is accessible for Macs running macOS Monterey and macOS Ventura. - [21 Security Flaws Found to Affect Over 86,000 Sierra AirLink Routers](https://firsthackersnews.com/sierra-airlink-routers/): Users of Sierra AirLink routers face potential threats, including remote code execution, unauthorized access, cross-site scripting, authentication bypass, and denial-of-service attacks. - [Microsoft Issues Warning on COLDRIVER: Ongoing Evolution in Evasion and Credential Theft Strategies](https://firsthackersnews.com/microsoft-issues-warning-coldriver/): COLDRIVER, the threat actor, persists in carrying out credential theft operations targeting entities strategically significant to Russia, concurrently enhancing its capabilities to evade detection. - [Atlassian Deploys Crucial Software Updates to Mitigate Remote Code Execution Vulnerabilities](https://firsthackersnews.com/atlassian-deploys-crucial-software-updates/): Atlassian has issued software patches to rectify four critical vulnerabilities in its software. Successful exploitation of these flaws could lead to remote code execution. - [Apple Addresses Exploited Zero-Day Vulnerabilities with Emergency Security Update: CVE-2023-42916, CVE-2023-42917](https://firsthackersnews.com/apple-zero-day/): Apple responded to the active exploitation of two zero-day vulnerabilities in the wild by swiftly issuing emergency security updates. Identified as CVE-2023-42916 and CVE-2023-42917, these vulnerabilities specifically impact the WebKit browser engine across iPhone, iPad, and Mac devices. - [Qlik Sense Vulnerabilities Exploited in Ransomware Attacks](https://firsthackersnews.com/qlik-sense-vulnerabilities/): There's evidence of a CACTUS ransomware campaign exploiting recently revealed security vulnerabilities in Qlik Sense, a cloud analytics and business intelligence platform. This exploitation serves as a means to gain access to targeted environments. - [Google Introduces RETVec: Gmail’s Latest Safeguard Against Spam and Malicious Emails](https://firsthackersnews.com/google-introduces-retvec-gmails/): Google has unveiled RETVec (Resilient and Efficient Text Vectorizer), a new multilingual text vectorizer designed to enhance Gmail's capability in detecting potentially harmful content, including spam and malicious emails. - [Exploitation Attempts Observed for Critical ownCloud Vulnerability (CVE-2023-49103)](https://firsthackersnews.com/critical-owncloud-vulnerability/): The cybersecurity community has expressed concerns as they've detected exploitative activities focusing on ownCloud, leveraging the CVE-2023-49103 vulnerability. - [Ensuring Your Security During Black Friday and Cyber Monday 2023](https://firsthackersnews.com/black-friday-cyber-monday/): Annually, the holiday season kicks off with the significant retail shopping events in the U.S., Black Friday and Cyber Monday, occurring on the Friday and Monday following Thanksgiving. - [New Rust-based SysJoker backdoor linked to Hamas hackers](https://firsthackersnews.com/sysjoker-backdoor/): SysJoker, a multi-platform malware, has been identified in a novel iteration, showcasing a comprehensive code overhaul implemented in the Rust programming language. - [CISA Alert: Serious Vulnerabilities in Adobe ColdFusion (CVE-2023-44350, CVE-2023-44351, CVE-2023-44353 and More)](https://firsthackersnews.com/adobe-coldfusion/): An alert has been released by CISA regarding several vulnerabilities affecting Adobe ColdFusion. The alert emphasizes that the vulnerabilities, if exploited, may give threat actors control over the affected systems. This highlights the importance for organizations to implement measures to safeguard their systems. - [DarkGate and PikaBot Malware Resurrect QakBot’s Techniques in New Phishing Assaults](https://firsthackersnews.com/qakbots-techniques-phishing/): Phishing campaigns distributing malware families like DarkGate and PikaBot are employing tactics reminiscent of attacks associated with the now-defunct QakBot trojan. - [Six Steps to Safeguard Small Businesses Against Cyberattacks](https://firsthackersnews.com/steps-to-safegaurd-cyberattacks/): Successful management of cyber risks in small businesses centers on adherence to workplace regulations and the attainment of robust security measures. - [MySQL: Servers Targeted by DDoS-as-a-Service, Ddostf](https://firsthackersnews.com/mysql-servers-ddos/): Malicious cyber actors exploit MySQL servers through a botnet known as 'Ddostf,' utilizing it as a DDoS-as-a-Service platform available for lease by other cybercriminals. - [Zimbra Zero-Day Exploited to Hack Government Emails](https://firsthackersnews.com/zimbra-zero-day-exploited/): Four distinct groups exploited a zero-day vulnerability in the Zimbra Collaboration email software in real-world attacks, aiming to illicitly acquire email data, user credentials, and authentication tokens. - [Critical CVE-2023-34060 Vulnerability in VMware Cloud Director Appliance: CISA Advises Immediate Patching](https://firsthackersnews.com/critical-cve-2023-34060/): Designated as CVE-2023-34060, this vulnerability presents a substantial risk, boasting a CVSSv3 score of 9.8, signifying its critical severity. Dustin Hartle from Ideal Integrations Inc. initially reported this issue to VMware on November 14, 2023. - [Google Warns of Malicious Exploitation of Bard by Fraudster](https://firsthackersnews.com/google-warns-malicious-exploitation/): Google Files Lawsuit Against Fraudsters Exploiting Bard's Genetics Artificial Intelligence Hype to Deceptively Distribute Malware. - [OracleIV DDoS Botnet Malware Targets Docker Engine API Instances](https://firsthackersnews.com/oracleiv-ddos-malware/): With the OracleIV DDoS botnet malware, attackers commence access by initiating an HTTP POST request to the Docker API, targeting the /images/create endpoint. - [Microsoft warns LinkedIn users of fake skills assessment portals](https://firsthackersnews.com/microsoft-warns-linkedin-users/): Microsoft has linked the observed activity to a threat actor identified as Sapphire Sleet, noting it as a "change in the persistent actor's tactics." - [BiBi-Windows Wiper: Targets Windows in Pro-Hamas attacks](https://firsthackersnews.com/bibi-windows-wiper/): Cybersecurity researchers have issued a warning about a Windows variant of a malware called BiBi-Windows Wiper. This malware has been observed targeting Linux systems in cyber attacks specifically aimed at Israel. - [GootBot: New dangerous variant of GootLoader malware](https://firsthackersnews.com/gootloader-malware/): The latest iteration of GootLoader malware, known as GootBot, enables lateral movement within compromised systems while successfully evading detection. - [New Variant of BlueNoroff Malware Targets Mac Users](https://firsthackersnews.com/bluenoroff-malware/): "Researchers Discover BlueNoroff RustBucket Malware Variant Targeting MacOS" - A recent report from Jamf Threat Labs sheds light on the ongoing evolution of this attack and its potential targets. - [SecuriDropper: New DaaS service installs malware on Android](https://firsthackersnews.com/securidropper/): A recently emerged business offering a "Dropper-as-a-Service" (DaaS) known as "SecuriDropper" bypasses Android's "Restricted Settings" function to install malware on devices and gain access to Accessibility Services. - [Mozi malware botnet: Disabled by mysterious kill-switch](https://firsthackersnews.com/mozi-malware-botnet/): The Mozi malware operation came to a sudden halt in August when an unidentified individual delivered a payload on September 27, 2023, triggering a kill-switch that effectively disabled all the associated bots. - [Arid Viper target Android users with spyware](https://firsthackersnews.com/arid-viper-target-android/): The hacking group known as Arid Viper (also identified as APT-C-23, Desert Falcon, or TAG-63) is purportedly responsible for a distribution campaign involving Android spyware. This spyware specifically targets Arabic-speaking users by posing as a fake dating app, and it clandestinely gathers data from compromised devices. - [Malicious NuGet Packages Caught Distributing SeroXen RAT Malware](https://firsthackersnews.com/malicious-nuget-packages/): Cybersecurity experts have discovered a fresh batch of malicious packages distributed through the NuGet package manager, employing a less conventional technique for deploying malware. - [Lazarus hackers targeted a software vendor using known vulnerabilities](https://firsthackersnews.com/lazarus-hackers-2/): A recent cyber campaign attributed to the Lazarus hackers from North Korea appears to have focused on a specific vendor's software, which remains unidentified. It's reported that these hackers exploited known vulnerabilities in widely-used software to compromise the company's security. - [Critical Vulnerability in F5 BIG-IP Configuration Utility Allows Request Smuggling, Leads to RCE: CVE-2023-46747](https://firsthackersnews.com/f5-big-ip/): A critical vulnerability, known as CVE-2023-46747, has been uncovered in F5 BIG-IP products, allowing unauthenticated remote code execution. This vulnerability is rated at a high CVSS score of 9.8, prompting significant security apprehensions. - [Safari Vulnerability Exposes Apple iPhones and Macs Powered by A and M-Series CPUs to Security Risks](https://firsthackersnews.com/ileakage/): A team of researchers has developed an innovative side-channel attack called iLeakage, which takes advantage of a vulnerability in Apple's A- and M-series CPUs found in iOS, iPadOS, and macOS devices. This technique allows for the extraction of sensitive information from the Safari web browser. - [Backdoor planted on hacked Cisco IOS XE devices altered to evade detection](https://firsthackersnews.com/backdoor/): The backdoor infiltrated Cisco devices by exploiting two zero-day flaws in IOS XE software has been altered by the threat actor to evade detection through previous fingerprinting techniques. - [iOS Zero-Day Attacks: Experts Uncover Deeper Insights into Operation Triangulation](https://firsthackersnews.com/zero-day-triangledb/): The TriangleDB implant, designed for infiltrating Apple iOS devices, incorporates four distinct modules: one for capturing audio from the device's microphone, another for extracting data from the iCloud Keychain, a third for pilfering information from SQLite databases employed by multiple apps, and a fourth for approximating the location of the target. - [SolarWinds: Serious RCE vulnerabilities discovered](https://firsthackersnews.com/solarwinds-serious-rce-vulnerabilities/): Security researchers have uncovered three critical remote code execution (RCE) vulnerabilities within the SolarWinds Access Rights Manager (ARM) product. These vulnerabilities could potentially be exploited by remote attackers to run privileged code with SYSTEM-level access. - [Zero-Day Vulnerabilities in Citrix NetScaler and WinRAR Are Under Active Exploitation (CVE-2023-4966, CVE-2023-38831)](https://firsthackersnews.com/zero-day-vulnerabilities-in-citrix-netscaler-and-winrar/): In a recent report, researchers exposed ongoing exploitation of CVE-2023-4966 in Citrix's NetScaler ADC and Gateway appliances. Simultaneously, Google's TAG has identified government-affiliated hacking groups using CVE-2023-38831 to exploit WinRAR. These attackers have harnessed these vulnerabilities as zero-days, with the aim of commandeering NetScaler appliance sessions and deploying malicious code through WinRAR to compromise and infect targeted systems. - [SpyNote: Android spyware records your calls](https://firsthackersnews.com/spynote-android-spyware/): Security researchers conducted an analysis of the Android trojan called SpyNote, revealing numerous spyware capabilities associated with it. - [Fake browser updates are used to distribute malware](https://firsthackersnews.com/fake-browser-updates/): Numerous users lack the knowledge and training necessary to discern and evade the deceptive ploys of attackers, making them vulnerable targets for fake browser updates. - [User Submitted Posts: Vulnerability found in WordPress plugin](https://firsthackersnews.com/user-submitted-posts-vulnerability/): His team at Patch Stack recently uncovered a fresh vulnerability in the WordPress plugin "User Submitted Posts," affecting versions from 20230902 onwards. - [Microsoft: New bug bounty program for AI-powered Bing](https://firsthackersnews.com/microsoft-new-bug-bounty/): Microsoft has unveiled a fresh bug bounty program that centers around enhancing the AI-powered Bing experience, offering researchers compensation of up to $15,000. - [‘Rapid Reset’ DDoS Attacks Rise: October 2023 Patch Tuesday Has Arrived (CVE-2023-36563, CVE-2023-41763, CVE-2023-44487)](https://firsthackersnews.com/rapid-reset/): In October 2023, Microsoft unveiled its latest Patch Tuesday, addressing a comprehensive 103 security vulnerabilities. Within this count, 12 have received a critical rating, while three zero-day vulnerabilities are currently under active exploitation. Notably, one of these zero-day vulnerabilities is linked to the emergence of Rapid Reset DDoS attacks, further highlighting their growing significance. - [Google Expands Bug Bounty Program With Chrome, Cloud CTF Events](https://firsthackersnews.com/google-chrome/): Google's research team introduced the v8CTF, a capture-the-flag (CTF) challenge centered around the V8 JavaScript engine used in the Chrome browser. This initiative can be considered an extension of the company's exploit reward programs. - [Formbook is a highly prevalent malware strain](https://firsthackersnews.com/formbook-malware/): This incident led to the proliferation of the Remcos Remote Access Trojan (RAT) malware and marked the ascent of Formbook as a dominant malware strain, following the decline of Qbot. - [The importance of email marketing for businesses](https://firsthackersnews.com/email-marketing/): In the contemporary era dominated by technology and social media, email marketing continues to stand out as a highly effective promotional technique for businesses. Despite the growing prominence of social media, email marketing continues to provide substantial opportunities for businesses. - [Exploits released for Linux flaw giving root on major distros](https://firsthackersnews.com/linux-flaw/): Online, proof-of-concept exploits have emerged for a critical vulnerability in GNU C Library's dynamic loader, granting local attackers root privileges on prominent Linux distributions. - [Cisco Releases Urgent Patch to Fix Critical Flaw in Emergency Responder Systems](https://firsthackersnews.com/cisco-critical-flaw/): Cisco has issued updates to rectify a critical security vulnerability affecting Emergency Responder, which permits unauthorized remote attackers to access vulnerable systems through the use of hardcoded credentials. - [Increased number of victims reported to “leak sites” of ransomware gangs](https://firsthackersnews.com/ransomware-attacks/): According to the "2023 State of the Threat" report by Her Secureworks, the number of victims reported on ransomware leak sites by criminal gangs reached exceptionally high levels from March to June 2023. - [EvilProxy: Phishing Microsoft 365 via indeed.com open redirect](https://firsthackersnews.com/evilproxy-phishing-2/): A recent phishing campaign dubbed "EvilProxy" has come to light, with its sights set on the Microsoft 365 accounts of top-level executives within US-based organizations. This campaign takes advantage of open redirects on the job listings website Indeed.com. - [Lazarus hackers breach aerospace company with new LightlessCan malware](https://firsthackersnews.com/lazarus-attack-chain/): The Lazarus hacking group, associated with North Korea, launched a cyberattack on a Spanish aerospace company by enticing its employees with bogus job offers, eventually infiltrating the corporate network through an undisclosed backdoor dubbed 'LightlessCan'. - [Cisco: Prompts administrators to patch an IOS zero-day](https://firsthackersnews.com/cisco-prompts-administrators-to-patch/): On Wednesday, Cisco issued a warning to its customers, urging them to address a zero-day vulnerability in IOS and IOS XE systems, which can be exploited by malicious users. - [Zanubis: The Android banking trojan gets even more dangerous](https://firsthackersnews.com/zanubis-android-banking-trojan/): The Android banking Trojan Zanubis has adopted a new disguise, posing as the official application of the Peruvian government organization SUNAT (Superintendencia Nacional de Aduanas y de Administración Tributaria), thereby tricking unsuspecting users. - [Hackers are actively exploiting an Openfire flaw](https://firsthackersnews.com/openfire-flaw/): Malicious actors are actively taking advantage of a critical vulnerability in Openfire messaging servers, using it to encrypt server data with ransomware and deploy cryptocurrency miners. - [Researchers uncover a thriving underground economy for malware targeting IoT devices](https://firsthackersnews.com/malware-targets-iot-devices/): Researchers have exposed a robust clandestine ecosystem focused on crafting malware for IoT device exploitation. - [ZenRAT Malware Uncovered in Bitwarden Impersonation](https://firsthackersnews.com/zenrat-malware/): A recently discovered malware variant named ZenRAT has surfaced, camouflaged within fraudulent Bitwarden installation bundles. - [Xenomorph Android malware: Targets users of banks and crypto wallets in the US](https://firsthackersnews.com/xenomorph-android-malware/): In the latest campaign that commenced in August 2023, the operators of the Xenomorph Android malware opted to employ phishing pages. They enticed visitors to update their Chrome browser on mobile devices, with the goal of tricking them into downloading the malicious APK. - [Stealth Falcon hackers are using the new Deadglyph malware](https://firsthackersnews.com/deadglyph-malware/): The Deadglyph malware deployed by the Stealth Falcon hackers is highly modular, enabling it to fetch new modules from the C2 server. These modules contain diverse shellcodes designed to be executed by the Executor component. - [The Rise of Mobile Malware](https://firsthackersnews.com/mobile-malware/): Mobile malware, as its name implies, is specialized malicious software crafted specifically to infiltrate mobile devices such as smartphones and tablets, with the intent of compromising sensitive user data. - [Fake WinRAR proof-of-concept exploit drops VenomRAT malware](https://firsthackersnews.com/venomrat-malware/): An imitation proof-of-concept (PoC) exploit targeting a WinRAR RCE vulnerability that was recently patched has been discovered on GitHub, with the intention of spreading the VenomRAT malware to unsuspecting users. - [Mastodon Vulnerabilities and Critical Zero-Day in TrendMicro’s Apex One Addressed: CVE-2023-41179, CVE-2023-42451, CVE-2023-42452](https://firsthackersnews.com/mastodon-vulnerabilities-and-critical-zero-day/): Mastodon has taken action to resolve two vulnerabilities, specifically CVE-2023-42451 and CVE-2023-42452. Additionally, a zero-day vulnerability, denoted as CVE-2023-41179, has been swiftly addressed in TrendMicro’s Endpoint Security product, Apex One. - [Nest devices can now only join one speaker group at a time](https://firsthackersnews.com/nest-devices/): Google has confirmed that due to a recent court ruling, it is currently not possible to simultaneously use your Nest devices in multiple rooms. - [Within the Code of a Fresh XWorm Variant](https://firsthackersnews.com/xworm/): XWorm is a recent addition to the remote access trojan family, quickly establishing itself as one of the most enduring global threats. - [The new Android banking trojan is based on ERMAC](https://firsthackersnews.com/hook-new-android-banking-trojan/): A recent analysis of the Android banking trojan Hook has uncovered its foundation in its predecessor, ERMAC. - [Uncommon AWS Services Targeted by New AMBERSQUID Cryptojacking Operation](https://firsthackersnews.com/ambersquid-cryptojacking/): The cloud and container security firm Sysdig has codenamed this malicious cyber activity as AMBERSQUID. - [LockBit Attack Fails, 3AM Ransomware Steps In as Plan B](https://firsthackersnews.com/3am-ransomware/): Researchers found that the 3AM ransomware only encrypts specific files and adds ".threeamtime" to their names, while also attempting to delete Volume Shadow (VSS) copies. - [Free Download Manager site has been redirecting Linux users to malware for years ChatGPT](https://firsthackersnews.com/free-download-manager/): The Free Download Manager website has been consistently redirecting Linux users to malware-infected destinations over an extended period! An incident report highlights an attack on the Free Download Manager supply chain, which led Linux users to a deceptive Debian package repository, ultimately installing information-stealing malware. - [Notepad++ 8.5.7 addresses critical security vulnerabilities](https://firsthackersnews.com/notepad-8-5-7-vulnerabilities/): "The latest release, Notepad++ version 8.5.7, includes security updates to address several buffer overflow vulnerabilities identified in the previous version." - [A Modular Malware Loader, HijackLoader, Gaining Prominence in the World of Cybercrime](https://firsthackersnews.com/hijackloader/): "HijackLoader, a recently emerged malware loader, is rapidly gaining popularity within the cybercriminal community for distributing a range of payloads, which include DanaBot, SystemBC, and RedLine Stealer." - [How to make sure you don’t lose important emails in Gmail](https://firsthackersnews.com/dont-lose-important-emails-ingmail/): Secure Entry in Gmail is a crucial mode that enables users to safeguard against missing essential emails. This feature empowers users to designate specific email addresses and domains within Gmail, ensuring that all messages from these designated sources bypass spam filters and are delivered directly to the inbox. - [Akira Ransomware Attacks Exploit Zero-Day Cisco ASA Vulnerability](https://firsthackersnews.com/cisco-cve-2023-20269/): In recent updates, there have been emerging reports about threat actors associated with the Akira ransomware focusing their attention on Cisco VPNs that do not employ multi-factor authentication (MFA). - [Alert for Mac Users: A Malvertising Campaign spreads Atomic Stealer macOS Malware](https://firsthackersnews.com/atomic-stealer/): A fresh malvertising campaign has come to light, disseminating an updated variant of macOS stealer malware known as Atomic Stealer (AMOS). This discovery suggests active maintenance by its author. - [Mirai botnet: New version financially infects Android TV boxes](https://firsthackersnews.com/mirai-botnet/): A recently updated variant of the Mirai botnet malware is now targeting Android TV set-top boxes, which are widely utilized by millions of users for streaming, with a particular emphasis on financial exploitation. - [A new Python variant of the Chaes Malware is focusing on the banking and logistics sectors.](https://firsthackersnews.com/chaes-malware/): In early 2022, Avast conducted an analysis that unveiled how the individuals responsible for a feature named Lucifer had infiltrated over 800 WordPress websites. They used this access to distribute the Chaes malware to users of Banco do Brasil, Loja Integrada, Mercado Bitcoin, Mercado Livre, and Mercado Pago. - [Zero-Day Alert: Latest Android Patch Update Addresses Actively Exploited Vulnerability with New Fix](https://firsthackersnews.com/latest-android-patch/): Google has released its monthly security patches for Android to tackle various vulnerabilities, one of which is a zero-day bug that may have been exploited in real-world scenarios. - [Recent BLISTER Malware Update Boosting Stealthy Network Intrusion](https://firsthackersnews.com/blister-malware/): "In the ongoing SocGholish infection chains, a revised BLISTER malware loader is now deployed to distribute Mythic, an open-source command-and-control (C2) framework. - [VIPRE research on spam and phishing emails](https://firsthackersnews.com/vipre-research-on-spam-and-phishing-emails/): Based on a report from VIPRE, the use of malicious links in phishing emails reached 85%, and there was a 30% increase in spam emails from the first quarter to the second quarter of 2023. - [Reported ransomware attacks have targeted LogicMonitor customers, leading to security breaches](https://firsthackersnews.com/logicmonitor/): Today, LogicMonitor, a network monitoring company, confirmed that certain users of its SaaS platform have been impacted by cyberattacks. - [Chinese APT Uses Fake Messenger Apps to Spy on Android Users](https://firsthackersnews.com/badbazaar-spyware/): In the coming years, Signal's applications became compromised, while Telegram, containing the BadBazaar spyware, was uploaded to Google Play and Samsung Galaxy Store by the Chinese hacking group known as GREF. - [DarkGate malware activity is increasing](https://firsthackersnews.com/darkgate-malware/): A recently detected malspam campaign has been identified as distributing a readily available malware known as DarkGate. - [The emerging ransomware collective “Ransomed” has adopted a novel extortion strategy.](https://firsthackersnews.com/ransomware-ransomed/): Dubbed "Ransomed," this group was initially identified by cybersecurity analyst and blogger Flashpoint on August 15th. The group has established a dedicated Telegram channel and is also showcasing a prominent "ransomed" domain name, presumably for their main website. - [A Single-Click Security Vulnerability Found in Zimbra Collaboration Suite: CVE-2023-41106](https://firsthackersnews.com/single-click-security-vulnerability-zimbra/): Within the realm of digital communication and collaboration, the Zimbra Collaboration Suite has long stood as a dependable companion. Nevertheless, a cloud of doubt has been cast upon its security in recent times. - [ALPHV ransomware: New data leak API as a new extortion strategy](https://firsthackersnews.com/alphv-ransomware-2/): The ALPHV ransomware group, known as BlackCat, aims to intensify ransom payment pressure on victims by offering an API for their leak site, thereby amplifying the exposure of their attacks. - [NEW STUDY SHEDS LIGHT ON ADHUBLLKA RANSOMWARE NETWORK](https://firsthackersnews.com/adhubllka-ransomware/): Cybersecurity analysts have revealed an intricate network of interconnected ransomware variants, all of which can be traced back to a shared origin: the Adhubllka ransomware family. - [Roblox Game Developers Facing Threat from Over a Dozen Malicious npm Packages](https://firsthackersnews.com/malicious-npm-packages-2/): Since the beginning of August 2023, over twelve malicious packages have been found in the npm package repository. These packages have the ability to install an open-source information stealer named Luna Token Grabber on systems owned by Roblox developers. - [Scarab Ransomware Deployed Worldwide Via Spacecolon Toolset](https://firsthackersnews.com/spacecolon-scarab-ransomware/): "Cybersecurity experts at ESET reveal the discovery of a malevolent toolkit called Spacecolon, which has been utilized to propagate various strains of the Scarab ransomware across numerous victim organizations worldwide." - [New variant of XLoader macOS Malware masquerading as OfficeNote app](https://firsthackersnews.com/xloader-malware/): A fresh iteration of the XLoader malware targeting macOS disguises itself under the name 'OfficeNote' productivity application. - [Chinese Hackers Using Stolen Ivacy VPN Certificate To Sign Malware](https://firsthackersnews.com/chinese-hackers-using-stolen-ivacy-vpn/): The Bronze Starlight hacking group has ingeniously employed a legitimate Ivacy VPN code-signing certificate to focus on the Southeast Asian gambling sector. - [Hackers Can Exploit New WinRAR Vulnerability to Gain PC Control](https://firsthackersnews.com/winrar-vulnerability/): A security vulnerability of significant severity has been revealed in the WinRAR utility, posing a potential risk for threat actors to execute remote code on Windows systems. - [BlackCat’s Sphynx ransomware integrates Impacket, RemCom](https://firsthackersnews.com/blackcats-sphynx/): A new iteration of the BlackCat ransomware was recently unveiled by Microsoft's researchers. Termed 'Sphynx', this variant incorporates the Impacket networking framework and the Remcom hacking tool. - [Researchers Detect Vulnerabilities in PowerShell Gallery Enabling Supply Chain Attacks](https://firsthackersnews.com/vulnerabilities-in-powershell/): Malicious actors could exploit existing vulnerabilities within the PowerShell Gallery to execute supply chain attacks targeting users of the registry. - [Ivanti Avalanche Critical Buffer Overflow Vulnerabilities: CVE-2023-32560](https://firsthackersnews.com/ivanti-avalanche/): Two significant security flaws, designated as CVE-2023-32560, have been unearthed in Ivanti Avalanche. This enterprise mobility management (EMM) solution is tasked with the management, monitoring, and security of diverse mobile devices. - [MaginotDNS: DNS cache poisoning attacks](https://firsthackersnews.com/maginotdns-attack/): Researchers from UC Irvine and Tsinghua University have created a potent cache poisoning attack named "MaginotDNS." This attack focuses on Conditional DNS (CDNS) resolvers and has the potential to compromise entire top-level domains (TLDs). - [Gafgyt: Exploits five year old flaw in EoL Zyxel](https://firsthackersnews.com/gafgyt-malware/): Fortinet has raised an alert regarding the Gafgyt botnet malware, which is currently targeting a vulnerability in the Zyxel EoL router. This vulnerability occurs during the router's final phase and results in thousands of daily attacks. - [Lapsus$: How They Hacked Some of the Biggest Targets](https://firsthackersnews.com/lapsus-team/): The amateur hacker group Lapsus$—mostly teenagers with limited technical training—has skillfully breached major targets like Microsoft, Okta, Nvidia, and Globant. The government is studying their methods to enhance cybersecurity. - [Microsoft Patch Tuesday August: Warns of 2 zero-days](https://firsthackersnews.com/microsoft-patch-tuesday-2/): Microsoft introduces the August 2023 Patch Tuesday update, encompassing 87 security enhancements addressing 23 vulnerabilities. Among these are two vulnerabilities currently under active exploitation. The update also tackles twenty-three instances of remote code execution vulnerabilities. - [Suspected Vietnamese hacker targets Chinese, Bulgarian organizations with new ransomware](https://firsthackersnews.com/new-yashmaransomware/): Since June 4, 2023, an unidentified threat actor has been employing a Yashma ransomware variant to target entities in English-speaking countries, Bulgaria, China, and Vietnam. - [QakBot Malware Operators Ramp Up C2 Network with 15 New Servers](https://firsthackersnews.com/qakbot-malware/): As of late June 2023, the QakBot (aka QBot) malware operators have established 15 new command-and-control (C2) servers. - [“Critical Remote Code Execution (RCE) Vulnerability (CVE-2023-39143) in PaperCut Application Servers”](https://firsthackersnews.com/papercut-application-servers/): PaperCut NG and PaperCut MF are widely adopted software solutions for managing print services on servers. - [Critical Microsoft Power Platform Vulnerability: Proactive Security Methods to Prevent Exploitation](https://firsthackersnews.com/microsoft-power-platform/): To protect against the Microsoft Power Platform vulnerability, consider implementing the following recommendations: - [Fake VMware vConnector package detected in PyPI](https://firsthackersnews.com/vmware-pypi/): IT professionals were targeted by a malicious package named "VMConnect," which impersonated the VMware vSphere connector module "vConnector" and was uploaded to the Python Package Index (PyPI). - [Malicious apps employ sneaky versioning techniques to evade detection by Google Play Store scanners.](https://firsthackersnews.com/malicious-apps-google-playstore/): ThreatFabric disclosed that malware distributors exploit an Android bug to make malicious apps appear benign by "corrupting components of an app" while keeping the overall app valid, as reported by KrebsOnSecurity. - [NodeStealer 2.0 takes over Facebook Business accounts and targets crypto wallets](https://firsthackersnews.com/nodestealer/): Palo Alto Networks Unit 42 found a new phishing campaign distributing a Python variant of NodeStealer. The code aims to seize Facebook business accounts and steal cryptocurrency funds. - [A new attack significantly affects AI chatbots](https://firsthackersnews.com/ai-chatbots/): The research indicates that the issue of AI chatbots deviating from guidelines is not a minor flaw that can be easily corrected with simple rules. Instead, it reveals a fundamental vulnerability that poses challenges to the development of more advanced AI. - [Fruity Trojan: Uses deceptive software installers to spread the Remcos RAT](https://firsthackersnews.com/fruity-trojan/): Inside the installer, along with the genuine software, the Fruity trojan is placed. This Python-based malware disguises itself by embedding within an MP3 file and using steganography to conceal two executables and shellcode. - [Flipper Zero: Now has an app store for third-party applications](https://firsthackersnews.com/flipper-zero/): The Flipper Zero team recently introduced "Flipper Apps," its very own mobile app store. This new store enables mobile users to easily install 3rd party applications, expanding the capabilities of the renowned wireless pen-testing tool. - [WordPress Ninja Forms: Flaw in plugin allows data theft](https://firsthackersnews.com/wordpress-ninja/): Despite the availability of the updated version, current statistics from WordPress.org indicate that merely half of WordPress Ninja Forms users have taken action to download the latest release, leaving approximately 400,000 sites still exposed and vulnerable to potential attacks. - [Lazarus: They hijack Microsoft’s IIS servers to distribute malware](https://firsthackersnews.com/lazarus-iis-web-servers/): In a previous blog post (May 2023) titled "Lazarus Group Targeting Windows IIS Web Servers," there were documented instances of the Lazarus threat group targeting IIS servers. The attackers gained initial access by exploiting poorly managed or vulnerable web servers. Additionally, there were cases where RDP (Remote Desktop Protocol) was used for lateral movement after internal reconnaissance. - [Azimut: Italian Asset Manager victim of ransomware attack](https://firsthackersnews.com/azimut/): Azimuth Group, an Italian asset management company, oversees a substantial portfolio of over $87.2 billion in assets. It has recently made a strong statement, affirming that it will not yield to any demands from the notorious ransomware group, BlackCat. - [Microsoft: Stolen key gave access to cloud services](https://firsthackersnews.com/microsoft-stolen-key-gave-access-to-cloud-services/): Wiz security researchers have revealed that Chinese hackers, known as Storm-0558, successfully stole Microsoft's consumer signing key. - [Estée Lauder: Hacked by two ransomware gangs](https://firsthackersnews.com/estee-lauder/): The Estée Lauder Companies confirmed a ransomware attack in an SEC filing, stating that the attackers gained access to some of its systems, and data may have been stolen. - [Mallox ransomware exploits weak MS-SQL servers to breach networks](https://firsthackersnews.com/mallox-ransomware/): New findings from Palo Alto Networks Unit 42 reveal that in 2023, Mallox ransomware activities have surged by an alarming 174% compared to the previous year. - [BundleBot malware steals sensitive information](https://firsthackersnews.com/bundlebot-malware/): Discovered by Check Point, the BundleBot malware utilizes custom-made obfuscation and junk code to evade analysis successfully. This advanced threat possesses a wide array of capabilities, including data theft from web browsers, screenshot capture, Discord token acquisition, and the gathering of sensitive information from Telegram and Facebook accounts. - [Adobe: Urgent patch fixes ColdFusion zero-day](https://firsthackersnews.com/coldfusion-zero-day/): Adobe has addressed three vulnerabilities in ColdFusion, including a zero-day vulnerability. - [“Blackhat AI Module ‘WormGPT’ Attracts 5,000 Subscribers in a Few Days”](https://firsthackersnews.com/blackhat-ai-wormgpt/): Artificial Intelligence (AI) has introduced revolutionary advances, including generative AI, which shows great potential for creative use. However, the emergence of tools like WormGPT has raised concerns about its implications. - [Turla: Targets Exchange servers with new DeliveryCheck backdoor malware](https://firsthackersnews.com/turla-threatacto/): Microsoft and the Ukrainian CERT issued a warning about Russian state hacking group Turla launching new attacks. The targets include the defense industry and Microsoft Exchange servers, exploiting a new "DeliveryCheck" malware backdoor. - [Critical and High Vulnerabilities in Citrix ADC and Citrix Gateway (CVE-2023-3519, CVE-2023-3466, CVE-2023-3467)](https://firsthackersnews.com/citrix-adc-citrix-gateway/): Citrix ADC and Citrix Gateway, renowned for their role in facilitating secure application delivery and remote access solutions, have unfortunately been discovered to possess critical vulnerabilities. - [AVrecon malware infects 70.000 Linux routers to create botnet](https://firsthackersnews.com/avrecon-malware/): AVrecon malware infects 70,000 Linux routers, forming a botnet for bandwidth theft and a hidden residential proxy service. - [Gamaredon hackers steal data in less than an hour after the breach](https://firsthackersnews.com/gamerdon-hackers-steals-data/): The Computer Emergency Response Team (CERT-UA) of Ukraine has issued a warning regarding the rapid actions of the hackers known as Gamaredon. - [Zimbra to admins: Manually patch this zero-day vulnerability](https://firsthackersnews.com/zimbra-zero-day-vulnerability/): Zimbra Collaboration Suite (ZCS) has issued an urgent advisory, urging administrators to apply a manual patch for a zero-day vulnerability. This vulnerability is actively exploited by attackers to target and compromise ZCS email servers. - [Fake PoC for a Linux Kernel vulnerability on GitHub contains malware](https://firsthackersnews.com/fake-poc-linux-kernel/): A fake PoC about a Linux kernel vulnerability on GitHub exposed researchers to malware. - [Triada Malware: Infects Android devices via fake Telegram app](https://firsthackersnews.com/triada-malware/): The Triada malware infiltrates Android devices through a counterfeit Telegram app. - [Critical Auth Bypass Vulnerabilities: SonicWall Urges Immediate Patching for GMS/Analytics](https://firsthackersnews.com/sonicwall-mmediate-patching/): SonicWall has issued an urgent warning to its customers, urging them to promptly patch several critical vulnerabilities that are affecting the company's Global Management System (GMS) firewall management and Analytics network reporting engine software suites. - [Microsoft’s July 2023 Patch Tuesday Fixes Five Zero-Days, Nine Critical Vulnerabilities](https://firsthackersnews.com/microsoft-july-patch/): Today, Microsoft Corp. released software updates to address a total of 130 security vulnerabilities in its Windows operating systems and related software. These updates include fixes for at least five flaws that are currently being actively exploited. - [Critical RCE Vulnerability in ShareFile: PoC Exploit Available](https://firsthackersnews.com/rce-vulnerability/): Recently, a critical vulnerability was discovered in ShareFile, a cloud-based file sharing application. This vulnerability, identified as CVE-2023-24489, enables unauthenticated individuals to perform arbitrary file uploads and execute remote code (RCE). - [MOVEit Transfer customers are being warned to fix a new, critical flaw](https://firsthackersnews.com/moveit-transfer-critical-flaw/): Progress is notifying customers about a newly discovered critical SQL injection vulnerability, identified as CVE-2023-36934, in its MOVEit Transfer software. - [Rekoobe Malware: Targets vulnerable Linux servers](https://firsthackersnews.com/rekoobe-malware/): Rekoobe, a backdoor malware, specifically targets vulnerable Linux servers commonly utilized by the Chinese APT31. - [Microsoft Teams: The TeamsPhisher tool exploits its bug](https://firsthackersnews.com/microsoftteams-teamsphisher-tool/): The "TeamsPhisher" cybersecurity tool provides a means for both pen testers and malicious actors to send harmful files directly to a Teams user via an external account or tenant - [New StackRot Linux kernel flaw allows privilege escalation](https://firsthackersnews.com/stackrot-linux-kernel-flaw/): Recent reports have brought to light crucial technical details regarding a critical vulnerability impacting various versions of the Linux kernel. This vulnerability, known as "StackRot" (CVE-2023-3269), can be triggered with minimal capabilities, posing a significant security risk. - [DDoSia Attack Tool Upgraded with Encryption, Concealed Targeting](https://firsthackersnews.com/ddosia-attack/): A new version of the DDoSia attack tool has been released by the threat actors, featuring an updated mechanism for obtaining the list of targets. This enhancement enables the tool to bombard the targets with spam HTTP requests, aiming to disrupt their services. - [WordPress plugin gives hackers admin access to your site](https://firsthackersnews.com/wordpress-plugin-gives-hackers-admin-access/): A vulnerability found in the Ultimate Member plugin has the potential to exploit thousands of WordPress sites, putting them at risk. However, implementing a quick fix can prevent your site from being compromised and taken over. - [BlackCat Ransomware Gang to Launch Malicious WinSCP Ads](https://firsthackersnews.com/malicious-winscp-ads/): The BlackCat ransomware group launched a malvertising campaign to push Cobalt Strike. They put up advertisements to attract people to fake WinSCP pages. Instead of the application, the victims download malware. - [Modified Telegram app with malware that puts your data at risk found](https://firsthackersnews.com/modified-telegram-app-malware/): Cybersecurity researchers recently uncovered a concerning discovery regarding a modified iteration of the widely-used messaging application, Telegram, specifically designed for Android devices. This modified version has been identified as malicious, posing a significant threat to users' data security as it is capable of unauthorized data theft. - [New Malware by Lazarus-Backed Andariel Group Exploits Log4j](https://firsthackersnews.com/lazarus/): Kaspersky said the advanced persistent threat group Andariel operated for over a decade within Lazarus Group. - [Newly Uncovered ThirdEye Windows-Based Malware Steals Sensitive Data](https://firsthackersnews.com/thirdeye-windows-based-malware/): Security researchers have recently discovered ThirdEye, an information stealer designed for Windows operating systems. This stealthy malware is capable of collecting sensitive data from computers that have been infected. - [Android malware Fluhorse targets credit cards](https://firsthackersnews.com/android-malware-fluhorse/): Cybersecurity experts have recently disclosed the intricate workings of Fluhorse, an Android malware family. - [Akira ransomware: Linux version targets VMware ESXi servers](https://firsthackersnews.com/akira-ransomware/): Akira, a ransomware operation, has recently shifted its focus from Windows systems to VMware ESXi virtual machines, utilizing a Linux encryptor to carry out the encryption process. - [Arcserve: Fixed critical vulnerability in UDP software](https://firsthackersnews.com/arcserve-fixed-critical-vulnerability/): Arcserve has recently launched a security update to resolve a severe authentication bypass vulnerability known as CVE-2023-26258, in their ArcServe UDP Backup software. - [Windows malware spreads through infected Super Mario game](https://firsthackersnews.com/super-mario-game/): The trojanized Super Mario game installer does more than just mine cryptocurrency. It also employs Umbral Stealer, an open-source information stealer. This advanced malware can steal sensitive data from infected Windows devices. - [Vulnerabilities Identified and Patched in BIND 9 DNS Software](https://firsthackersnews.com/bind-9-dns/): The BIND 9 DNS software suite, an integral part of the Domain Name System (DNS), has recently received updates to neutralize three high-priority vulnerabilities. This could potentially induce significant service interruptions. The formal designations for these vulnerabilities are CVE-2023-2828, CVE-2023-2829, and CVE-2023-2911. - [Powerful JavaScript Dropper PindOS distributes Bumblebee and IcedID malware](https://firsthackersnews.com/bumblebee-icedid-malware/): A new strain of the JavaScript dropper has been observed delivering next-stage payloads such as Bumblebee and IcedID. - [The IDOR Vulnerability in Microsoft Teams](https://firsthackersnews.com/idor/): Cybersecurity researchers have recently informed that a vulnerability in the latest version of Microsoft Teams allows attackers to inject malware into any organization's network. - [Chinese APT15 hackers use new Graphican backdoor](https://firsthackersnews.com/graphican-backdoor/): The team of researchers suggests that the Graphican backdoor represents an evolved version of an older malware previously utilized by the hackers, rather than a fresh creation. Its noteworthy attributes include the use of Microsoft Graph API and OneDrive to subtly retrieve its command and control (C2) infrastructure addresses in an encrypted format, thereby ensuring versatility and resilience against potential disruptions. - [Android malware GravityRAT steals your WhatsApp backups](https://firsthackersnews.com/gravityrat-malware/): ESET researchers have identified an updated version of Android GravityRAT spyware being distributed as the messaging apps BingeChat and Chatico.  - [Infostealer malware has stolen 101.000 ChatGPT accounts](https://firsthackersnews.com/infostealer-malware/): More than 101.000 ChatGPT user accounts have been stolen by infostealer malware over the past year, according to data from the dark web market. - [SeroXen Malware Latest to Deploy BatCloak Evasion Tool](https://firsthackersnews.com/seroxen-malware/): Security researchers warn that malware developers are adopting a handy obfuscation tool to get malware past antiviruses. - [The rise of phishing scams and how to avoid them.](https://firsthackersnews.com/phishing-scam/): Cybersecurity scams continue to be on the rise. As scammers get smarter, it’s important to stay up to date on the latest trends. One of the best things you can do for yourself is to be able to recognize the signs of a potential phishing scam and how to avoid them.  - [Zyxel patches critical vulnerability in NAS devices (CVE-2023-27992)](https://firsthackersnews.com/zyxel-patches-critical-vulnerability/): Zyxel has released firmware patches for a critical vulnerability (CVE-2023-27992) in some of its consumer network attached storage (NAS) devices. - [New Mystic Stealer Malware Targets 40 Web Browsers and 70 Browser Extensions](https://firsthackersnews.com/mystic-stealer-malware/): A new stealer malware is on the rise, designed to obtain user credentials to help attackers penetrate specific environments and obtain other information of financial value. - [What Is the Principle of Least Privilege (POLP)?](https://firsthackersnews.com/principle-of-least-privilege-polp/): The principle of least privilege (POLP), also named the “principle of least authority” (POLA) or “the principle of minimal privilege” (POMP), stands for a cybersecurity best practice based upon granting the minimum required access that a user needs to perform an assigned task. - [New Diicot group targets SSH servers with brute-force malware](https://firsthackersnews.com/diicot-targets-ssh-server/): Diicot shares its new name with the Romanian anti-terrorist police unit and uses the same style of messaging and imagery. - [Fake zero-day PoC exploits on GitHub spread Windows and Linux malware](https://firsthackersnews.com/fake-zero-day/): This campaign was discovered by VulnCheck, which reports that it has been running since at least May 2023, promoting alleged exploits for zero-day flaws in popular software such as Chrome, the Discord, the Signal, WhatsApp and Microsoft Exchange. - [Gamaredon: Uses PowerShell USB malware to drop backdoors](https://firsthackersnews.com/gamaredon-uses-powershell-usb-malware-to-drop-backdoors/): Russia-linked state-sponsored cyber-espionage group Gamaredon (Armageddon, UAC-0010) continues its relentless attacks against government entities, and organizations in Ukraine's military and security intelligence sectors, using updated malware tools, according to a new report from Symantec threat intelligence team. - [New Golang-based Skuld Malware Stealing Discord and Browser Data from Windows PCs](https://firsthackersnews.com/golang-based-skuld-malware/): The Purpose of Skuld malware tried to steal sensitive information from its victims as per Trellix researcher. To get these information it searches for data stored in applications such as Discord and web browsers; information from the system and files stored in the victim’s folders.  - [Hackers use BatCloak to make their malware completely undetectable](https://firsthackersnews.com/hackers-use-batcloak/): A fully undetectable (FUD) malware obfuscation engine called BatCloak has been used to deploy various malwastrains since September 2022, persistently evading detection by antiviruses. - [Fortinet Patches Critical FortiGate SSL VPN Vulnerability](https://firsthackersnews.com/fortinet-patch/): Fortinet has patched a critical flaw in its Fortigate devices, with admins urged to apply firmware updates as a matter of urgency.  - [Google Switches Email Authentication Method Following Exploitation by Scammers](https://firsthackersnews.com/google-switches-emailauthentication/): Gmail’s system uses Brand Indicators for Message Identification (BIMI) as well as DMARC (Domain-based Message Authentication, Reporting, and Conformance) and a VMC (Verified Mark Certificate) issued by a certification authority, such as Entrust or DigiCertto, to verify both the logo and the domain attached. - [Cisco Addresses High-Severity Bug in Secure Client Software](https://firsthackersnews.com/cisco-addresses-high-severity-bug/): Cisco has recently fixed a high-severity vulnerability found in its Cisco Secure Client (previously known as AnyConnect Secure Mobility Client) software. This issue could have allowed attackers to escalate their privileges to the SYSTEM account used by the operating system. - [New PowerDrop Malware Targets U.S. Aerospace Industry](https://firsthackersnews.com/powerdrop-malware/): A new PowerShell malware script, named “PowerDrop”, has been discovered to be used in attacks targeting the US aerospace defense industry. - [New Malware Campaign Leveraging Satacom Downloader to Steal Cryptocurrency](https://firsthackersnews.com/satacom-downloader/): A recent malware campaign has been discovered that exploits the Satacom downloader as a means to deploy discreet malware capable of stealing cryptocurrency by using a deceptive extension for Chromium-based web browsers. - [Cyclops Ransomware group offers a multiplatform Info Stealer](https://firsthackersnews.com/cyclops-ransomware/): The Cyclops group has developed multi-platform ransomware that can infect Windows, Linux, and macOS systems. - [Alarming Surge in TrueBot Activity Revealed with New Delivery Vectors](https://firsthackersnews.com/truebot/): TrueBot downloader trojan botnet activity has increased significantly in the past month, researchers say. - [Google fixes new zero-day vulnerability in Chrome browser](https://firsthackersnews.com/google-fixes-zero-day/): Yesterday, Google addressed another zero-day vulnerability affecting Google Chrome. The Flashpoint Intel Team quickly published an alert to VulnDB customers and have been closely tracking the vulnerability since.Yesterday, Google addressed another zero-day vulnerability affecting Google Chrome. The Flashpoint Intel Team quickly published an alert to VulnDB customers and have been closely tracking the vulnerability since. - [WordPress: Automatic update to fix vulnerability in Jetpack plugin](https://firsthackersnews.com/vulnerability-in-jetpack-plugin/): The popular and one of the most-used WordPress plugins, Jetpack recently addressed a critical security issue. Despite no active exploitation, WordPress force installed Jetpack plugin updates to websites to patch the vulnerability. - [Gigabyte Firmware Code Injection: Persistent Backdoor Leads to Supply Chain Risks](https://firsthackersnews.com/gigabyte-firmware-code-injection/): Cybersecurity firm Eclypsium has uncovered a potential backdoor in Gigabyte systems, raising concerns about the security of the technology supply chain. - [Attackers Exploit Critical Zero-Day Vulnerability in MOVEit Transfer](https://firsthackersnews.com/zero-day-vulnerability-in-moveit-transfer/): The zero-day vulnerability, which Progress disclosed Wednesday, is a SQL injection flaw that could lead to escalated privileges and potential unauthorized access in the managed file transfer (MFT) product. Currently, there is no patch available for the flaw, and it has not been assigned a CVE. - [CVE-2023-33733: RCE Vulnerability in ReportLab Python Library](https://firsthackersnews.com/cve-2023-3373-vulnerability/): A technical write-up for a ReportLab vulnerability are now available. The vulnerability tracked as CVE-2023-33733. - [LEVERAGING CHATGPT TO STRENGTHEN YOUR CYBERSECURITY](https://firsthackersnews.com/leveraging-chatgpt-to-strengthen-your-cybersecurity/): ChatGPT (generative pre-trained transformer) is an AI-powered chatbot created by Open AI and designed to produce human-like text and interact with users in a conversational way. While ChatGPT is technically a chatbot, it is significantly advanced in comparison to any previously released model.  - [Android trojan “DogeRAT” targets Indian users, stealing personal and financial information](https://firsthackersnews.com/android-trojan-dogerat/): An open-source Android virus known as DogeRAT (Remote Access Trojan) has been discovered by CloudSEK, an AI cybersecurity company.  - [Android apps with SpinOk spyware module installed over 421,000K times](https://firsthackersnews.com/android-apps-with-spinok-spyware/): A new Android malware – SpinOk – distributed as an advertisement SDK has been discovered in several apps – many of which were previously listed on Google Play and have been downloaded a total of over 400 million times. - [Critical Vulnerabilities in D-Link Products](https://firsthackersnews.com/d-link-vulnerability/): D-Link has fixed two critical vulnerabilities in the D-View 8 network management suite that could allow remote attackers to bypass authentication and execute arbitrary code. - [Zyxel firewalls are affected by two security flaws](https://firsthackersnews.com/zyxel-firewalls/): Zyxell has released a security advisory for multiple buffer overflow vulnerabilities. Exploitation of these vulnerabilities could allow an unauthenticated attacker to cause denial-of-service (DoS) conditions and even a remote code execution on the affected Zyxell firewalls. - [Google’s New ZIP Domain Could Be Used for Phishing and Malware Attacks](https://firsthackersnews.com/googles-new-zip-domain/): Security professionals warn that Google's new top-level domains, .zip and .mov, pose social engineering risks while providing little reason for their existence. - [Luxottica Data Leak Exposes Over 70M Customers’ Data](https://firsthackersnews.com/luxottica-data/): Luxottica, the world’s largest eyewear company, has revealed that it was the victim of a major cyber attack. The attack exposed the personal information of over 70 million customers on hacking forums. - [GUI-vil’s Strategies in AWS Compromises](https://firsthackersnews.com/gui-vils-aws-compromises/): Researchers have been tracking a financially motivated threat group known as GUI-vil (aka p0-LUCR-1), based in Indonesia, which engages in unauthorized cryptocurrency mining. - [BlackCat ransomware is using signed Microsoft kernel drivers to avoid detection](https://firsthackersnews.com/blackcat-ransomware-is-using-signed-microsoft-kernel-drivers-to-avoid-detection/): The new driver used by the BlackCat ransomware company helps it to elevate its privileges on infected machines and then stop processes related to security agents. - [Vulnerability in KeePass Password Manager Permits Retrieving Master Password (CVE-2023-32784)](https://firsthackersnews.com/cve-2023-32784/): The KeePass 2.X branch for Windows, Linux, and macOS is vulnerable to CVE-2023-32784. - [IcedID Macro Attacks Deploy Nokoyawa Ransomware](https://firsthackersnews.com/icedid-macro-attacks/): Malicious actors frequently resort to alternative techniques to gain initial access, such as employing diverse file formats and payloads. It is important to highlight that they still actively use VBA macros embedded within Office documents to infiltrate target systems. - [Live Speech & Personal Voice: Apple’s two useful features for speech impaired people](https://firsthackersnews.com/apples-two-useful-features/): Apple announced that it will make available new important "Accessibility functions"At iOS 17 that will be released this year, and two of the most important are “Live Speech" and "personal voice". Both functions can help them significantly users that face problems with speech. - [CopperStealer Malware Crew Resurfaces with New Rootkit and Phishing Kit Modules](https://firsthackersnews.com/copperphish-malware/): The threat actors behind the CopperStealer malware re-emerged in March and April 2023 with two new campaigns designed to deliver two new payloads called CopperStealth and CopperPhish. - [Discord reveals data breach after worker hack](https://firsthackersnews.com/discord-databreac/): Top streaming service Discord has suffered a minor cybersecurity incident in which potentially sensitive and personal user data was exposed.  - [Critical Privilege Escalation in Essential Addons for Elementor Plugin](https://firsthackersnews.com/cve-2023-32243-vulnerability/): WordPress plugins allow organizations to quickly extend the functionality of their websites without requiring any coding or advanced technical skills. But they have also been the biggest source of risk for website operators in recent years. - [RapperBot Crew Drops DDoS/CryptoJacking Botnet Collab](https://firsthackersnews.com/rapperbot-cryptojacking-botnet/): New samples of it RapperBot botnet malware, reviewed by experts security, they have added cryptomining capabilities to mine cryptocurrency from hacked machines with Intel x64. - [Scammers Distribute Malware via Verified Account Ads on Facebook](https://firsthackersnews.com/scammers-verified-accounts/): The scammers behind these attacks may have compromised Facebook pages that purchased malware-laden ads. - [New PhaaS ‘Greatness’ Simplifies Microsoft 365 Phishing Attacks](https://firsthackersnews.com/phaas-greatness/): A Phishing-as-a-Service (PhaaS) platform called “Greatness” has seen a spike in activity as it targets organizations using Microsoft 365 in the United States, Canada, the United Kingdom, Australia and South Africa. - [Magecart malware strikes e-commerce websites again and again](https://firsthackersnews.com/magecart-malware/): Shopping cart malware, known as Magecart, is still one of the most popular tools in the attacker's toolbox, and despite efforts to mitigate and eliminate its presence, it remains fully active. - [Malware Attacks From SmokeLoader And RoarBAT, CERT-UA Warns](https://firsthackersnews.com/smokeloader-malware/): Based on the Computer Emergency Response Team of Ukraine (CERT-UA), the SmokeLoader malware is now being spread via a phishing campaign using lures centered around invoices. A ZIP folder containing a fake document and a JavaScript file is attached to the emails, which the agency says were sent from hacked accounts. - [FluHorse malware attacks Android phones stealing personal data including passwords](https://firsthackersnews.com/fluhorse-malware/): A new Android malware named “FluHorse” has been discovered, targeting users in East Asia with malicious apps that mimic legitimate versions. - [New KEKW malware infects open source Python Wheel files](https://firsthackersnews.com/kekw-malware/): The KEKW malware employs a malicious function known as system_information() to gather a wide range of system-related data from infected machines. - [Cisco Phone Adapters Flaw Let Attackers Execute Arbitrary Code](https://firsthackersnews.com/cve-2023-20126-vulnerability/): Cisco SPA112 2-Port Phone Adapters have been reported to be vulnerable to arbitrary code execution via a malicious firmware upgrade. Cisco has classified this vulnerability as Critical, with a CVSS Score as 9.8. - [New ‘Cactus’ Ransomware Encrypts Itself to Evade Detection](https://firsthackersnews.com/cactus-ransomware/): A novel ransomware strain dubbed ‘Cactus’ has been found to be exploiting vulnerabilities in Fortinet VPN devices to gain initial access to corporate or other large-scale networks. - [Sandworm Attackers Use WinRAR to Wipe Data from Government Devices](https://firsthackersnews.com/sandworm-attackers-winrar/): Sandworm (UAC-0165), a Russian hacking group, has been linked to an attack on Ukrainian state networks that involved wiping data from government devices using WinRAR, according to an advisory from the Ukrainian Government Computer Emergency Response Team (CERT-UA).  - [Windows admins can sign up for “known issue” email alerts](https://firsthackersnews.com/known-issue-email-alerts/): The Windows Known Issue Email Alerts is a new feature recently introduced. The Email Alerts for Windows known issue was the highly-requested feature for IT administrators who are responsible for planning and implementing Windows features and quality updates: email alerts. - [South Korean Lures Used to Deploy ROKRAT Malware](https://firsthackersnews.com/rokrat-malware/): The North Korean threat actor known as APT37 has been observed changing deployment methods and using South Korean foreign and domestic affairs-themed lures with archives containing Windows shortcut (LNK) files that initiate ROKRAT malware infection chains. - [New LOBSHOT Malware Deployed Via Google Ads](https://firsthackersnews.com/lobshot-malware/): Cybersecurity researchers have discovered a new malware, called ‘LOBSHOT,’ distributed through Google ads. - [Global Malverposting Campaign Infecting Over 500,000 Devices](https://firsthackersnews.com/malverposting-campaign/): A recent ‘malverposting’ campaign linked to a Vietnamese threat actor has been ongoing for months and is estimated to have infected over 500,000 devices worldwide in the past three months alone. - [How to Use GitHub Desktop in Windows 10 and 11](https://firsthackersnews.com/github-desktop/): Git and GitHub are essential tools for developers. However, the learning curve to adapting git version control into your daily workflow can be difficult at first. Newbie developers are often frustrated by the extensive list of commands needed to use git. - [Atomic macOS Malware Steals Auto-fills, Passwords, Cookies, Wallets](https://firsthackersnews.com/atomic-macos-malware/): Recently, the cybersecurity researchers at Cyble discovered a new macOS malware, ‘Atomic’ (aka ‘AMOS’), sold for $1,000/month on private Telegram channels. - [RTM Locker Ransomware Variant Targeting ESXi Servers](https://firsthackersnews.com/rtm-locker/): RTM Locker ransomware-as-a-service operators have now turned their attention to Linux, network-attached storage devices and ESXi hosts. - [Clop and LockBit Ransomware Gangs Target PaperCut Servers](https://firsthackersnews.com/papercut-servers/): Microsoft has recently revealed that the Clop and LockBit ransomware gangs are responsible for the attacks on PaperCut servers, exploiting vulnerabilities to steal corporate data. In April, two vulnerabilities, CVE-2023-27350 and CVE-2023-27351, were fixed in the PaperCut Application Server, which allowed remote attackers to perform unauthenticated remote code execution and information disclosure. - [VMware Resolves Crucial Pwn2Own Zero-Day Exploit Chain](https://firsthackersnews.com/vmware-resolves-zero-day-exploit/): To address zero-day vulnerabilities that might be used to achieve code execution on computers using unpatched versions of VMware’s Workstation and Fusion software hypervisors, the company has provided security upgrades. - [Evasive Panda’s Malicious Campaign Exploits Software Update Channels](https://firsthackersnews.com/evasive-panda/): Evasive Panda's malicious campaign uses the update channels of legitimate Chinese applications to deliver their infamous backdoor, MgBot malware, to unsuspecting victims. - [Code Insight – VirusTotal Launched AI-Powered Malware Analysis Features](https://firsthackersnews.com/virustotal/): An AI-powered code analysis feature was recently launched by VirusTotal, dubbed “Code Insight.” Google Cloud Security AI Workbench’s Sec-PaLM large language model (LLM), optimized for security use cases, powers VirusTotal’s latest feature. - [Yellow Pages Canada confirms cyberattack as BlackBasta leaks its data](https://firsthackersnews.com/yellow-pages-data/): Yellow Pages Group, a Canadian directory publisher has confirmed to BleepingComputer that it has been hit by a cyber attack. - [New SLP Vulnerability Could Let Attackers Launch 2200x Powerful DDoS Attacks](https://firsthackersnews.com/slp-vulnerability/): The Service Location Protocol (SLP) is intended to allow the automated discovery of shared services within a local area network (LAN) without the need for prior configuration on the part of client systems.  Its primary use to date has been to facilitate the identification and use of shared network printers. - [Finding Decoy Dog Toolkit via Anomalous DNS Traffic](https://firsthackersnews.com/decoy-dog/): The ‘Decoy Dog’ malware toolkit, aimed at enterprises, was uncovered recently by the security analysts at Infoblox by analyzing 70 billion DNS records and traffic that differs from typical online behavior. - [Bumblebee malware: Distributed via Google Ads and used for ransomware attacks](https://firsthackersnews.com/bumblebee-malware/): The bumblebee malware, first spotted last year targeting enterprise users is now distributed via SEO poisoning and Google Ads, which promote popular software such as Zoom, Cisco AnyConnect, the Chat GPT and Citrix Workspace. - [EvilExtractor Stealer Malware Attacks Peaked in March 2023](https://firsthackersnews.com/evil-extractor/): EvilExtractor malware affects Windows systems, and attackers utilize it mainly for stealing browser data and other sensitive information. Kodex released the malware in October 2022 and has since been updating it. - [LockBit ransomware encryptors found targeting Mac devices](https://firsthackersnews.com/lockbit-ransomware/): LockBit is the name of a ransomware targeting Mac Operating Systems (OSes). It is associated with the LockBit ransomware gang – the developers of LockBit, LockBit 2.0, LockBit 3.0, and various other variants. The aforementioned malware target Windows, Linux, and VMware ESXi servers. - [New QBot Banking Trojan Campaign Hijacks Business Emails to Spread Malware](https://firsthackersnews.com/new-qbot-banking-trojan/):  Kaspersky has also observed some Qbot versions turning victims’ computers into proxy servers to facilitate traffic redirection. - [WhatsApp introduces new security features](https://firsthackersnews.com/whatsappsecurity-feature/): WhatsApp has announced several new security features which include an extra check when an account is transferred to a new device. - [How to install the Android 14 Beta on Google Pixel](https://firsthackersnews.com/android-14-beta-googlepixcel/): After a few early developer previews, the Android 14 Beta program has officially arrived. Here’s how to get Android 14 on your Google Pixel smartphone. - [Kyocera: Exploited to distribute malware](https://firsthackersnews.com/kyocera-malware/): The Kyocera Android print app is vulnerable to unauthorized manipulation, providing malicious applications the opportunity to download and potentially install malware on vulnerable people Appliances. - [Hacked sites are spreading malware using fake Chrome updates](https://firsthackersnews.com/fake-chrome-updates/): Hackers are once again using fake Google Chrome updates as means to infect unsuspecting users with malware. - [Two New Emergency Patches from Apple](https://firsthackersnews.com/apple-patches/): Apple just issued a short, sharp series of security fixes for Macs, iPhones and iPads. - [Microsoft Issues Patches for 97 Flaws, Including Active Ransomware Exploit](https://firsthackersnews.com/microsoft-issues-patchupdate/): Microsoft has released another set of security updates to fix a total of 97 flaws impacting its software, one of which has been actively exploited in ransomware attacks in the wild. - [Microsoft and SAP Release Security Updates to Address Critical Vulnerabilities](https://firsthackersnews.com/microsoft-sap-release-security-updates/): The most important of the new notes deals with two critical vulnerabilities in SAP Diagnostics Agent that could be exploited to execute commands on all monitored SAP systems. The bugs are tracked as CVE-2023-27497 (CVSS score of 10) and CVE-2023-27267 (CVSS score of 9). - [Balada Injector malware campaign: It has infected 1 million WordPress sites](https://firsthackersnews.com/balada-injector-malware/): In recent years, Balada Injector has exploited over 100 domains and a variety of methods to exploit existing security vulnerabilities (such as HTML injection and Site URL). The attackers mainly aimed to obtain database credentials from the wp-config.php file. - [FusionCore – An Emerging Malware-as-a-Service Group in Europe](https://firsthackersnews.com/fusioncore-mawalre-as-a-service/): An up-and-coming cybercrime group, FusionCore, is likely composed of English-speaking European teenagers with distinct skills. - [New Rilide Malware Strikes Chromium-Based Browsers to Steal Cryptocurrency](https://firsthackersnews.com/new-rilide-malware-strikes-chromium-based-browsers-to-steal-cryptocurrency/): Researchers discovered a new malware that fakes legitimate Google Drive extensions to inject malicious scripts and steal cryptocurrency. The new Rilide malware targets Chromium-based browsers like Google Chrome, Microsoft Edge, Brave, and Opera. - [ALPHV Ransomware Affiliate targets vulnerable backup installations to gain initial access](https://firsthackersnews.com/alphv-ransomware/): Mandiant has identified a new affiliate of ALPHV (BlackCat ransomware), identified as UNC4466, that targets publicly exposed Veritas Backup Exec installations that are vulnerable to CVE-2021-27876, CVE-2021-27877, and CVE- 2021-27878 for an initial intrusion into the victims' networks. - [CryptoClippy: New Clipper malware targets Portuguese crypto users](https://firsthackersnews.com/cryptoclippy-malware/): Portuguese users should be wary of CryptoClippy, a new form of malware targeting them in a malvertising campaign. This malware is capable of stealing cryptocurrency if unsuspecting users are not careful. - [New Rorschach Ransomware: The Fastest Encryptor](https://firsthackersnews.com/rorschach-ransomware/): Upon execution, Rorschach ransomware attempts to stop a predefined list of services from systems. - [Hackers Exploit WinRAR SFX Archives to Install Backdoors Undetected](https://firsthackersnews.com/winrar/): Threat actors exploit WinRAR self-extracting (SFX) archives containing decoy files by adding malicious functionality to install backdoors in target systems without detection.  - [New AlienFox toolkit steals credentials for 18 cloud services](https://firsthackersnews.com/alienfox-steals-credentials/): A recently discovered comprehensive toolset dubbed AlienFox toolkit is circulating on Telegram.  - [QNAP Issues Urgent Warning to Customers Regarding Critical Linux Vulnerability](https://firsthackersnews.com/qnap-linux-vulnerability/): QNAP, a manufacturer of network-attached storage (NAS) systems, issued a warning to its users regarding a critical vulnerability that can be exploited through the Sudo program for Linux.  - [Microsoft Bing Search Results Altered Through AAD Misconfiguration](https://firsthackersnews.com/azure-active-directory/): Recently, cybersecurity company Wiz discovered a misconfiguration issue in Azure Active Directory (AAD) that resulted in unauthorized access to several applications, which could have also led to a Bing.com takeover. - [Mélofée: The latest malware targeting Linux servers](https://firsthackersnews.com/melofee-malware/): ExaTrack, a cybersecurity company based in France, recently discovered the innovative malware it named Mélofée. This malware specifically targets Linux servers and is believed to be operated by an anonymous Chinese state-sponsored APT group. - [Researchers warn of two new variants of potent IcedID malware loader](https://firsthackersnews.com/icedid-malware/): New IcedID variants found without the usual bank fraud feature. Instead, they appear to be aiming to install additional malware on infected devices. - [Card Skimming Attack Targets WooCommerce Websites](https://firsthackersnews.com/woocommerce-websites/): Online transactions ease our daily lives but also pose a serious risk to both businesses and their customers. Magecart attacks are one of them. Magecart is a type of malware that can steal credit card information from eCommerce websites. This threat has now extended to WordPress environments, particularly those using WooCommerce. - [SharePoint Phishing Scam Targets 1600 Across US, Europe](https://firsthackersnews.com/sharepoint-phishingscam/): A new Phishing campaign based on legitimate servers from the Microsoft SharePoint platform aims at least 1600 people throughout the Europe, the USA and other areas around the world using one native notification mechanism. - [Nexus Android Malware targets customers of 450 financial institutions worldwide](https://firsthackersnews.com/nexus-android/): The recently evolved version of Nexus has targeted more than 450 banks and cryptocurrency services. Multiple threat actors are already found to be using Nexus to conduct fraudulent campaigns. - [Adobe Acrobat Sign Abused to Distribute Malware](https://firsthackersnews.com/adobe-acrobat/): Cybercriminals have been observed abusing Adobe’s Acrobat Sign service to deliver emails leading to a RedLine stealer infection, cybersecurity firm Avast warns. - [The new HinataBot botnet could launch massive DDoS attacks](https://firsthackersnews.com/hinatabot-botnet/): Akamai said the malware itself was christened “Hinata” by its author after a character from the Naruto anime series. The security vendor found evidence of the “HinataBot” in its HTTP and SSH honeypots and said it is being actively updated by its authors. - [SAP Fixes Multiple Critical Vulnerabilities on March 2023 Patch Day](https://firsthackersnews.com/sap-vulnerability/): SAP has recently fixed 19 vulnerabilities as part of its March 2023 patch day. Five vulnerabilities are rated critical and have also been labeled “hot news” by the vendor. - [Android malware “FakeCalls” targets financial firms in South Korea](https://firsthackersnews.com/fakecalls-malware/): “FakeCalls malware possesses the functionality of a Swiss army knife, able not only to conduct its primary aim but also to extract private data from the victim’s device,” said CPR cybersecurity researcher Alexander Chailytko. - [Chinese and Russian Hackers Using SILKLOADER Malware to Evade Detection](https://firsthackersnews.com/silkloader-malware/): A piece of malware designed to load Cobalt Strike beacons onto victim machines has been traced back to both Chinese and Russian threat actors. - [Microsoft fixes Windows zero-day exploited in ransomware attacks](https://firsthackersnews.com/cve-2023-23397/): “CVE-2023-23397 is a critical EOP Vulnerability in Microsoft Outlook that is triggered when an attacker sends a message with an extended MAPI property with a UNC path to an SMB (TCP 445) share on a threat actor-controlled server. No user interaction is required,” Microsoft explained. - [GoBruteforcer: New Golang-Based Malware Breaches Web Servers Via Brute-Force Attacks](https://firsthackersnews.com/gobruteforcer/): A recently identified Golang-based botnet is targeting web servers running FTP, MySQL, phpMyAdmin, and Postgres services, Palo Alto Networks reports. - [Clop ransomware: Breached companies via GoAnywhere MFT zero-day](https://firsthackersnews.com/clop-ransomware-goanywhere/): The gang behind it Clop ransomware has begun extorting companies whose data were stolen thanks to the use of a zero-day vulnerability in your file sharing solution Fortra GoAnywhere MFT. - [Xenomorph Android malware: Now stealing data from 400 banks](https://firsthackersnews.com/xenomorph-android-malware-now-stealing-data-from-400-banks/): A new version of the Xenomorph Android malware has been released with increased malicious capabilities, such as the Automatic Transfer System framework and the ability to steal credentials from 400 banks. Now equipped with these powerful tools, it can carry out even more damaging attacks on unsuspecting victims. - [Proof-of-Concept released for critical Microsoft Word RCE bug](https://firsthackersnews.com/proof-of-concept-released-for-critical-microsoft-word-rce-bug/): A PoC exploit for CVE-2023-21716, a critical RCE vulnerability in Microsoft Word that can be exploited when the user previews a specially crafted RTF document, is now publicly available. - [Google Is Giving VPN Access to Every Google One Subscriber](https://firsthackersnews.com/google-is-giving-vpn-access/): Google VPN is helpful if you need to hop onto the net from another IP. While it doesn't offer as many customization options as ExpressVPN (which allows users to connect through another country), using it still comes with some drawbacks – like Google tracking your data even when you switch between sites . - [Dangerous emotet botnet resumes email activity](https://firsthackersnews.com/emotet-botnet/): Successful compromises by the notorious Emotet malware are occurring again. After several months of inactivity, the botnet resumed its email activity on 07.03.2023.  - [The rise of phishing scams and how to avoid them](https://firsthackersnews.com/the-rise-of-phishing-scams/): Cybersecurity scams continue to be on the rise. As scammers get smarter, it’s important to stay up to date on the latest trends. One of the best things you can do for yourself is to be able to recognize the signs of a potential phishing scam and how to avoid them.  - [Apple iOS 16.4: new features!](https://firsthackersnews.com/apple-update/): Apple is in the process of being finalized iOS 16.4 for its official public release this spring! If all goes according to plan, users can expect access to a variety of new and improved features on iPhone them in either March or April.  - [Google announces new features for Android and Wear OS](https://firsthackersnews.com/google-feature/): Google has announced a slew of new features for Android, Chromebook and Wear OS that are designed to improve connectivity, productivity and accessibility.  - [DoppelPaymer ransomware: Two key gang members targeted by authorities](https://firsthackersnews.com/doppelpaymer/): An international law enforcement operation has led to the arrests of suspected core members of the prolific DoppelPaymer ransomware operation. - [Aruba Networks fixes six critical vulnerabilities in ArubaOS](https://firsthackersnews.com/aruba-network-vulnerability/): Aruba Networks has issued a security advisory addressing six critical vulnerabilities that exist in various versions of its proprietary operating system – ArubaOS. - [Bitdefender releases MortalKombat decryptor to help recover your files](https://firsthackersnews.com/mortalkombat-decryptor/): Cybersecurity company Bitdefender has recently announced the release of a new decryptor for the MortalKombat ransomware. The decryptor is now available for download and can help victims of ransomware to recover their encrypted files without having to pay the ransom. - [New Exfiltrator-22 post-exploitation kit linked to LockBit ransomware](https://firsthackersnews.com/new-exfiltrator-22/): Exfiltrator-22 is a new post-exploitation kit that can spread ransomware undetected. Researchers speculate that the creators of this kit are former LockBit 3.0 affiliates, experts in anti-analysis and defense evasion. - [Critical vulnerabilities in Houzez WordPress theme lead to privilege escalation attacks](https://firsthackersnews.com/wordpress-houzez-theme/): Two critical severity vulnerabilities in the Houzez theme and plugin for WordPress are actively being exploited to hijack websites. The vulnerabilities, tracked as CVE-2023-26540 and CVE-2023-26009 are both privilege escalation flaws having a CVSS severity rating of 9.8 out of 10, classifying them as critical threats that need immediate attention.  - [Beware! New WhiteSnake Malware Attack Windows & Linux Users](https://firsthackersnews.com/whitesnake-malware/): Below is a list of the prices for WhiteSnake Stealer with their respective validity:- - [Hydrochasma hackers target medical research labs](https://firsthackersnews.com/hydrochasma-hackers/): Dubbed "Hydrochasma" by Symantec cybersecurity researchers, the threat actor appears to have had a possible interest in industries connected with COVID-19 treatments or vaccines. - [VMware Fixes Critical Vulnerability in Carbon Black App Control (CVE-2023-20858)](https://firsthackersnews.com/carbon-black-app-control/): VMware has fixed a critical vulnerability (CVE-2023-20858) in Carbon Black App Control, its enterprise solution for preventing untrusted software from executing on critical systems and endpoints. - [Exploit released for critical Fortinet RCE flaws, patch now](https://firsthackersnews.com/fortinet-rce-flaws/): Security researchers have released a proof-of-concept exploit for a critical vulnerability (CVE-2022-39952) in Fortinet's FortiNAC network access control suite. - [New Stealc malware emerges with a wide set of stealing capabilities](https://firsthackersnews.com/stealc-malware/): A new information stealer advertised as "Stealc" has been discovered by Sekoia researchers. - [Samsung has created a zero-click antivirus for messages](https://firsthackersnews.com/samsung-has-created-a-zero-click/): Samsung has introduced a new Message Guard security feature for its Galaxy range of smartphones and tablets that can better protect users against “zero-click” cyberattacks disguised as image attachments in messages.  - [Coinbase cyberattack targeted employees with fake SMS alert](https://firsthackersnews.com/coinbase-cyberattack/): A sneaky cyber attack has recently surfaced with the aim of deceiving Coinbase employees through fake SMS alerts. - [GODADDY CLAIMS HACKERS STOLE SOURCE CODE AND PUT MALWARE ON ITS SERVERS](https://firsthackersnews.com/godaddy-hackers-stole-data/): GoDaddy, a web hosting company, has disclosed that during a multi-year period, hackers broke into its systems, planted malware on its network, and stole some of its source code. - [Fuser-master: Compromises WordPress Sites](https://firsthackersnews.com/fuser-master/): Fuser-master is an innovation tool which generates a specialized URL. When users click on it, they will automatically be taken to the legitimate blog alongside a popunder page displayed in the background. This popup from an external page has the ability to display a variety of advertisements. - [Microsoft Exchange ProxyShell flaws exploited in new crypto-mining attack](https://firsthackersnews.com/proxyshellminer-malware/): ProxyShellMiner is being distributed to Windows endpoints by a very elusive malware operation, according to Morphisec. - [Cloudflare Thwarts Largest DDoS Attack on Record: 71M Requests](https://firsthackersnews.com/cloudflare-thwarts/): Cloudflare stated that it had managed to mitigate multiple “hyper-volumetric” DDoS attacks that originated from more than 30,000 IP addresses. - [Microsoft Patch Tuesday February: Fixes over 75 vulnerabilities](https://firsthackersnews.com/microsoft-patch-2/): Microsoft released it Patch Tuesday for February 2023 correcting over 75 security vulnerabilities, which include all three zero-day bugsthat have been used in attacks. - [RedEyes: Uses M2RAT malware to steal data from Windows and phones](https://firsthackersnews.com/m2rat-malware/): RedEyes Hacking Group (aka APT37), a threat group known for its cyber espionage activities, has recently adopted a new tactic in its efforts to collect intelligence from targeted individuals.  - [MortalKombat ransomware: Targets systems in the US](https://firsthackersnews.com/mortalkombat-ransomware/): Hackers running a new financially motivated campaign are using a variant of the Xortist ransomware called 'MortalKombat', along with the Laplas clipper in cyberattacks. - [7 Types of Social Engineering Attacks Targeting You](https://firsthackersnews.com/social-engineering-attacks/): Social engineering has been an observable phenomenon since the beginning of history. People with something to gain have always found avenues to manipulate others’ fears or willingness to trust. In the modern world, social engineering attacks most frequently take place over the telephone or internet. - [Malicious PyPi packages contained the W4SP Stealer malware](https://firsthackersnews.com/malicious-pypi/): Five malicious packages were found on the Python Package Index (PyPI), stealing passwords, Discord authentication cookies, and cryptocurrency wallets from unsuspecting developers. - [Patch Released for CVE-2023-25194 RCE Vulnerability in Apache Kafka](https://firsthackersnews.com/cve-2023-25194/): Tracked as CVE-2023-25194, Apache Kafka could allow a remote authenticated attacker to execute arbitrary code on the system, caused by an unsafe deserialization when configuring the connector via the Kafka Connect REST API. - [Linux Variant of Cl0p Ransomware Emerges](https://firsthackersnews.com/linux-variant-of-cl0p-ransomware-emerges/): Cl0p ransomware (a.k.a. CLOP) is part of the Cryptomix ransomware family and has been active since 2019. It has targeted cybersecurity compliance firm Qualys and several health services and organizations over the years.  - [ESXiArgs Ransomware Attack Targets VMware Servers Worldwide](https://firsthackersnews.com/esxiargs-ransomware/): The vulnerability, tracked as CVE-2021-21974, is caused by a stack overflow issue in the OpenSLP service that unauthenticated threat actors in low-complexity attacks can exploit.  - [Clop ransomware for Linux: Flaw allows file recovery](https://firsthackersnews.com/clop-ransomware/): The Clop ransomware operation now also uses a variant of the malware that only targets Linux servers, but a flaw in the encryption system allows victims to recover their files without paying a ransom. - [Google Fi data breach let hackers perform SIM swapping](https://firsthackersnews.com/google-fi-data-breach/): Google Fi, Google’s U.S.-only telecommunications and mobile internet service, has notified customers that personal data was exposed by a data breach at one of its primary network providers. Some of them were also warned that it allowed SIM swapping attacks. - [New HeadCrab Malware Hijacks 1,200 Redis Servers](https://firsthackersnews.com/headcrab-malware/): When using HeadCrab malware on these Redis servers, threat actors rely on them not enabling authentication by default. Once threat actors gain access to Redis servers, they issue a “slaveof” command to connect to an attacker-controlled master server and install the HeadCrab malware on the infected system.  - [Hackers Use New IceBreaker Malware to Breach Gaming Companies](https://firsthackersnews.com/icebreaker/): Hackers have been targeting online gaming and gambling companies with what appears to be a previously unseen backdoor that researchers have named IceBreaker.  - [New SH1MMER Exploit for Chromebook Unenrolls Managed ChromeOS Devices](https://firsthackersnews.com/sh1mmer-exploit/): A new exploit called ‘Sh1mmer’ can be used to “unenrolling” enterprise-managed Chromebooks to install apps and bypass device restrictions. - [Attacks Targeting Realtek SDK Vulnerability Ramping Up](https://firsthackersnews.com/realtek-sdk-vulnerability/): Palo Alto Networks warns of an increase in cyberattacks targeting CVE-2021-35394, a remote code execution (RCE) vulnerability in the Realtek Jungle SDK. - [Yandex Code Repositories Leaked Allegedly by Former Employee](https://firsthackersnews.com/yandex-code-repositories/): The threat actor has dumped a whopping 44.7 GB worth of Yandex data, including its source code repository, on a popular hacker forum. - [VMware Patches Critical RCE Vulnerabilities in vRealize Log Insight](https://firsthackersnews.com/vmware-patch/): VMware addresses multiple vulnerabilities, including two rated as critical, in the vRealize Log Insight product. - [Remote Code Execution Vulnerability in Microsoft Teams](https://firsthackersnews.com/remote-code-execution/): Researchers discovered an RCE vulnerability in Microsoft Teams during Pwn2Own 2022. The application is used by a wide range of people, including professionals, and an exploit could cause significant harm to its users.  - [Chinese Hackers Exploited Recent Fortinet Flaw as 0-Day to Drop Malware](https://firsthackersnews.com/backdoor-boldmove/): The attacks entailed the use of a sophisticated backdoor dubbed BOLDMOVE, a Linux variant of which is specifically designed to run on Fortinet's FortiGate firewalls. - [Samsung Galaxy Store App Found Vulnerable to Sneaky App Installs and Fraud](https://firsthackersnews.com/samsung-app-vulnerable/): Two new vulnerabilities have been found in the Galaxy App Store application allowing local attackers to install arbitrary applications or execute JavaScript by launching a specific web page. - [CISA Warns for Vulnerabilities in Industrial Control Systems (ICS)](https://firsthackersnews.com/cisa-vulnerabilities/): The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has released several Industrial Control Systems (ICS) advisories warning of critical security flaws affecting products from Sewio, InHand Networks, Sauter Controls, and Siemens. - [New Backdoor Created Using Leaked CIA’s Hive Malware Discovered in the Wild](https://firsthackersnews.com/new-backdoor-created-using-leaked-cias/): This new variant of the HIVE kit, named Xdr33, mainly functions as a backdoor. It collects sensitive information and provides a foothold for subsequent intrusions. - [Attackers Infected a CircleCI Employee with Malware to Steal Customer Session Tokens](https://firsthackersnews.com/attackers-infected-a-circleci-employee/): Software development service CircleCI has revealed that a recently disclosed data breach was the result of information stealer malware being deployed on an engineer’s laptop. - [RAT malware campaign tries to evade detection using polyglot files](https://firsthackersnews.com/rat-malware-polyglot-files/): Operators of the StrRAT and Ratty distant entry trojans (RAT) are operating a brand new marketing campaign utilizing polyglot MSI/JAR and CAB/JAR information to evade detection from safety instruments. - [Cacti Patched CVE-2022-46169 Critical RCE Vulnerability](https://firsthackersnews.com/cacti-vulnerability/): Open-source, web-based network monitoring and graphing tool Cacti received an update recently to fix a critical-severity security vulnerability that enabled executing arbitrary code on a server running Cacti. - [Expert Analysis Reveals Cryptographic Weaknesses in Threema Messaging App](https://firsthackersnews.com/threema-messaging-app/): A comprehensive analysis of the cryptographic protocols used in the Swiss encrypted messaging application Threema has revealed a number of loopholes. - [Microsoft ends Windows 7 extended security updates on Tuesday](https://firsthackersnews.com/microsoft-ends-windows-7/): Windows 7 Professional and Enterprise editions will no longer receive extended security updates for critical and important vulnerabilities starting Tuesday, January 10, 2023. - [Russian Turla Hackers Hijack Decade-Old Malware Infrastructure to Deploy New Backdoors](https://firsthackersnews.com/russian-turla-hackers/): Organisations that fell victim to Andromeda, a commodity malware that dates back 12 years, seem to be at risk of compromise by the Moscow-backed advanced persistent threat (APT) group tracked variously as UNC2410 or Turla, according to Mandiant, which has observed the group reactivating second-hand command and control (C2) infrastructure in a year-long campaign against Ukrainian targets. - [Hackers Using CAPTCHA Bypass Tactics in Freejacking Campaign on GitHub](https://firsthackersnews.com/captcha-bypass-tactics/): Unit 42 also found that some of the automated account creation cases bypassed CAPTCHA images using simple image analysis technique and identified the creation of more than 130,000 user accounts created on cloud. - [Synology Fixes a Max Severity RCE Vulnerability in VPN Server Products](https://firsthackersnews.com/cve-2022-43931/): "Taiwan-based NAS maker Synology has addressed a maximum (10/10) severity vulnerability affecting routers configured to run as VPN servers.The vulnerability, tracked as CVE-2022-43931, was discovered internally by Synology's Product Security Incident Response Team (PSIRT) in the VPN Plus Server software and was given a maximum CVSS3 Base Score of 10 by the company - [RCE Vulnerability (CVE-2022-45359) in Yith WooCommerce Gift Cards Plugin Exploited in Attacks](https://firsthackersnews.com/cve-2022-45359-vulnerability/): Hackers are actively exploiting a critical vulnerability, tracked as CVE-2022-45359 (CVSS v3: 9.8), affecting the WordPress plugin YITH WooCommerce Gift Cards Premium. - [PyTorch Machine Learning Framework Compromised with Malicious Dependency](https://firsthackersnews.com/pytorch-framework-compromised/): The PyTorch team has issued a warning to users who installed PyTorch-nightly over the holidays, advising them to uninstall the framework and the counterfeit 'torchtriton' dependency. - [Thousands of Citrix Servers Still Unpatched for Critical Vulnerabilities](https://firsthackersnews.com/thousands-of-citrix-servers-still-unpatched/): Two critical vulnerabilities tracked as CVE-2022-27510 and CVE-2022-27518 still affect thousands of Citrix Application Delivery Controller (ADC) and Gateway devices, NCC Group’s Fox IT team said in a blog post. - [APT Hackers Turn to Malicious Excel Add-ins as Initial Intrusion Vector](https://firsthackersnews.com/apt-hackers-excel-add-in/): Now according to Cisco Talos, advanced persistent threat (APT) actors and commodity malware families alike are increasingly using Excel add-in (.XLL) files as an initial intrusion vector. - [Critical Linux Kernel Vulnerability Let Attackers Execute Remote Code](https://firsthackersnews.com/linux-vulnerability/): A critical remote code execution vulnerability (CVE-2022-47939) has been identified in the ksmbd module of the Linux kernel. - [PrivateLoader PPI Service Found Distributing Info-Stealing RisePro Malware](https://firsthackersnews.com/private-loader/): PrivateLoader is an active malware in the loader market, used by multiple threat actors to deliver various payloads, mainly information stealer.  - [GuLoader Malware Utilizing New Techniques to Evade Security Software](https://firsthackersnews.com/guloader-malware/): Cybersecurity researchers exposed new evasion techniques adopted by an advanced malware downloader called GuLoader. - [CVE-2022-47633 Vulnerability Allows Attackers to Bypass Kyverno Signature Verification](https://firsthackersnews.com/cve-2022-47633/): Kyverno’s admission controller offers a signature verification mechanism to ensure that only signed container images can enter a Kubernetes cluster.  - [Vice Society Ransomware Attackers Adopt Robust Encryption Methods](https://firsthackersnews.com/vice-society-ransomware/): SentinelLabs disclosed that the Vice Society group has adopted a new custom-branded ransomware payload in recent intrusions, dubbed ‘PolyVice,’ which implements an encryption scheme, using NTRUEncrypt and ChaCha20-Poly1305 algorithms. - [LastPass Admits to Severe Data Breach, Encrypted Password Vaults Stolen](https://firsthackersnews.com/lastpass-brach/): LastPass has confirmed that cybercriminals stole its customers’ encrypted password vaults, which store its customers’ passwords and other secrets, in a data breach earlier this year. - [ProxyNotShell Vulnerabilities Being Actively Exploited (CVE-2022-41040 and CVE-2022-41082)](https://firsthackersnews.com/proxynotshell-vulnerability/): Reports says, the zero-day vulnerabilities CVE-2022-41040 and CVE-2022-41082, dubbed ProxyNotShell, are still being actively exploited. - [Raspberry Robin Worm Strikes Again, Targeting Telecom and Government Systems](https://firsthackersnews.com/raspberry-robin-worm-targets-telcos-governments/): Researchers at Trend Micro have been tracking Raspberry Robin since September and are warning the worm is notable for its 10 layers of obfuscation and its ability to deploy a fake payload to throw off detection efforts. - [Cybercriminals Launch New BrasDex Android Trojan Targeting Brazilian Banking Users](https://firsthackersnews.com/brasdex-android-trojan/): The threat actors behind the Windows banking malware known as Casbaneiro has been attributed as behind a novel Android trojan called BrasDex that has been observed targeting Brazilian users. - [Malicious PyPI package posed as SentinelOne SDK to serve info-stealing malware](https://firsthackersnews.com/malicious-pypi-package-posed-as-sentinelone/): Cybersecurity researchers at ReversingLabs have discovered a new malicious package, named ‘SentinelOne,’ on the Python Package Index (PyPI) repository that impersonates a legitimate software development kit (SDK) for SentinelOne. - [Apple patches active exploit vulnerability for iPhones](https://firsthackersnews.com/apple-patch-webkit/): Apple has confirmed that an iPhone software update it released two weeks ago fixed a zero-day security vulnerability that it now says was actively exploited. - [Microsoft Reevaluates SPNEGO NEGOEX Vulnerability CVE-2022-37958 as Critical](https://firsthackersnews.com/microsoft-reevaluates-spnego-negoex-vulnerability/): A critical remote code execution vulnerability has been discovered in the SPNEGO (Simple and Protected GSS-API Negotiation Mechanism). - [Microsoft CVE-2022-44693: Microsoft SharePoint Server Remote Code Execution Vulnerability](https://firsthackersnews.com/cve-2022-44693/): Microsoft on Tuesday released patches for 48 vulnerabilities in seven Microsoft product families. This includes 6 Critical-class issues affecting Microsoft Dynamics, SharePoint, and Windows. - [Fortinet Released Patch for FortiOS SSL-VPN RCE Vulnerability CVE-2022-42475](https://firsthackersnews.com/fortinet-released-patch/): Fortinet has released a patch for a critical zero-day security vulnerability affecting its FortiOS SSL-VPN product. The vulnerability could lead to remote code execution and is actively exploited. - [Amazon ECR Public Gallery flaw could have wiped or poisoned any image](https://firsthackersnews.com/amazon-ecr-public-gallery/): Security flaw has been disclosed in Amazon Elastic Container Registry (ECR) Public Gallery that could have been potentially exploited according to cloud security firm Lightspin. - [MegaRAC flaws, IP leak impact multiple server brands](https://firsthackersnews.com/megarac/): Research team has found three different vulnerabilities in the MegaRAC Baseboard Management Controller (BMC) software. - [Cryptocurrency Mining Campaign Hits Linux Users with Go-based CHAOS Malware](https://firsthackersnews.com/chaos-rat/): The CHAOS RAT, once downloaded and launched, transmits detailed system metadata to a remote server, while also coming with capabilities to carry out file operations, take screenshots, shutdown and restart the computer, and open arbitrary URLs. - [Researchers Uncover New Drokbk Malware that Uses GitHub as a Dead Drop Resolver](https://firsthackersnews.com/drokbk-malware/): Secureworks Counter Threat Unit (CTU) researchers are investigating the Drokbk malware, which is operated by a subgroup of the Iranian government-sponsored COBALT MIRAGE threat group. - [Researchers Uncover Darknet Service Allowing Hackers to Trojonize Legit Android Apps](https://firsthackersnews.com/researchers-uncover-darknet-service-allowing-hackers-to-trojonize-legit-android-apps/): Researchers have shed mild on a new hybrid malware campaign targeting the two Android and Windows running programs in a bid to broaden its pool of victims. - [Lazarus group uses fake cryptocurrency apps to plant AppleJeus malware](https://firsthackersnews.com/applejeus-malware/): Lazarus hacking group spreads malware using a fake cryptocurrency app called BloxHolder. This made-up brand pretends to offer cryptocurrency applications, tricking users to install AppleJeus malware. - [New Go-based Zerobot Botnet Exploiting Dozen of IoT Vulnerabilities to Expand its Network](https://firsthackersnews.com/zerobot-botnet/):  Zerobot has been observed in the wild proliferating by taking advantage of nearly two dozen security vulnerabilities in the internet of things (IoT) devices and other software. It contains several modules, including self-replication, attacks for different protocols, and self-propagation. It also communicates with its command-and-control server using the WebSocket protocol.  - [Critical Ping bug potentially allows remote hack of FreeBSD systems](https://firsthackersnews.com/freebsd-bug/): A critical stack-based buffer overflow bug, tracked as CVE-2022-23093, in the ping service can allow to take over FreeBSD systems. - [GoTo’s Cloud Storage and Dev Environment Breached by Hackers](https://firsthackersnews.com/gotos-cloud-storage/): GoTo, maker of the popular virtual meeting and desktop-sharing software, and its affiliate LastPass confirmed on Wednesday that their shared cloud-storage service was hit by unknown hackers. - [LastPass breach affects customer data—but not passwords](https://firsthackersnews.com/lastpass-breach/): Password manager LastPass has told customers that some of their information has been accessed in a cybersecurity breach, but says passwords remain safe. - [Google Accuses Spanish Spyware Vendor of Exploiting Chrome, Firefox, & Windows Zero-Days](https://firsthackersnews.com/google-accuses-spanish-spyware-vendor-of-exploiting-chrome-firefox-windows-zero-days/): Google researchers said on Wednesday they have linked a Barcelona, Spain-based IT company to the sale of advanced software frameworks that exploit vulnerabilities in Chrome, Firefox, and Windows Defender. - [ManageEngine Vulnerability (CVE-2022-40300)](https://firsthackersnews.com/manageengine-vulnerability/): ManageEngine recently patched a SQL injection vulnerability bug in their Password Manager Pro, PAM360, and Access Manager Plus products. - [Google discovers Windows exploit framework used to deploy spyware](https://firsthackersnews.com/windows-exploit-framework-spyware/): A Spanish company that offers “tailor made Information Security Solutions” may have exploited vulnerabilities in Chrome, Firefox and the Microsoft Defender antivirus program to deploy spyware, researchers with Google’s Threat Analysis Group said Wednesday. - [Windows 11 is getting a VPN status indicator in the taskbar](https://firsthackersnews.com/windows11-vpnstatus/): Microsoft already released the big Windows 11 update for the year, 22H2, but the company isn’t slowing down on development. A new feature is now in testing that aims to improve VPNs on Windows. - [Hackers Using Trending TikTok ‘Invisible Challenge’ to Spread Malware](https://firsthackersnews.com/tiktok-malware/): Hackers are always coming up with clever ways to exploit the latest trends, and the latest example leverages a popular TikTok challenge to trick unsuspecting users into installing malware on their devices. - [Amazon addresses vulnerability affecting AWS AppSync](https://firsthackersnews.com/aws-appsync/): The bug allows attackers to abuse AWS’ AppSync service and assume Identity and Access Management (IAM) roles in other AWS accounts. This gives an attacker the opportunity “to pivot into a victim organization and access resources in those accounts,” according to Datadog. - [Patch now! Google Chrome’s GPU code has a zero-day](https://firsthackersnews.com/google-chrome-gpu/): Google has released an important update to Chrome web browser that fixes another zero-day vulnerability.  - [WhatsApp data leak: 500 million user records for sale](https://firsthackersnews.com/whatsapp-data-leak-500-million-user/): The latest WhatsApp data leak has reportedly affected as many as 80 countries, including Russia, Italy, Egypt, Brazil, Spain, and more. The list also includes India. - [Researchers Warn of Cyber Criminals Using Go-based Aurora Stealer Malware](https://firsthackersnews.com/aurora-malware/): Researchers at SEKOIA identified 7 traffers teams on Dark Web forums that announced the availability of the Aurora Stealer in their arsenal, a circumstance that confirms the increased popularity of the malware among threat actors. - [Ducktail Malware Operation Evolves with New Malicious Capabilities](https://firsthackersnews.com/ducktail-malware/): A Vietnam-based hacking operation dubbed "Ducktail" is targeting individuals and companies operating on Facebook's Ads and Business platform. - [Google Chrome extension used to steal cryptocurrency, passwords](https://firsthackersnews.com/venomsoftx-malware/): A Google Chrome extension named "VenomSoftX" is being used to steal cryptocurrency from wallets and breach passwords. The malware has been tracked over 93,000 times so far in 2022. - [New AXLocker Ransomware Steals Victims’ Discord Tokens](https://firsthackersnews.com/axlocker-ransomware/): AXlocker - [Notorious Emotet Malware Returns With High-Volume Malspam Campaign](https://firsthackersnews.com/emotet-malware-campaign/): The Emotet malware-delivery botnet is back after a short hiatus, quickly ramping up the number of malicious emails it's sending and sporting additional capabilities, including changes to its binary and delivering a new version of the IcedID malware dropper. - [Chinese Hackers Using 42,000 Imposter Domains in Massive Phishing Attack Campaign](https://firsthackersnews.com/china-based-42000-phishing-domains/): Fangxiao- The threat actor has been active since at least 2017, and has used more than 42,000 domains in its phishing operation - [North Korean Hackers Targeting Europe and Latin America with Updated DTrack Backdoor](https://firsthackersnews.com/lazarus-group-dtrack/): North Korea-linked APT Lazarus is using a new version of the DTrack backdoor to attack organizations in Europe and Latin America, Kaspersky researchers warn. - [F5 Released Hotfixes for BIG-IP and iControl REST Vulnerabilities](https://firsthackersnews.com/big-ip-vulnerabilities/): The vulnerability CVE-2022-41622 makes BIG-IP and BIG-IQ vulnerable to unauthenticated remote code execution (RCE) via cross-site request forgery due to Big-IP’s SOAP API lacking CSRF protection and other protective measures. - [Critical vulnerability in Spotify’s Backstage discovered, patched](https://firsthackersnews.com/vulnerability-spotify-backstage/): A critical unauthenticated remote code execution vulnerability in Spotify’s Backstage project has been found and fixed, and developers are advised to take immediate action in their environments. - [Windows Kerberos authentication breaks after November updates](https://firsthackersnews.com/windows-kerberos-authentication/): Microsoft on Sunday reported that after installing updates released on the most recent Patch Tuesday on Nov. 8, security teams might have issues with Kerberos authentication on Windows Servers with the Domain Controller role. - [Over 15,000 WordPress Sites Compromised in Malicious SEO Campaign](https://firsthackersnews.com/word-press-site-compromised/): Over 15,000 WordPress and other sites have been redirected to the spam Q&A sites, according to Sucuri. The hackers are using modified WordPress PHP files and, in some cases, their own PHP files to achieve the redirects, with targeted sites on average containing 100 infected files each. - [New “Earth Longzhi” APT Targets Ukraine and Asian Countries with Custom Cobalt Strike Loaders](https://firsthackersnews.com/earth-longzhi/): A new APT group, Earth Longzhi, reportedly targeted organizations in East Asia, Southeast Asia, and Ukraine using a Cobalt Strike loader. The group, active since at least 2020, is considered a subgroup of the state-backed hacking group APT41. - [Warning: New Massive Malicious Campaigns Targeting Top Indian Banks’ Customers](https://firsthackersnews.com/malicious-campaigns-targeting-top-indian-banks-customers/): Trend Micro researchers observed an uptick in attacks targeting bank customers in India, the common entry point being a text message with a phishing link. - [Several Cyber Attacks Observed Leveraging IPFS Decentralized Network](https://firsthackersnews.com/several-cyber-attacks-observed-leveraging-ipfs/): The InterPlanetary File System (IPFS) is a protocol and peer-to-peer network for storing and sharing data. It is designed to enable decentralized storage of resources on the internet. It was built to be resilient against content censorship, meaning that it is not possible to effectively remove content from within the IPFS network once it’s stored there. - [Microsoft November 2022 Patch Tuesday Fixed 11 Critical Vulnerabilities and 6 Zero-Days](https://firsthackersnews.com/microsoft-patch/): Microsoft November 2022 Patch Tuesday has been released with patches for a total of 68 vulnerabilities, which include 6 actively exploited zero days and 11 critical vulnerabilities. - [New Laplas Clipper Malware Targeting Cryptocurrency Users via SmokeLoader](https://firsthackersnews.com/clipboard-hijacker/): Threat actors have developed a new approach to deceive cryptocurrency users. They are using Laplas Clipper, a new feature-rich clipboard stealer that allows hackers to gain more control and insights into target environments. - [Experts Find URLScan Security Scanner Inadvertently Leaks Sensitive URLs and Data](https://firsthackersnews.com/urlscan-security-scanner/): Sensitive URLs to shared documents, password reset pages, team invites, payment invoices and more are publicly listed and searchable on urlscan.io, a security tool used to analyze URLs. - [Robin Banks Phishing Service for Cybercriminals Returns with Russian Server](https://firsthackersnews.com/robin-banks-phishing-service/): A phishing-as-a-service (PhaaS) platform known as Robin Banks has relocated its attack infrastructure to DDoS-Guard, a Russian provider of bulletproof hosting services. - [Researchers Find Links b/w Black Basta Ransomware and FIN7 Hackers](https://firsthackersnews.com/black-basta-ransomware-fin7-hackers/): A new analysis of tools put to use by the Black Basta ransomware operation has identified ties between the threat actor and the FIN7 (aka Carbanak) group. - [OpenSSL Announced Two High-Severity Vulnerabilities Are Fixed](https://firsthackersnews.com/openssl-vulnerabilities/): OpenSSL released patches for two vulnerabilities that have caused widespread concern among cybersecurity experts and researchers over the last week and a half. OpenSSL is a commonly used code library designed to allow secured communication over the internet. - [Dropbox breached, GitHub repositories stolen](https://firsthackersnews.com/dropbox-breached/): File-hosting company Dropbox revealed on Tuesday that it has suffered a phishing incident. Attackers took 130 code repositories using stolen credentials after gaining access to one of Dropbox's GitHub accounts. - [Emotet botnet starts blasting malware again after 5 month break](https://firsthackersnews.com/emotet-botnet-starts-blasting-malware-again/): The malicious program operators have been silent for five months and have now again started to spam emails with malicious programs after the vacation. Emotet is the malware typically spread using phishing email campaigns that rely on Word or Excel documents with malicious pieces. - [A New Rising Social Engineering Trend: Callback Phishing](https://firsthackersnews.com/callback-phishing/): Callback phishing emerged as a hybrid social engineering technique that combines phishing and vishing. The phishing technique used to steal sensitive data or transmit harmful packages via email and vishing. - [Fodcha DDoS Botnet Resurfaces with New Capabilities](https://firsthackersnews.com/fodcha-ddos-botnet/): Researchers have discovered a new version of the Fodcha DDoS botnet, featuring upgrades to deter analysis by security researchers and the ability to inject ransom demands into packets. - [Actively exploited Windows MoTW zero-day gets unofficial patch](https://firsthackersnews.com/motw-zero-day/): A free unofficial patch is available for a Mark-of-the-web (MoTW) security vulnerability impacting Windows 10 and 11, Bleeping Computer reports. - [Chrome issues urgent zero-day fix – update now!](https://firsthackersnews.com/chrome-issues-urgent-zero-day-fix/): Google has announced an update for Chrome issues that fixes an in-the-wild exploit. - [Newly Unsealed Indictment Charges the Operator of Raccoon Infostealer](https://firsthackersnews.com/newly-unsealed-indictment-charges-the-operator-of-raccoon-infostealer/): U.S. officials have charged a Ukrainian national over his alleged role in the Raccoon Infostealer malware-as-a-service operation that infected millions of computers worldwide. - [Microsoft links Raspberry Robin worm to Clop ransomware attacks](https://firsthackersnews.com/raspberry-robin/): Microsoft has discovered recent activity that links the Raspberry Robin worm to human-operated ransomware attacks.  - [Windows 10 KB5018482 update released with nineteen improvements](https://firsthackersnews.com/windows-10-kb5018482-update-released-with-nineteen-improvements/): Despite the release of Windows 11 this early October, there have been updates for Windows 10, still. There are 19 improvements released in the KB5018482 Preview cumulative update for Windows 10 20H2, Windows 10 21H1, and Windows 10 21H2. - [Apple Releases Patch for Exploited Zero-Day](https://firsthackersnews.com/apple-releases-patch-for-exploited-zero-day/): Apple on Monday disclosed and patched a kernel-level zero-day vulnerability affecting many of its iOS devices. - [22 Years Old Vulnerability in SQLite Allows Arbitrary Code Execution](https://firsthackersnews.com/22-years-old-vulnerability-in-sqlite-allows-arbitrary-code-execution/): The security expert Andreas Kellas detailed a high-severity vulnerability, tracked as CVE-2022-35737 (CVSS score: 7.5), in the SQLite database library, which was introduced in October 2000. - [SideWinder APT Using New WarHawk Backdoor to Target Entities in Pakistan](https://firsthackersnews.com/sidewinder-apt/): SideWinder, a prolific nation-state actor mainly known for targeting Pakistan military entities, compromised the official website of the National Electric Power Regulatory Authority (NEPRA) to deliver a tailored malware called WarHawk. - [Ursnif Malware Moving to Ransomware Operations from Bank Account Theft](https://firsthackersnews.com/ursnif-malware/): Ursnif (a.k.a. Gozi), a former banking trojan, has been repurposed as a generic backdoor. Threat actors could use the new variant to distribute ransomware. Ursnif (a.k.a. Gozi), a former banking trojan, has been repurposed as a generic backdoor. Threat actors could use the new variant to distribute ransomware.  - [New Prestige Ransomware Targeting Polish and Ukrainian Organizations](https://firsthackersnews.com/prestige-ransomware/): The Prestige ransomware first appeared in the threat landscape on October 11 in attacks occurring within an hour of each other across all victims. - [Venus Ransomware targets publicly exposed Remote Desktop services](https://firsthackersnews.com/venus-ransomware/): The malicious actors behind the relatively new Venus ransomware are hacking publicly exposed Remote Desktop Services to encrypt Windows devices. - [New Chinese Cyberespionage Group Targeting IT Service Providers and Telcos](https://firsthackersnews.com/chinese-cyberespionage-group/): Telecommunications and IT company providers in the Middle East and Asia are currently being specific by a beforehand undocumented Chinese-talking menace team dubbed WIP19. - [New Chinese Malware Attack Framework Targets Windows, macOS, and Linux Systems](https://firsthackersnews.com/chinese-malware-attack/): A beforehand undocumented command-and-manage (C2) framework dubbed Alchimist is most likely currently being used in the wild to focus on Windows, macOS, and Linux devices. - [Aruba Released Patches for EdgeConnect’s Critical Vulnerabilities](https://firsthackersnews.com/aruba-released-patch/): Aruba addressed multiple critical severity vulnerabilities in the EdgeConnect Enterprise Orchestrator that can be exploited by remote attackers to compromise the vulnerable host. - [Critical RCE Vulnerability with Max CVSS Score in VM2 Sandbox Library](https://firsthackersnews.com/critical-rce-vulnerability/): A critical vulnerability in vm2 might let a remote attacker bypass the sandbox environment and execute shell commands on the device hosting the sandbox.  - [Microsoft Patch Tuesday Fixes New Windows Zero-Day; No Patch for Exchange Server Bugs](https://firsthackersnews.com/microsoft-zero-day/): Microsoft released fixes for a Windows zero-day and a publicly disclosed vulnerability on October Patch Tuesday but security updates for two Exchange Server zero-days discovered last month are still in limbo. - [Researchers Detail Malicious Tools Used by Cyberespionage Group Earth Aughisky](https://firsthackersnews.com/cyberespionage-group-earth-aughisky/): A brand new piece of analysis has detailed the more and more refined nature of the malware toolset employed by a sophisticated persistent risk (APT) group named Earth Aughisky. - [Unpatched RCE Vulnerability in Zimbra Actively Exploited](https://firsthackersnews.com/vulnerability-in-zimbra/): Zimbra-CVE-2022-41352 is an unpatched remote code execution vulnerability in Zimbra Collaboration Suite discovered in the wild due to active exploitation. The vulnerability is due to the method (cpio) in which Zimbra’s antivirus engine (Amavis) scans inbound emails. - [LilithBot Malware, a new MaaS offered by the Eternity Group](https://firsthackersnews.com/lilithbot-malware/): Zscaler researchers linked a recently discovered sample of a new malware called LilithBot to the Eternity group. - [Hackers Can Use ‘App Mode’ in Chromium Browsers’ for Stealth Phishing Attacks](https://firsthackersnews.com/desktop-phishing-page/): That reported, Google is phasing out help for Chrome apps in favor of Progressive Web Applications (PWAs) and web-standard technologies, and the aspect is envisioned to be totally discontinued in Chrome 109 or later on on Windows, macOS, and Linux. - [Details Released for Recently Patched new macOS Archive Utility Vulnerability](https://firsthackersnews.com/macos-vulnerability/): Security researchers have shared facts about a now-addressed security flaw in Apple’s macOS functioning technique that could be possibly exploited to run destructive applications in a manner that can bypass Apple’s security measures - [BlackByte ransomware abuses legit driver to disable security products](https://firsthackersnews.com/blackbyte-ransomware/): The BlackByte ransomware gang is using a new technique that researchers are calling “Bring Your Own Driver,” which enables bypassing protections by disabling more than 1,000 drivers used by various security solutions. - [Experts Warn of New RatMilad Android Spyware Targeting Enterprise Devices](https://firsthackersnews.com/android-spyware/): A novel Android malware referred to as RatMilad has been observed concentrating on a Middle Jap business cell device by concealing by itself as a VPN and phone selection spoofing app. - [Researchers Link Cheerscrypt Linux-Based Ransomware to Chinese Hackers](https://firsthackersnews.com/cheerscrypt-linux-based-ransomware/): The recently learned Linux-Based ransomware pressure acknowledged as Cheerscrypt has been attributed to a Chinese cyber espionage team regarded for working short-lived ransomware techniques. - [Microsoft Exchange server zero-day mitigation can be bypassed](https://firsthackersnews.com/zero-day-mitigation/): Last week, Microsoft confirmed that two zero-day vulnerabilities in Microsoft Exchange recently disclosed by researchers at cybersecurity firm GTSC are being actively exploited in the wild. - [Hackers Exploiting Dell Driver Vulnerability to Deploy Rootkit on Targeted Computers](https://firsthackersnews.com/hackers-exploiting-dell-driver-vulnerability/): The North Korea-backed Lazarus Team has been observed deploying a Windows rootkit by taking gain of an exploit in a Dell firmware driver, highlighting new tactics adopted by the state-sponsored adversary. - [Threat Actors Impersonate GitHub, Zoom, and Cloudflare to Steal User Information](https://firsthackersnews.com/actors-impersonate-github-zoom-and-cloudflare-to-steal-information/): On September 16, GitHub discovered phishing attacks by hackers impersonating CircleCI. During the attack, users are warned of session expiration and directed to log in again using their GitHub credentials. - [Hacking group hides backdoor malware in Windows logo image](https://firsthackersnews.com/bakcdoor-windows-logo/): Security researchers have discovered a malicious campaign by the hacking group ‘Witchetty’, which uses steganography to hide backdoor malware in a Windows logo. - [Researchers Warn of New Go-based Malware Targeting Windows and Linux Systems](https://firsthackersnews.com/go-based-malware/): A new, multi-functional Go-based malware dubbed Chaos has been rapidly growing in volume in recent months to ensnare a wide range of Windows, Linux, small office/home office (SOHO) routers, and enterprise servers into its botnet. - [Sophisticated Covert Cyberattack Campaign Targets Military Contractors](https://firsthackersnews.com/cyberattack-campaign/): A cyberattack campaign, potentially bent on cyber espionage, is highlighting the increasingly sophisticated nature of cyberthreats targeting defense contractors in the US and elsewhere. - [Threat Actors Utilize PowerPoint Files to Distribute Graphite Malware](https://firsthackersnews.com/graphite-malware/): Threat actors started utilizing PowerPoint presentations as a code execution method and delivering Graphite malware in targeted attacks. - [FARGO ransomware targets vulnerable Microsoft SQL servers in new wave of attacks](https://firsthackersnews.com/fargo-ransomware/): Microsoft SQL servers are succumbing to FARGO ransomware, security researchers at AhnLab Security Emergency Response Center (ASEC) have warned. - [China-linked TA413 group targets Tibetan entities with new backdoor](https://firsthackersnews.com/china-linked-ta413/): A China-linked cyberespionage group, tracked as TA413 (aka LuckyCat), is exploiting recently disclosed flaws in Sophos Firewall (CVE-2022-1040) and Microsoft Office (CVE-2022-30190) to deploy a never-before-detected backdoor called LOWZERO in attacks aimed at Tibetan entities. - [BlackCat Ransomware Attackers Spotted Fine-Tuning Their Malware Arsenal](https://firsthackersnews.com/blackcat-ransomware-2/): BlackCat Ransomware attackers fine-tuning their malware arsenal in a bid to remain undercover and expand their reach.  - [CISA Urges to Patch ManageEngine Against RCE Vulnerability](https://firsthackersnews.com/cisa-urges-patch-manageengine/): The US Cybersecurity and Infrastructure Security Agency (CISA) on Thursday added a critical Java deserialisation bug affecting multiple Zoho ManageEngine products to its Known Exploited Vulnerabilities (KEV) catalogue and warned that the flaw has been actively exploited in attacks. - [Hackers Using Malicious OAuth Apps to Take Over Email Servers](https://firsthackersnews.com/hackers-using-malicious-oauth-apps/): Microsoft on Thursday warned of a consumer-facing attack that made use of rogue OAuth applications on compromised cloud tenants to ultimately seize control of Exchange servers and spread spam. - [Record DDoS Attack with 25.3 Billion Requests Abused HTTP/2 Multiplexing](https://firsthackersnews.com/ddos-attack/): Cybersecurity company Imperva has disclosed that it mitigated a dispersed denial-of-company (DDoS) attack with a whole of more than 25.3 billion requests on June 27, 2022. - [Europol and Bitdefender Release Free Decryptor for LockerGoga Ransomware](https://firsthackersnews.com/lockergoga/): Cybersecurity firm Bitdefender published a new decryptor on Friday for LockerGoga, a strain of ransomware best known for its 2019 attack on Norwegian aluminum giant Norsk Hydro. - [Microsoft Teams’ GIFShell Attack](https://firsthackersnews.com/gifshell-attack/): The newly published GIFShell attack method, which occurs through Microsoft Teams, is a perfect example of how threat actors can exploit legitimate features and configurations that haven't been correctly set. - [Trend Micro Warnes for Actively Exploited RCE Flaw in Apex One](https://firsthackersnews.com/trend-micro-apex-one/): Trend Micro recently released a patch for an actively exploited flaw in its endpoint security platform, Apex One. The security software provider published an advisory to report six vulnerabilities and advised their customers to apply the patches immediately.  - [Hackers Had Access to LastPass’s Development Systems for Four Days](https://firsthackersnews.com/hackers-had-access-to-lastpass/): Password management solution LastPass shared more details pertaining to the security incident last month, disclosing that the threat actor had access to its systems for a four-day period in August 2022. - [North Korean Hackers Spreading Trojanized Versions of PuTTY Client Application](https://firsthackersnews.com/putty-trojan/): Researchers believe that hackers with links to North Korean government have been pushing the Trojanized Version of PuTTY networking tool in a bid to hack the networks of organizations they wish to monitor. - [WordPress Sites Compromised Due to FishPig Supply Chain Attack](https://firsthackersnews.com/wordpress-sites-compromised-due-to-fishpig/): Threat actors infected FishPig’s distribution server as part of a supply chain attack. The vendor’s service integrates Adobe’s Magento eCommerce platform into WordPress websites. Attackers injected malicious code into FishPig’s software to access the WordPress websites.  - [Phishing page embeds keylogger to steal passwords as you type](https://firsthackersnews.com/phishing-page-embeds-keylogger/): A novel phishing campaign is underway, targeting Greeks with phishing sites that mimic the state's official tax refund platform and steal credentials as they type them. - [Loader Malware Emotet is Now Led by Quantum and BlackCat](https://firsthackersnews.com/loader-malware-emotet/): Emotet (also known as SpmTools) is a sophisticated, modular banking trojan. Emotetmostly serves as a downloader or dropper of other banking trojans. It is a loader-as-a-service (LaaS). It is mainly distributed by spam emails (malspam). - [Microsoft’s Latest Security Update Fixes 64 New Flaws, Including a Zero-Day](https://firsthackersnews.com/microsofts-latest-security-update-fixes/): Of the 64 bugs, five are rated critical, 57 are rated important, one is rated moderate, and one is rated low in severity. Microsoft earlier this month addressed 16 vulnerabilities in its Chromium-based Edge browser as well as patches. - [Apple Releases iOS and macOS Updates to Patch Actively Exploited Zero-Day Flaw](https://firsthackersnews.com/apple-patch-zero-day/): Apple iPhone, iPad, and Mac security update fixes actively exploited zero-day vulnerability, which allows hackers to carry out cyberattacks. - [Cisco Patches High-Severity Vulnerability in SD-WAN vManage](https://firsthackersnews.com/cisco-patch-vulnerability/): The patches for a high-severity vulnerability in the binding configuration of SD-WAN vManage software containershas been announced by Cisco. The vulnerability tracked as CVE-2022-20696, the issue exists because of insufficientprotection mechanisms on messaging server container ports, allows an unauthenticated attacker to connect to anaffected system using these ports. - [Lampion Banking Malware Reappears in WeTransfer Phishing Attacks](https://firsthackersnews.com/lampion-banking-malware/): Lampion malware operators use the free file-sharing platform WeTransfer to perform phishing attacks. This way, attackers can avoid security alerts since they are tricking users into downloading from a trustworthy service.  - [High-Severity Firmware Security Flaws Left Unpatched in HP Enterprise Devices](https://firsthackersnews.com/high-severity-firmware-security-flaws/): A set of six high-severity firmware vulnerabilities impacting a broad range of HP Enterprise devices are still waiting to be patched, although some of them were publicly disclosed since July 2021. - [Hackers Exploit Zero-Day in WordPress BackupBuddy Plugin in ~5 Million Attempts](https://firsthackersnews.com/hackers-exploit-zero-day/): A zero-day flaw in a WordPress plugin known as BackupBuddy is being actively exploited, WordPress safety firm Wordfence has disclosed. - [North Korean Lazarus hackers take aim at U.S. energy providers](https://firsthackersnews.com/lazarus-hackers/): The North Korean state-sponsored crime ring Lazarus Group is behind a new cyberespionage campaign with the goal to steal data and trade secrets from energy providers across the US, Canada and Japan, according to Cisco Talos. - [Cisco Released Patches for Vulnerabilities Affecting Several Products](https://firsthackersnews.com/cisco-patch-update/):  Cisco has released updates to address vulnerabilities affecting multiple products. - [The North Face Warns of Major Credential Stuffing Campaign](https://firsthackersnews.com/credential-stuffing/): Outdoor clothing giant The North Face has notified customers that their account may have been compromised, after noticing unusual activity on its website last month. - [North Korean Hackers Deploying New MagicRAT Malware in Targeted Campaigns](https://firsthackersnews.com/new-magicrat-malware/): The Lazarus Group, a well-known North Korean nation-state actor, has been connected to the MagicRAT remote access trojan. - [New Stealthy Shikitega Malware Targeting Linux Systems and IoT Devices](https://firsthackersnews.com/shikitega-malware/): Dubbed Shikitega, the malware targets endpoints and Internet of Things devices that run on Linux operating systems and has been detailed by cybersecurity researchers at AT&T Alien Labs. - [QNAP Fixes Zero-Day Recently Leveraged by DeadBolt Ransomware](https://firsthackersnews.com/zero-day-vulnerability/): The Taiwanese company QNAP cautions customers about DeadBolt ransomware attacks upon exploiting a zero-day vulnerability in Photo Station. QNAP detected the issue on September 3.  - [New EvilProxy Phishing Service Allowing Cybercriminals to Bypass 2-Factor Security](https://firsthackersnews.com/evilproxy-phishing/): A new Phishing-as-a-Service (PhaaS) named EvilProxy (also known as Moloch) was seen for sale in dark web forums, according to the Resecurity team. - [SharkBot malware found on Google Play Store stealing login info again](https://firsthackersnews.com/sharkbot-malware-found-on-google-play-store-again/): The notorious Android banking trojan known as SharkBot has once again made an appearance on the Google Play Store by masquerading as antivirus and cleaner apps. - [Critical RCE Vulnerability in the Atlassian Bitbucket Server and Data Center](https://firsthackersnews.com/vulnerability-atlassians-bitbucket-server/): A Vulnerability has been discovered in Atlassian Bitbucket Server and Data Center which could allow for remote code execution. Bitbucket is a Git-based source code repository hosting service owned by Atlassian. - [Apple Releases iOS Update for Older iPhones to Fix Actively Exploited Vulnerability](https://firsthackersnews.com/apple-releases-ios-12-5-6-update/): Which Apple iOS devices are impacted? - [New Golang-based ‘Agenda Ransomware’ Can Be Customized For Each Victim](https://firsthackersnews.com/agenda-ransomware/): Cybersecurity company Trend Micro is raising the alarm on a new ransomware family called Agenda, which has been used in attacks on organizations in Asia and Africa. - [Google Launches New Open Source Bug Bounty to Tackle Supply Chain Attacks](https://firsthackersnews.com/google-launches-major-open-source/): Google on Tuesday announced it's launching a new bug bounty program that focuses specifically on open-source software.  - [Microsoft Uncovers New Post-Compromise Malware Used by Nobelium Hackers](https://firsthackersnews.com/microsoft-uncovers-newcompromisedmalware/): Nobelium was responsible for the SolarWinds breach, disclosed by Microsoft and FireEye (now known as Mandiant) in December 2020.  - [Okta Hackers Behind Twilio and Cloudflare Breach Hit Over 130 Organizations](https://firsthackersnews.com/okta-hackers/): Now, cybersecurity company Group-IB says the attack on Twilio was part of a wider campaign by the hacking group it’s calling “0ktapus,” a reference to how the hackers predominantly target organizations that use Okta as a single sign-on provider. - [LastPass developer systems hacked to steal source code](https://firsthackersnews.com/lastpass-developer/): Password management firm LastPass was hacked last week, allowing threat actors to steal the company’s source code and proprietary technical information. - [Crypto Miners Using Tox P2P Messenger as Command and Control Server](https://firsthackersnews.com/crypto-miners/): Threat actors have begun to make use of the Tox peer-to-peer on the spot messaging service as a command-and-control methodology, marking a shift from its earlier function as a contact methodology for ransomware negotiations. - [Hackers Using Fake DDoS Protection Pages to Distribute Malware](https://firsthackersnews.com/fake-ddos-protection-pages/): Recently security experts from Sucuri, spotted JavaScript injections targeting WordPress sites to display fake DDoS Protection pages which lead victims to download remote access trojan malware. - [GitLab Issues Patch for Critical Flaw in its Community and Enterprise Software](https://firsthackersnews.com/gitlab-issue-patch/): GitLab released patches where they fixed a critical remote code execution vulnerability. It is labeled CVE-2022-2884 with a CVSS score of 9.9. This critical vulnerability in the GitHub Import API can be exploited by an attacker who has successfully obtained authentication. - [Meet Borat RAT, a New Unique Triple Threat](https://firsthackersnews.com/borat-rat-malware/): Atlanta-based mostly cyber risk intelligence corporation, Cyble found out a new Remote Accessibility Trojan (RAT) malware. - [New Grandoreiro Banking Malware Campaign Targeting Spanish Manufacturers](https://firsthackersnews.com/grandoreiro-banking-malware/): Organizations in the Spanish-speaking nations of Mexico and Spain are in the crosshairs of a new campaign designed to deliver the Grandoreiro banking trojan. - [Apple security updates fix 2 zero-days used to hack iPhones, Macs](https://firsthackersnews.com/apple-security-updates/): Apple has launched emergency safety updates at the moment to repair two zero-day vulnerabilities beforehand exploited by attackers to hack iPhones, iPads, or Macs. - [Windows KB5012170 update causing BitLocker recovery screens, boot issues](https://firsthackersnews.com/windows-kb5012170-updatae/): Windows users who have installed a new KB5012170 security update for Secure Boot have encountered various issues, ranging from boots failing with BitLocker Recovery prompts to performance issues. - [Researchers found one-click exploits in Discord and Teams](https://firsthackersnews.com/one-click-exploit/): A group of security researchers found a series of vulnerabilities in the software underlying popular apps like Discord, Microsoft Teams, Slack and many others, which are used by tens of millions of people all over the world. - [Chinese Hackers Backdoored MiMi Chat App to Target Windows, Linux, macOS Users](https://firsthackersnews.com/chinese-hackers-backdoored-mimi-chat-app/): Reports from cybersecurity firms SEKOIA and Trend Micro confirm that a new effort by the Chinese threat actor Lucky Mouse involves using a trojanized version of a cross-platform messaging software to backdoor devices.  - [SOVA malware adds ransomware feature to encrypt Android devices](https://firsthackersnews.com/sova-malware/): Sova malware adds new features that make it more dangerous to a wider range of Android payment and banking app users. - [Palo Alto Networks: New PAN-OS DDoS flaw exploited in attacks](https://firsthackersnews.com/pan-os-ddos/): Threat actors are exploiting a vulnerability, tracked as CVE-2022-0028 a high severity issue in Palo Alto Networks devices running the PAN-OS to launch reflected amplification denial-of-service attacks. - [Researchers Warn of Ongoing Mass Exploitation of Zimbra RCE Vulnerability](https://firsthackersnews.com/zimbra-rce-vulnerability/): “CVE-2022-27925 was originally mentioned as an RCE exploit necessitating authentication,” Volexity reported. “When merged with a individual bug, nonetheless, it became an unauthenticated RCE exploit that manufactured remote exploitation trivial.” - [Cisco hacked by Yanluowang ransomware gang, 2.8GB allegedly stolen](https://firsthackersnews.com/yanluowang-ransomware/): Cisco confirmed today that the Yanluowang ransomware group infiltrated its corporate network in late May and that the actor attempted to blackmail them, threatening to leak stolen files online. - [Experts Uncover Details on Maui Ransomware Attack by North Korean Hackers](https://firsthackersnews.com/maui-ransomware-attack/): The first-ever incident possibly linked to the ransomware family known as Maui occurred on April 15, 2021, and targeted an unnamed Japanese housing company. - [Windows 11 KB5016629 update fixes Start Menu, File Explorer issues](https://firsthackersnews.com/windows11-kb5016629/): Microsoft has released the Windows 11 KB5016629 cumulative update with security updates, improvements, including fixes for File Explorer and the Start Menu and a new Focus Assist feature. - [Microsoft: Exchange ‘Extended Protection’ needed to fully patch new bugs](https://firsthackersnews.com/microsoft-exchange-extended-protection/): Microsoft says that some of the Exchange Server flaws addressed as part of the August 2022 Patch Tuesday also require admins to manually enable Extended Protection on affected servers to fully block attacks. - [CISA warns of Windows and UnRAR flaws exploited in the wild](https://firsthackersnews.com/cisa-warns-flaws/): The U.S. Cybersecurity and Infrastructure Security Agency has added two more flaws to its catalog of Known Exploited Vulnerabilities, based on evidence of active exploitation. - [New IoT RapperBot Malware Targeting Linux Servers via SSH Brute-Forcing Attack](https://firsthackersnews.com/rapperbot-malware/): A new IoT botnet malware dubbed RapperBot has been noticed promptly evolving its capabilities because it was 1st discovered in mid-June 2022. - [New GwisinLocker ransomware encrypts Windows and Linux ESXi servers](https://firsthackersnews.com/new-gwisinlocker-ransomware/): A new ransomware family called ‘GwisinLocker’ targets South Korean industrial and pharmaceutical companies.  - [Critical RCE vulnerability impacts 29 models of DrayTek routers](https://firsthackersnews.com/critical-rce-vulnerability-draytek/): Researchers at Trellix have discovered a critical unauthenticated remote code execution (RCE) vulnerability impacting 29 models of the DrayTek Vigor series of business routers. - [Russian organizations attacked with new Woody RAT malware](https://firsthackersnews.com/woody-rat-malware/): According to Malwarebytes, one of the Russian organizations which were targeted using this Rat malware is a government-controlled defense corporation. - [VMware Releases Patches for Several New Flaws Affecting Multiple Products](https://firsthackersnews.com/vmware-securityflaws/): VMware on Tuesday released updates to address 10 security flaws affecting several products that could be used by unauthenticated attackers to perform malicious activities. - [VirusTotal Reveals Most Impersonated Software in Malware Attacks](https://firsthackersnews.com/virustotal-reveals-malware-attacks/): Other most impersonated legitimate apps by icon include 7-Zip, TeamViewer, CCleaner, Microsoft Edge, Steam, Zoom, and WhatsApp, an analysis from VirusTotal has revealed. - [Gootkit Loader Resurfaces with Updated Tactic to Compromise Targeted Computers](https://firsthackersnews.com/gootkit-loader/): The operators of the Gootkit access-as-a-service (AaaS) malware have resurfaced with updated techniques to compromise unsuspecting victims. - [North Korean Hackers Using Malicious Browser Extension to Spy on Email Accounts](https://firsthackersnews.com/malicious-browser-extension/): A group of North Korean hackers is using a rogue Microsoft Edge or Chrome plugin to track or access user email accounts. - [Researchers Warns of Increase in Phishing Attacks Using Decentralized IPFS Network](https://firsthackersnews.com/phishing-attacks-using-ipfs/): The decentralized file system solution known as IPFS is becoming the new "hotbed" for hosting phishing sites, researchers have warned. - [LibreOffice Releases Software Update to Patch 3 New Vulnerabilities](https://firsthackersnews.com/libreoffice-softwareupdate/): The team behind LibreOffice has released security updates to fix three security flaws in the productivity software, one of which could be exploited to achieve arbitrary code execution on affected systems. - [Malicious IIS Extensions Gaining Popularity Among Cyber Criminals for Persistent Access](https://firsthackersnews.com/malicious-iis-extensions-gaining-for-persistent-access/): Malicious IIS extensions are less frequently encountered in attacks against servers, with attackers often only using script web shells as the first stage payload. - [Experts Find Similarities Between New LockBit 3.0 and BlackMatter Ransomware](https://firsthackersnews.com/lockbit-ransomware-blackmatter/): Cybersecurity researchers have reiterated similarities involving the hottest iteration of the LockBit ransomware and BlackMatter, a rebranded variant of the DarkSide ransomware strain that closed store in November 2021. - [Windows 11 now blocks RDP brute-force attacks by default](https://firsthackersnews.com/windows-11-now-blocks-rdp/): Recent Windows 11 builds come with the Account Lockout Policy policy enabled by default which will automatically lock user accounts (including Administrator accounts) after 10 failed sign-in attempts for 10 minutes. - [Candiru Spyware Caught Exploiting Google Chrome Zero-Day to Target Journalists](https://firsthackersnews.com/candiru-spyware/): The exploitation was connected to Candiru (aka Saito Tech) by the Czech cybersecurity company Avast. Candiru has a history of using previously undiscovered holes to spread the Windows malware known as DevilsTongue, a modular implant with Pegasus-like capabilities. - [Microsoft Resumes Blocking Office VBA Macros by Default After ‘Temporary Pause’](https://firsthackersnews.com/microsoft-blocking-macros/): Microsoft announced today that it resumed the rollout of VBA macro auto-blocking in downloaded Office documents after temporarily rolling it back earlier this month following user feedback. - [New Linux Malware Framework Lets Attackers Install Rootkit on Targeted Systems](https://firsthackersnews.com/new-linux-malware-framework/): A never ever-in advance of-observed Linux malware has been dubbed a “Swiss Military Knife” for its modular architecture and its functionality to set up rootkits. - [Atlassian fixes critical Confluence hardcoded credentials flaw](https://firsthackersnews.com/atlassian-fixes-critical-flaw/): Atlassian has patched a crucial hardcoded credentials vulnerability in Confluence Server and Information Heart that would let distant, unauthenticated attackers log into weak, unpatched servers. - [Experts Uncover New CloudMensis Spyware Targeting Apple macOS Users](https://firsthackersnews.com/cloudmensis-malware/): The malware, codename CloudMensis by Slovakian cybersecurity company ESET, is said to exclusively use public cloud storage services such as pCloud, Yandex Disk and Dropbox to receive commands from attackers and exfiltrate files. - [Russian Hackers Using DropBox and Google Drive to Drop Malicious Payloads](https://firsthackersnews.com/russian-hackers-using-dropbox-and-google-drive/): What is improved in the newer iterations is the use of cloud companies like Dropbox and Google Travel to conceal their steps and retrieve added malware into target environments. A second edition of the attack observed in late May well 2022 is explained to have tailored further to host the HTML dropper in Dropbox. - [New Air-Gap Attack Uses SATA Cable as an Antenna to Transfer Radio Signals](https://firsthackersnews.com/new-air-gap-attack-uses-sata-cable/): Researchers , have published a paper that demonstrates how a hacker could extract data from an otherwise secure system via its SATA cable.  - [7 Phases of Incident Response](https://firsthackersnews.com/incident-response-steps/): Incident Response :Sensitive data and confidential information are the new gold in the digital age, and cyber criminals are naturally always in pursuit of this goldmine. - [Netwrix Auditor Bug Could Lead to Active Directory Domain Compromise](https://firsthackersnews.com/netwrix-auditor-bug/): Netwrix IT asset tracker and compliance auditor, used across more than 11,500 organizations, contains a critical Insecure Object Deserialization vulnerability that could lead to Active Directory domain compromise. - [Juniper Releases Patches for Critical Flaws in Junos OS and Contrail Networking](https://firsthackersnews.com/juniper-releases-patches-for-critical-flaws/): Juniper Networks this week announced the release of patches for more than 30 vulnerabilities across its portfolio, including severe flaws in Contrail Networking and Junos OS. - [New UEFI firmware flaws impact over 70 Lenovo laptop models](https://firsthackersnews.com/uefi-firmware-flaws/): The UEFI firmware used in several laptops made by Lenovo is vulnerable to three buffer overflow vulnerabilities that could enable attackers to hijack the startup routine of Windows installations. - [Amazon squashes years-old authentication bugs in AWS Kubernetes service](https://firsthackersnews.com/amazon-authentication-bugs-in-aws-kubernetes-service/): AWS fixed three authentication bugs present in one line of code in its IAM Authenticator for Kubernetes, used by the cloud giant's popular managed Kubernetes service Amazon EKS, that could allow an attacker to escalate privileges within a Kubernetes cluster. - [ChromeLoader: New Stubborn Malware Campaign](https://firsthackersnews.com/chromeloader-malware-campaign/): A new browser hijacker/adware campaign named ChromeLoader also known as Choziosi Loader and ChromeBack was discovered. Despite using simple malicious advertisements, the malware became widespread, potentially leaking data from thousands of users and organizations. - [Microsoft: Windows Autopatch is now generally available](https://firsthackersnews.com/microsoft-windows-autopatch/): Microsoft on Monday announced the general availability of a feature called Autopatch that automatically keeps Windows and Office software up-to-date on enrolled endpoints. - [Checkmate Ransomware Targets QNAP SMB Services](https://firsthackersnews.com/checkmate-ransomware/): New Checkmate ransomware has been discovered targeting QNAP NAS devices. Although the attacks are still being investigated, it is known that these new ransomware attacks through SMB services are accessible via the internet. - [TrickBot Gang Shifted its Focus on “Systematically” Targeting Ukraine](https://firsthackersnews.com/trickbot-targeting-ukraine/): The operators of the TrickBot malware have resorted to systematically targeting Ukraine since the onset of the war. - [Hive Ransomware Upgraded to Rust to Deliver More Sophisticated Encryption](https://firsthackersnews.com/hive-ransomware/): Researchers from Microsoft Security have spotted an upgraded version of the ransomware-as-a-service (RaaS) dubbed Hive. - [Researchers Warn of New OrBit Linux Malware That Hijacks Execution Flow](https://firsthackersnews.com/orbit-linux-malware/): A new and entirely undetected Linux threat dubbed Orbit, signally a growing trend of malware attacks towards operating system. - [AsyncRAT being distributed to vulnerable MYSQL servers](https://firsthackersnews.com/asyncrat-mysql/): As AsyncRAT is open-source, it is being distributed in various ways. Recently, it disguised itself as a crack program of commercial software and was distributed via malicious websites. In the past, it was distributed via spam email. - [Researchers Uncover Malicious NPM Packages Stealing Data from Apps and Web Forms](https://firsthackersnews.com/malicious-npm-packages/): Researchers have uncovered a software supply-chain attack involving packages hosted on the Node Package Manager (npm), which is the package manager for the Node.js JavaScript platform. - [Gitlab patches critical RCE bug in latest security release](https://firsthackersnews.com/gitlab-patch/): Gitlab has patched a critical vulnerability that could allow an attacker to execute code remotely. - [Microsoft: Raspberry Robin worm already infected hundreds of networks](https://firsthackersnews.com/raspberry-robin-worm/): Raspberry Robin is a Windows worm discovered by cybersecurity researchers from Red Canary, the malware propagates through removable USB devices. - [Jenkins discloses dozens of zero-day bugs in multiple plugins](https://firsthackersnews.com/jenkins-discloses-zero-day-bugs/): The Jenkins security team announced 34 security vulnerabilities affecting 29 plugins for the Jenkins open-source automation server. 29 of these bugs are zero-days still waiting to be patched. It is a highly popular platform with support for over 1,700 plugins and is used by enterprises worldwide for building, testing, and deploying software. - [AstraLocker 2.0 infects users directly from Word attachments](https://firsthackersnews.com/astralocker-word-document/): AstraLocker 2.0 is a ransomware variant belonging to the Babuk family. It recently released its second major release, and according to threat analysts, its operators are involved in rapid attacks that drop its payload directly from email attachments. - [evilnum hackers return in new operation targeting migration orgs](https://firsthackersnews.com/evilnum-hackers/): The Evilnum hacking group have been targeting European organisations that are involved in international migration, showing renewed signs of malicious activity within the group. - [New ZuoRAT malware targets SOHO routers in North America, Europe](https://firsthackersnews.com/new-zuorat-malware/): A multistage remote access trojan (RAT) named ZuoRAT has been targeting remote workers with the help of small office/ home office (SOHO) routers across North America and Europe since 2020. - [Android Malware Called ‘Revive’ Poses as 2FA App For Spain’s BBVA Bank ](https://firsthackersnews.com/android-malware-revive/): The 2FA application necessary to access BBVA bank accounts in Spain is impersonated by a new Android banking malware called Revive. Instead of aiming to infect consumers of various financial institutions, this trojan has a more targeted strategy that targets the BBVA bank. - [Microsoft Exchange bug abused to hack building automation systems](https://firsthackersnews.com/microsoft-exhcnage-bug/): The threat actors had a considerable number of potential victims to target, seeing that the Dutch Institute for Vulnerability Disclosure (DIVD) found 46,000 servers unpatched against the ProxyLogon flaws one week after Microsoft patched them. - [Critical Security Flaws Identified in CODESYS ICS Automation Software](https://firsthackersnews.com/critical-flaw-affect-codesys/): CODESYS has launched patches to handle as many as 11 safety flaws that, if efficiently exploited, may end in info disclosure and a denial-of-service (DoS) situation, amongst others. - [Attackers exploited a zero-day in Mitel VOIP devices to compromise a network](https://firsthackersnews.com/mitel-voip-zero-day-flaw/): CrowdStrike researchers recently investigated the compromise of a Mitel VOIP appliance as an entry point in a ransomware attack against the network of an organization.  - [Dark Web Profile: Netwalker Ransomware](https://firsthackersnews.com/netwalker-ransomware/): Netwalker ransomware is an example of such a success. - [Malicious Windows ‘LNK’ attacks made easy with new Quantum builder](https://firsthackersnews.com/windows-lnk-attacks-quantum/): Quantum offers UAC bypass, Windows Smartscreen bypass, the ability to load multiple payloads on a single LNK file, post-execution hiding, startup or delayed execution.The . - [Chinese language hackers use ransomware as decoy for cyber espionage](https://firsthackersnews.com/chinese-hackers-cyber-espionage/): Two Chinese language hacking teams conducting cyber espionage and stealing mental property from Japanese and western firms are deploying ransomware as a decoy. - [Google patched 14 vulnerabilities with release of chrome 103](https://firsthackersnews.com/google-chrome-103/): Google announced the release of Chrome 103 to the stable channel with patches for a total of 14 vulnerabilities, including nine reported by external researchers. - [Chinese hackers target script kiddies with info-stealer trojan](https://firsthackersnews.com/nimbda-yahoyah-trojan/): Cybersecurity researchers have discovered a new campaign attributed to the chinese "Tropic Trooper" hacking group. Tropic Trooper was previously observed targeting Philippines, Hong Kong and Taiwan; while the two latest are Chinese-speaking countries. This employs a novel loader called Nimbda and a new variant of the Yahoyah trojan. - [Russian govt hackers hit Ukraine with Cobalt Strike, CredoMap malware](https://firsthackersnews.com/credomap-malware/): The Ukrainian CERT is warning that russian hacking groups are exploiting the Follina code execution vulnerability in new phishing campaigns to install the CredoMap malware and Cobalt Strike beacons. This APT28,targeting users with malware that steals credentials stored in browsers. - [VMware Spring Cloud Function Dos Vulnerability](https://firsthackersnews.com/vmware-spring-cloud/): In Vmware Spring Cloud Function versions 3.2.5 and older unsupported versions, it is possible for a user who directly interacts with framework provided lookup functionality to cause denial of service condition due to the caching issue in Function Catalog component of the framework. At the time of writing of this CVE such interaction is only possible via spring-cloud-function-web module. - [New ToddyCat APT group targets Exchange servers in Asia, Europe](https://firsthackersnews.com/toddycat-apt/): A complicated persistent menace (APT) group dubbed ToddyCat has been focusing on Microsoft Trade servers all through Asia and Europe for greater than a year. - [BRATA Malware Becomes an Advanced Threat](https://firsthackersnews.com/brata-malware/): The malicious attacker driving the BRATA banking trojan has upgraded its techniques and added information-stealing features to the malware. Cleafy, an Italian mobile security firm, has followed BRATA activity and identified alterations in subsequent campaigns that lead to extended device persistence.  - [730K WordPress Sites Force-Updated To Patch Critical Plugin Bug](https://firsthackersnews.com/wordpress-site-critical-plugin/): WordPress sites using Ninja Forms, a forms builder plugin with more than 1 million installations, have been force-updated this week to a new build that addresses a critical security vulnerability. The vulnerability is a code injection vulnerability affecting multiple Ninja Forms releases, starting with version 3.0 and up. - [High-Severity RCE Vulnerability Reported in Popular Fastjson Library](https://firsthackersnews.com/high-severity-fastjson-vulnerability/): Cybersecurity researchers have detailed a recently patched high-severity security vulnerability in the popular Fastjson library that could be potentially exploited to achieve remote code execution. - [Ransomware Gang Creates Site for Victims to Search for Their Stolen Data](https://firsthackersnews.com/blackcat-ransomware/): The ALPHV ransomware gang, also known as BlackCat has created a dedicated website that allows the customers and employees of their victims to check if their data was stolen in an attack. - [Hackers exploit three-year-old Telerik flaws to deploy cobalt strike](https://firsthackersnews.com/telerik-flaws/): The "Blue Mockingbird" group has targeted Telerik UI vulnerabilities to compromise servers. The threat actor installed the Cobalt Strike beacon and mined Monero. - [New Hertzbleed side-channel attack affects Intel,AMD CPUs](https://firsthackersnews.com/hertzbleed-side-channel-attack/): A new side-channel attack known as Hertzbleed allows remote attackers to steal full cryptographic keys by observing variations in CPU frequency enabled by dynamic voltage and frequency scaling(DVFS). - [Citrix Releases Security Updates for Application Delivery Management](https://firsthackersnews.com/application-delivery-management/): Citrix has released security updates to address vulnerabilities in application delivery management. An attacker could exploit these vulnerabilities to take control of an affected system. - [New Zimbra Email Vulnerability Could Let Attackers Steal Your Login Credentials](https://firsthackersnews.com/zimbra-email-vulnerbaility/): Zimbra is an enterprise-level email solution, similar to Microsoft Exchange. It comes with mail servers, load balancing features, a powerful web interface, and more.  - [Hello XD ransomware now drops a backdoor while encrypting](https://firsthackersnews.com/hello-xd-ransomware/): Cybersecurity researchers report increased activity of the Hello XD ransomware, whose operators are now deploying an stronger encryption .Instead, it prefers to direct the impacted victim to negotiations through TOX chat and onion-based messenger instances. - [Emotet Malware is Now Harvesting Credit Card Information from Google Chrome Browser](https://firsthackersnews.com/emotet-malware-is-now-harvesting-credit-card-information-from-google-chrome-browser/): Google Chrome has been infected with a new type of malware known as Emotet, which steal users' confidential credit card information. - [New Vytal Chrome extension hides location info that your VPN can’t](https://firsthackersnews.com/new-vytal-chrome-extension-hides-location-info-that-your-vpn-cant/): A new Google Chrome browser extension called Vytal prevents webpages from using programming APIs to find your geographic location leaked, even when using a VPN. - [Newest Symbiote Malware Affects All Running Processes on Linux Systems](https://firsthackersnews.com/newest-symbiote-malware-affects-all-running-processes-on-linux-systems/): A newly discovered Linux malware known as Symbiote infects all running processes on compromised systems, steals account credentials, and gives its operators backdoor access. - [10 ways attackers gain access to networks](https://firsthackersnews.com/10-ways-attackers-gain-access-to-networks/): A joint multi-national cybersecurity advisory has revealed the top ten attackers vectors most exploited by cybercriminals in order to gain access to organisation networks, as well as the techniques they use to gain access. - [Cuba ransomware returns to extorting victims with updated encryptor](https://firsthackersnews.com/cuba-ransomware-returns-to-extorting-victims-with-updated-encryptor/): The refinement of the Cuba ransomware variant can only mean that the group will continue to be a threat to organizations in the following months, mainly those located in North America. - [This WhatsApp Call Forwarding Trick Allows Hackers To Hijack Your Account](https://firsthackersnews.com/this-whatsapp-call-forwarding-trick-allows-hackers-to-hijack-your-account/): As we all know each WhatsApp account is tied to a phone number, and hackers are calling these phone numbers directly and employing social engineering techniques to trick victims into handing over their WhatsApp accounts. However, victims may not suspect that the calls legitimate ones. - [Qbot malware now uses windows MSDT Zer0-Day in phishing attacks](https://firsthackersnews.com/qbot-malware-now-uses-windows-msdt-zer0-day-in-phishing-attacks/): A serious Windows zero-day vulnerability known as Follina is currently being actively exploited in continuing phishing campaigns to infect targets with Qbot malware, which is still waiting for an official fix from Microsoft. - [DeadBolt Ransomware Locks Out Vendors With Multitiered Extortion Scheme](https://firsthackersnews.com/deadbolt-ransomware-locks-out-vendors-with-multitiered-extortion-scheme/): The number of DeadBolt-infected devices is considerably high for a ransomware family that is exclusively targeting NAS devices.The goal of DeadBolt actors is to infect as many victims as possible to get a decent payout or to get a vendor to pay one of the ransom options to get substantial financial payouts from its attacks. - [LuoYu APT delivers WinDealer malware via man-on-the-side attacks](https://firsthackersnews.com/luoyu-apt-delivers-windealer-malware-via-man-on-the-side-attacks/): LuoYu, a Chinese-speaking hacking group, is infecting victims with the WinDealer information stealer that installs backdoors to maintain persistence. The stealer performs man-on-the-side attacks. - [Unpatched Atlassian Confluence vulnerability is actively exploited](https://firsthackersnews.com/unpatched-atlassian-confluence-vulnerability-is-actively-exploited/): Researchers found a vulnerability in Atlassian Confluence by conducting an incident response investigation. Atlassian rates the severity level of this vulnerability as critical. - [Threat Actors Chaining Unpatched VMware Vulnerabilities for Full System Control](https://firsthackersnews.com/threat-actors-chaining-unpatched-vmware-vulnerabilities-for-full-system-control/): The CISA is releasing this CSA to warn organizations that malicious cyber actors, likely APT actors, are exploiting VMware vulnerabilities CVE-2022-22954 and CVE-2022-22960 separately. - [Analysis of the Massive NDSW/NDSX Malware Campaign](https://firsthackersnews.com/analysis-of-the-massive-ndsw-ndsx-malware-campaign/): The "Parrot TDS" campaign involving more than 16,500 infected websites. such massive infections don't go unnoticed by Sucuri and immediately recognized that the infection in their writeup belonged to the campaign researchers internally refer to as "ndsw/ndsx" malware. - [Microsoft Security: Exposing POLONIUM activity and infrastructure targeting Israeli organizations](https://firsthackersnews.com/microsoft-security-exposing-polonium-activity-and-infrastructure-targeting-israeli-organizations/): Microsoft successfully detected and disabled attack activity abusing OneDrive by a previously undocumented Lebanon-based activity group Microsoft Threat Intelligence Center (MSTIC) tracks as POLONIUM . - [Conti ransomware targeted Intel firmware for stealthy attacks](https://firsthackersnews.com/conti-ransomware-targeted-intel-firmware-for-stealthy-attacks/): Researchers analyzing the leaked chats of the notorious Conti ransomware operation have discovered that teams inside the Russian cybercrime group were actively developing firmware hacks. - [VMware and F5 BIG-IP flaws are being exploited by EnemyBot](https://firsthackersnews.com/vmware-and-f5-big-ip-flaws-are-being-exploited-by-enemybot/): EnemyBot, a botnet derived from many pieces of malware codes, extends its overall reach by rapidly incorporating exploits for previously detected severe vulnerabilities in web servers, content management systems, IoT, and Android devices - [XLoader botnet now uses probability theory to hide its servers](https://firsthackersnews.com/xloader-botnet-now-uses-probability-theory-to-hide-its-servers/): Threat analysts have spotted a new version of the XLoader botnet malware that uses probability theory to hide its command and control servers, making it difficult to disrupt the malware’s operation. - [New Microsoft Office Zero-Day Exploit in the Wild](https://firsthackersnews.com/follina-a-microsoft-office-code-execution-vulnerability-zero-day/): Security researchers recently discovered a new Microsoft Office zero-day flaw(Follina) exploited in PowerShell remote code execution attacks. The new vulnerability, tracked as CVE-2022-30190, would let hackers execute malicious PowerShell commands through Microsoft Diagnostic Tool (MSDT). - [Windows malware uses PowerShell to inject malicious extension into Chrome](https://firsthackersnews.com/windows-uses-powershell-command-to-inject-malicious-extension/): The malware is designed to install malicious extension(s) onto browsers. Currently, two distinct variants of ChromeLoader have been detected - one targeting Windows Operating Systems and another - Mac Operating Systems. - [Austria hit by BlackCat Ransomware, which demands $5 Million](https://firsthackersnews.com/blackcat-ransomware-attack/): The Austrian Federal State, Carinthia was attacked on Tuesday and Government services were severely disrupted as more workstations were apparently locked by the attacker. - [Critical Vulnerabilities Identified in OAS Platform](https://firsthackersnews.com/oas-platform-vulnerability/): Open Automation Software (OAS) has been identified with vulnerabilities by researchers. These vulnerabilities are getting exploited by the threat actors. - [Automobile Manufacturer – General Motors under Credential Stuffing Attack](https://firsthackersnews.com/general-motors-under-attack/): The General Motors had released a report last week about a data breach in the company that occurred between 11th - 29th of April month. - [Further Analysis into BPFDoor reveals about Vulnerability Exploitation](https://firsthackersnews.com/further-analysis-into-bpfdoor/): BPFDoor is a traditional backdoor that had been exploited against the Government, telecommunication, Education and Logistics organizations for at least a several years. This was possible because it has been staying under the radar, undetected. - [SpiceJet hit by Ransomware, Flights services are slowed down.](https://firsthackersnews.com/spicejet-hit-by-ransomware-flights-services-are-slowed-down/): SpiceJet, an airline service providing air transport services since a long time. It offers various destination flights for its customers. - [Cobalt Strike loaded with Malicious Python Packages](https://firsthackersnews.com/malicious-python-packages/): A malicious python package named “pymafka” was found in the PyPI registry by Sonatype’s automated malware detection bots. The name “pymafka” is similar to “pykafka”, a popular and legitimate programmer-friendly Apache kafka client for python. - [NIKKEI Hit by Ransomware Attack – Not the First Time](https://firsthackersnews.com/nikkei-hit/): Nikkei announced on this Thursday that their server at Asian headquarters located in Singapore was hit by a ransomware attack. - [PDF Documents Carrying Snake KeyLogger – Info Stealer](https://firsthackersnews.com/pdf-documents-carrying-snake-keylogger-info-stealer/): Microsoft Office Files are exploited for social engineering lures (especially Excel and Word), as these file formats are highly preferred by the public. The users are comfortable because the applications used to access these files are ubiquitous. - [Lazarus targeting on VMware – Log4J Vulnerability Still Active](https://firsthackersnews.com/lazarus-vmware-vulnerability/): VMware servers are targeted again by the North Korean Hackers called Lazarus. The CVE-2021-44228 is exploited again to bring impact to a variety of products including the VMware Horizon Servers. - [Phishing attacks targeting Microsoft Windows Users with three Malwares](https://firsthackersnews.com/phishing-attack-with-three-malwares/): A sophisticated phishing campaign has started targeting Windows User. But, this campaign differs from other phishing attacks as it installs three malwares into the victim’s system. - [Fake Mobile Apps to steal your Credentials and Private Keys](https://firsthackersnews.com/fake-mobile-apps-to-steal-your-credentials-and-private-keys/): Recent observance by researchers in the Google Play Store showed that numbers of applications are malicious to the user. The malicious activities performed includes the stealing of credentials, private information such as private keys of the user’s crypto currency wallets. - [Increasing Investors in NFT leads Hackers to Target NFT Sites](https://firsthackersnews.com/nft-pixelmon/): Due to the hiking interests towards the Pixelmon NFT Site, the threat actors have turned their attention towards them. - [BPFDoor with Firewall Security evasion, Linux Specific](https://firsthackersnews.com/linux-malware/): Recently, BPFDoor - a malware was brought to light after years under the radar. It allows a threat actor to backdoor a system for remote code execution. - [Ramping efforts of Russian Hackers against the Satellites of SpaceX](https://firsthackersnews.com/russian-hackers-against-of-space-x/): Starlink is Satellite Internet Company owned by Elon Musk and it was activated in Ukraine after Russia crippled the country's communication systems during the ongoing war - [Microsoft Exchange Servers affected by Post-Exploitation Malware](https://firsthackersnews.com/microsoft-exchange-servers-affected-by-post-exploitation-malware/): A post-exploitation malware Framework set down within the Microsoft Exchange Servers of organizations in various sectors across multiple regions. This campaign seems to be gathering intelligence and is tethered to a targeted state-sponsored campaign. - [F5 Released Security Patches for the “CVE-2022-1388” – Act Immediately](https://firsthackersnews.com/cve-2022-1388/): Admins have been warned by the security researchers against a critical Remote-Control Execution (RCE) flaw in the F5 BIG-IP.   - [“Fileless Malware” with a New Form of Cover-Up](https://firsthackersnews.com/fileless-malware/): Researchers have discovered a new malicious campaign using a never-before-seen technique for injecting Fileless malware on target systems. - [A Data Breach at IKEA, Canada – Company confirms](https://firsthackersnews.com/data-breach-at-ikea-canada/): IKEA Canada has notified Canada’s Office of Privacy Commissioner (OPC) after the personal information of 95k Canadian customers appeared in a data breach. - [CISCO NFV Zero-day Vulnerability](https://firsthackersnews.com/cisco-nfv-zero-day-vulnerability/): Cisco has released software updates that address the Enterprise Network Function Virtualization Infrastructure Software (NFVIS) vulnerabilities. - [Critical Vulnerability in Common Enterprise Switches and more…](https://firsthackersnews.com/critical-vulnerability-in-common-enterprise-switches-and-more/): TLStorm - a group of vulnerabilities found while implementing TLS(Transport Security Layer) in multiple models of network switches. - [Beware Corporate, Mergers & Acquisitions are being targeted !](https://firsthackersnews.com/mergers-are-targeted/): A recently uncovered espionage threat actors are targeting the employees majoring in the mergers and acquisitions to facilitate a mass email collection from the victim’s environments. Also focusing on the large corporate data of transactions. - [CERT-In advisory for Indian Organization – All You Need to Know !!](https://firsthackersnews.com/cert-in-advisory/): Past Week we could see a lot of Indian Organizations were under targeted attack and they were compromised. Now we can see CERT-In became active and provided guidelines for Organizations. This Article is an abstract and overview of recently published Advisory. - [Is Black Basta Ransomware a Beast? Sounds like it is.](https://firsthackersnews.com/is-black-basta-ransomware-a-beast-sounds-like-it-is/): Black Basta, a new ransomware has started its play during the month of April, with a start of approximately ten to fifteen companies. - [Why Indian Companies are not taking the Cyber Attack Seriously ?](https://firsthackersnews.com/why-indian-companies-are-not-taking-the-cyber-attack-seriously/): The article released by us on Monday about "Stormous Ransomware" Group is targeting the Indian companies, contained the list of websites targeted by the group. Those organizational websites were chosen through an open poll conducted by this group, and we had brought up those list in the article. - [Indian Companies are under Targeted Attack – Financially motivated](https://firsthackersnews.com/indian-companies/): Security Researchers Identified "Stormous ransomware campaigns" targeting multiple organization, especially Indian organization for financial motivation - [The Duck has Started Mining Again – As per CrowdStrike Researchers](https://firsthackersnews.com/lemonduck-botnet/): The Emerging growth of the Digital Currencies also develops the need of protection from unforeseen hazards. The “LemonDuck” botnet, already in existence, is now targeting the Docker APIs for Crypto Currency mining. It is an anonymous mining operation that uses the proxy tools and disables the Alibaba Cloud Defense system to Stay under the hood while the job is getting done - [Windows 11 Upgrade – Fake Campaign is back Again & Again to steal the rest of what you have.](https://firsthackersnews.com/windows-11-upgrade-fake-campaign/): Attack was active on Feb-08-2022 through RedLine Malware, now it’s more effective and researchers named that as “Inno Stealer”. - [Digital Currency Exchanges and Users are under Targeted Attack by North Korean – TraderTraitor](https://firsthackersnews.com/exchanges-under-attack/): This targeted Attack is succeeded through effective “Social Engineering Techniques”. Techniques used here which resembles the attack from “Lazarus Group "AppleJeus”. Dangerous customized Trojan has been designed for this specific attack which is targeting the crypto currency industries and its users which can steal all your cryptocurrencies and NFT’s. Continuous Spear Phishing Campaigns has been targeted the exchanges which will utilize the presence of existing vulnerabilities in their applications and servers. - [Security Update — BIG-IP APM AD Authentication Vulnerability](https://firsthackersnews.com/security-update-big-ip-apm-ad-authentication-vulnerability/): BIG-IP APM AD (Active Directory) authentication can be bypassed using a spoofed AS-REP (Kerberos Authentication Service Response) response sent over a hijacked KDC (Kerberos Key Distribution Center) connection, or from an AD server compromised by an attacker. - [Threat Actors Abusing Excel Against Malicious XLM Macros](https://firsthackersnews.com/threat-actors-abusing-excel-against-malicious-xlm-macros/): Attackers using Excel documents to distribute various malware — placing backdoor to compromise machines. - [Security Vulnerability Update — Siemens Mendix Applications](https://firsthackersnews.com/security-vulnerability-update-siemens-mendix-applications/): Siemens released security update for Siemens Mendix Applications — prone to an elevation of privilege vulnerability.prone to an elevation of privilege vulnerability. - [Security Vulnerability Update — Adobe RoboHelp Privilege Elevation](https://firsthackersnews.com/security-vulnerability-update-adobe-robohelp-privilege-elevation/): Adobe released vulnerability update for RoboHelp — prone to an elevation of privilege vulnerability. - [Passwordstate Password Manager Installs Backdoor — Supply Chain Attack](https://firsthackersnews.com/passwordstate-password-manager-installs-backdoor-supply-chain-attack/): Passwordstate app's update hijacked to install malware in a supply-chain attack after breaching its networks. - [ToxicEye Remote Access Trojan Exploits Telegram For C&C](https://firsthackersnews.com/toxiceye-remote-access-trojan-exploits-telegram-for-cc/): To steal data from victims and update itself to perform additional malicious activities — Telegram exploited by Remote Access Trojan - [Twitter Suspicious Email Asking For Account Confirmation](https://firsthackersnews.com/twitter-suspicious-email-asking-for-account-confirmation/): Many users are receiving Email alike phishing from Twitter asking users to confirm their accounts. - [Zero-Day Security Vulnerability — Pulse Connect Secure VPN](https://firsthackersnews.com/zero-day-security-vulnerability-pulse-connect-secure-vpn/): Attackers are exploiting zero-day in Pulse Secure VPNs to breach organisations — (CVE-2021-22893) - [Critical Security Vulnerability Update — Adobe Bridge](https://firsthackersnews.com/critical-security-vulnerability-update-adobe-bridge/): Adobe has released a security update for Adobe Bridge for arbitrary code execution in the context of the current user. - [Ryuk Ransomware Updates Its Hacking Functionality](https://firsthackersnews.com/ryuk-ransomware-updates-its-hacking-functionality/): This time the ransomware relied more on compromising exposed RDP connections to gain an initial foothold on a target network. - [Critical Remote Code Execution Vulnerability — Juniper OS](https://firsthackersnews.com/critical-remote-code-execution-vulnerability-juniper-os/): During external security research a CRITICAL remote code execution vulnerability discovered in overlayd service. - [Apache Critical Security Vulnerability — CVE-2021-27850](https://firsthackersnews.com/apache-critical-security-vulnerability-cve-2021-27850/): Apache released security updates for bypass of older vulnerability — Arbitrary Code Execution - [Critical Security Vulnerability Update — Adobe Photoshop](https://firsthackersnews.com/critical-security-vulnerability-update-adobe-photoshop/): Adobe has released updates for Windows and macOS for CRITICAL severity vulnerabilities in Photoshop. - [Update For UnPatched Browsers — RCE Exploit](https://firsthackersnews.com/update-for-unpatched-browsers-rce-exploit/): An exploit aimed at the V8 JavaScript rendering engine to hack Google Chrome and Microsoft Edge (Chromium) browsers. - [Huawei Users Alert — Infecting Joker Malware](https://firsthackersnews.com/huawei-users-alert-infecting-joker-malware/): Over 500,000 Huawei Android devices were found to be infected as malicious apps were downloaded from the company’s official Android store. - [Pierre Fabre Group Hit By REvil Cyber Attack — $25 million Ransom](https://firsthackersnews.com/pierre-fabre-group-hit-by-revil-cyber-attack-25-million-ransom/): Leading pharmaceutical group Pierre Fabre confirmed a REvil ransomware attack — demanded a $25 million ransom. - [Gigaset Mobile Users Targeted Via Hacked Update Server](https://firsthackersnews.com/gigaset-mobile-users-targeted-via-hacked-update-server/): Malware infection detected in Gigaset Android devices as external update server got compromised. - [Multiple Security Vulnerabilities Affecting Cisco Products](https://firsthackersnews.com/multiple-security-vulnerabilities-affecting-cisco-products/): Cisco has released security updates regarding multiple vulnerabilities — considered as CRITICAL severity. - [Android Malware Spreads Via WhatsApp Auto-Replies](https://firsthackersnews.com/android-malware-spreads-via-whatsapp-auto-replies/): Researchers discovered wormable android malware — capable of propagating via WhatsApp messages. - [SAP Applications Are Critical Against Old Vulnerabilities](https://firsthackersnews.com/sap-applications-are-critical-against-old-vulnerabilities/): Threat actors targeting widely deployed, mission-critical SAP applications — exposing the networks of commercial and government organizations to attacks. - [Critical Vulnerability Update — VMware Carbon Black Cloud Workload Appliance](https://firsthackersnews.com/critical-vulnerability-update-vmware-carbon-black-cloud-workload-appliance/): Security update is available to remediate the critical vulnerability addressing VMware Carbon Black Cloud Workload appliance. - [LinkedIn Phishing Job Offers Targeting Professionals](https://firsthackersnews.com/linkedin-phishing-job-offers-targeting-professionals/): Fake job offer — phishing campaigns delivering backdoor, targeting job professionals in LinkedIn. - [Zero-Day Vulnerability Discovered — QNAP NAS Devices](https://firsthackersnews.com/zero-day-vulnerability-discovered-qnap-nas-devices/): Multiple vulnerabilities were found in QNAP NAS devices allowing access to user data and complete takeover. - [Users Facebook Personal Data Leaked On Hacker Forum](https://firsthackersnews.com/users-facebook-personal-data-leaked-on-hacker-forum/): Over 533 million worldwide Facebook users data leaked on a popular cyber-crime forum for free. - [Privilege Escalation Vulnerability In Umbraco](https://firsthackersnews.com/privilege-escalation-vulnerability-in-umbraco/): Researcher identified in Umbraco CMS — privilege escalation vulnerability allowing attackers to access resources which are normally accessible only by higher-privileged users. - [Attackers Targeting Fortinet FortiOS Servers Using Multiple Exploits](https://firsthackersnews.com/attackers-targeting-fortinet-fortios-servers-using-multiple-exploits/): The FBI and CISA warn — APT actors are scanning Fortinet FortiOS for vulnerabilities — to gain access for multiple high-level service networks. - [Google Chrome Security Vulnerabilities — Stable Channel Update](https://firsthackersnews.com/google-chrome-security-vulnerabilities-stable-channel-update/): Chrome - the Stable channel updated to 89.0.4389.114 for Windows, Mac and Linux. - [Over 3.5M MobiKwiK Users Data Leaked On Dark Web](https://firsthackersnews.com/over-3-5m-mobikwik-users-data-leaked-on-dark-web/): Thousands of customers data using Indian Payments App account leaked and available on the dark web. - [Android Malware Steals Data Poses As Security Update](https://firsthackersnews.com/android-malware-steals-data-poses-as-security-update/): Researchers uncovered malware posing as System Update — takes control of the device, steals almost all the data, and perform a variety of invasive actions. - [Purple Fox Worm Targets Microsoft Windows Machines](https://firsthackersnews.com/purple-fox-worm-targets-microsoft-windows-machines/): Threat actors are hosting a new malware "Purple Fox" campaign — attacks have spiked by about 600% according to  Guardicore researchers. - [Phishing Campaigns Bypassing Email Gateways — Microsoft Warns](https://firsthackersnews.com/phishing-campaigns-bypassing-email-gateways-microsoft-warns/): According to Microsoft, a phishing campaign active since December expanded with new feature, also now bypass Email Gateway. - [Apache OFBiz Critical Vulnerability — Fix Now](https://firsthackersnews.com/apache-ofbiz-critical-vulnerability-fix-now/): RCE vulnerability in latest Apache OFBiz due to Java serialisation using RMI — Patch to the latest version. - [Critical Vulnerability SQL Injection, XSS Attacks — MyBB Security Update](https://firsthackersnews.com/critical-vulnerability-sql-injection-xss-attacks-mybb-security-update/): MyBB released security updates for multiple vulnerabilities including SQL injection, XSS attacks, bypassing issues. - [Acer Hit By REvil Ransomware — Largest Known Ransom](https://firsthackersnews.com/acer-hit-by-revil-ransomware-largest-known-ransom/): PC giant Acer attacked by ransomware gangs — demanded $50 million to not leak on dark web — decrypt the company's computers. - [Security Vulnerability Update — Intel Cell Modem](https://firsthackersnews.com/security-vulnerability-update-intel-cell-modem/): A security vulnerability update released by Intel to mitigate this potential vulnerability. - [Compromised E-Commerce Platforms Credit Card Details Stored In .JPG File](https://firsthackersnews.com/compromised-e-commerce-platforms-credit-card-details-stored-in-jpg-file/): An E-Commerce platform running open-source Magento v2 compromised by threat actors — hid the stolen details in a JPG image. - [Security Vulnerability Update — Adobe Framemaker](https://firsthackersnews.com/security-vulnerability-update-adobe-framemaker/): Adobe has released security updates for its products causing Boundary Condition problem. - [DearCry Ransomware Targets Exchange Servers Using ProxyLogon vulnerability](https://firsthackersnews.com/dearcry-ransomware-targets-exchange-servers-using-proxylogon-vulnerability/): Threat actors are using the recently disclosed zero-day ProxyLogon vulnerabilities — installing a new strain of ransomware called DEARCRY in Exchange servers. - [Another Zero-Day Bug Fix — Google Chrome Security Update](https://firsthackersnews.com/another-zero-day-bug-fix-google-chrome-security-update/): Google fixed another 0-day vulnerability in Chrome browser within a month. - [FortiProxy SSL-VPN —Security Vulnerability Update](https://firsthackersnews.com/fortiproxy-ssl-vpn-security-vulnerability-update/): Fortinet released security fix for the vulnerability — Security ByPass - [Apple Security Vulnerability Update For Critical Bug](https://firsthackersnews.com/apple-security-vulnerability-update-for-critical-bug/): Apple has released security updates for a severe vulnerability affected in Apple Safari, macOS Big Sur, iOS, iPadOS and watchOS. - [Security Vulnerability Update — Accellion FTA](https://firsthackersnews.com/security-vulnerability-update-accellion-fta/): Accellion released patches addressing vulnerabilities in its File Transfer Appliance. - [Critical Android Bugs — Samsung Fix Released](https://firsthackersnews.com/critical-android-bugs-samsung-fix-released/): Samsung started rolling out Android's March 2021 security updates for critical security vulnerabilities. - [Exchange Server Attacks Against US Local Governments — Zero-Day Vulnerabilities](https://firsthackersnews.com/exchange-server-attacks-against-us-local-governments-zero-day-vulnerabilities/): Zero-Day vulnerabilities are actively exploit — attacks against local US government agencies. - [Chrome 89 Security Update — Active Zero-Day Vulnerability](https://firsthackersnews.com/chrome-89-security-update-active-zero-day-vulnerability/): Google warned users to update Chrome browser — zero-day vulnerability in the Chrome browser — actively exploited in the wild. - [iPhone Models Under Risk — New iOS Jailbreak Threat](https://firsthackersnews.com/iphone-models-under-risk-new-ios-jailbreak-threat/): Jailbreaking threat made possible to all iPhone models under risk as a vulnerability that Apple already been fixed. - [Serious Windows 10 Drive Corruption Bug — Microsoft Fixed](https://firsthackersnews.com/serious-windows-10-drive-corruption-bug-microsoft-fixed/): A weird Windows 10 drive corruption bug fixed — available for Windows Insider program. - [Oxford University Lab System’s Hacked — Studying COVID-19](https://firsthackersnews.com/oxford-university-lab-systems-hacked-studying-covid-19/): Research at Oxford University lab studying COVID-19 — attacked by threat actors. - [Critical Bug In All VMware ESXi and vSphere Client](https://firsthackersnews.com/critical-bug-in-all-vmware-esxi-and-vsphere-client/): Security updates are available to remediate multiple vulnerabilities affecting VMware products. - [Security Update — PHP Race Condition Vulnerability](https://firsthackersnews.com/security-update-php-race-condition-vulnerability/): A security update released for PHP Denial of Service Vulnerability. - [Security Update — Cisco AnyConnect DLL Hijacking](https://firsthackersnews.com/security-update-cisco-anyconnect-dll-hijacking/): Cisco released security updates for Cisco AnyConnect secure mobility client for windows arbitrary code execution vulnerability. - [Kia Motors Hit By Ransomware Attack — Denied As No Evidence Of Attack](https://firsthackersnews.com/kia-motors-hit-by-ransomware-attack-denied-as-no-evidence-of-attack/): Kia Motors America denied the ransomware attack after a day-long network outages. - [UL — Global Safety Certification Giant Hit By Ransomware Attack](https://firsthackersnews.com/ul-global-safety-certification-giant-hit-by-ransomware-attack/): Underwriters Laboratories UL LLC, a global safety certification company has suffered a ransomware attack that encrypted its servers. - [Zero-Day Vulnerability IBM InfoSphere Information Server](https://firsthackersnews.com/zero-day-vulnerability-ibm-infosphere-information-server/): Researchers discovered a zero-day vulnerability on IBM InfoSphere Information Server 8.5.0.0 - [Botnet Targeting Windows, Linux Servers For Two Years](https://firsthackersnews.com/botnet-targeting-windows-linux-servers-for-two-years/): WatchDog botnet performs cryptojacking for almost 2 years to take over windows and linux servers. - [Apple Patched Severe macOS Big Sur Data Loss Bug](https://firsthackersnews.com/apple-patched-severe-macos-big-sur-data-loss-bug/): Apple has released a new update that could cause serious data loss. - [Telegram Sticker Could Expose Your Data To Threat Actors](https://firsthackersnews.com/telegram-sticker-could-expose-your-data-to-threat-actors/): A Sticker sent to Telegram account could expose data including Secret chats, Photos, etc - [Caution — Valentine’s Day Cyber Attacks On the Rise](https://firsthackersnews.com/caution-valentines-day-cyber-attacks-on-the-rise/): Security experts warn internet users on the rise of scam due to Valentine's day. - [Security Advisory — SAP Commerce Critical Vulnerability](https://firsthackersnews.com/security-advisory-sap-commerce-critical-vulnerability/): Patch released for a new critical vulnerability affecting SAP commerce platforms. - [User Details Sold By Yandex Employee For Personal Gain](https://firsthackersnews.com/user-details-sold-by-yandex-employee-for-personal-gain/): The system administrator of Russian company sold thousands of user email accounts. - [Hackers Modified Drinking Water Levels To Dangerous Parameters In Florida](https://firsthackersnews.com/hackers-modified-drinking-water-levels-to-dangerous-parameters-in-florida/): Threat actors modified the concentration of LYE to dangerous parameters. - [Multiple Sri Lankan DNS Records Were Poisoned — Including Google.lk](https://firsthackersnews.com/multiple-sri-lankan-dns-records-were-poisoned-including-google-lk/): Hackers group has poisoned multiple Sri Lankan domains on Saturday. - [SitePoint Discloses A Data Breach — Sold On Hacking Forum](https://firsthackersnews.com/sitepoint-discloses-a-data-breach-sold-on-hacking-forum/): SitePoint admitted a data breach after finding sale of one million SitePoint user details. - [New Chrome 0-Day Bug — Update Immediately](https://firsthackersnews.com/new-chrome-0-day-bug-update-immediately/): Google’s browser released a vulnerability which is actively being exploited in the wild. - [A Severe Bug Impacts Many Project — Libgcrypt](https://firsthackersnews.com/a-severe-bug-impacts-many-project-libgcrypt/): A severe vulnerability found in Libgcrypt and recommended not to use. - [Hezbollah Hackers Targeted Web Servers Using Unpatched Servers](https://firsthackersnews.com/hezbollah-hackers-targeted-web-servers-using-unpatched-servers/): Hackers group Lebanese Cedar attack unpatched Atlassian servers at telcoms, Hosting and ISPs providers. - [Security Vulnerability For Cisco DNA Center](https://firsthackersnews.com/security-vulnerability-for-cisco-dna-center/): Cisco disclosed a high-severity vulnerability allows cross-site request forgery (CSRF) attacks and Information Disclosure Vulnerability. - [Linux — SUDO Flaw Let Local User Gain Root Privileges](https://firsthackersnews.com/linux-sudo-flaw-let-local-user-gain-root-privileges/): Sudo vulnerability, local user can exploit this flaw for root privilege escalation. - [Apple iOS Fixes Zero-Day Vulnerabilities](https://firsthackersnews.com/apple-ios-fixes-zero-day-vulnerabilities/): Three new Zero-Day vulnerabilities patch released by Apple. - [Alert! New Android Malware Spreading Through WhatsApp](https://firsthackersnews.com/alert-new-android-malware-spreading-through-whatsapp/): Researchers found a new Adware campaign spreading through WhatsApp contacts. - [A CCTV Techie Spied On Hundreds Of Customers Private Moments](https://firsthackersnews.com/a-cctv-techie-spied-on-hundreds-of-customers-private-moments/): A technician from ADT accessed more than hundreds of customers CCTV systems to spy on them, engaging in private moments - [Critical Security Vulnerabilities In Cisco SD-WAN — Update Now](https://firsthackersnews.com/critical-security-vulnerabilities-in-cisco-sd-wan-update-now/): Cisco warns customers about critical security vulnerabilities affecting SD-WAN, DNA, and the Smart Software Manager Satellite. - [0-Day Bug In SonicWall’s Own VPN Product](https://firsthackersnews.com/0-day-bug-in-sonicwalls-own-vpn-product/): SonicWall released an urgent notice to their clients to patch a series Zero-Day vulnerability. - [Phishing Campaign: Thousands Of Stolen Passwords Exposed Online](https://firsthackersnews.com/phishing-campaign-thousands-of-stolen-passwords-exposed-online/): A phishing scam through Google search left thousands of stolen passwords exposed. - [Google Chrome’88 Update — Improve Password Security](https://firsthackersnews.com/google-chrome88-update-improve-password-security/): Chrome 88 new update with a feature now checks for weak passwords, helps fix them. - [Adobe Photoshop Security Vulnerability Advisory](https://firsthackersnews.com/adobe-photoshop-security-vulnerability-advisory/): Adobe released security updates for arbitrary code execution vulnerability for Windows and macOS. - [Malwarebytes Hit By SolarWinds — Accessed Internal Emails](https://firsthackersnews.com/malwarebytes-hit-by-solarwinds-accessed-internal-emails/): After Microsoft, FireEye and CrowdStrike, Malwarebytes hit by hacked SolarWinds. - [Hacker Gained Admin Access — Leads To Data Breach — OpenWRT](https://firsthackersnews.com/hacker-gained-admin-access-leads-to-data-breach-openwrt/): User data stolen from OpenWRT Forum leading to a database breach. - [164 Bombarding Android App Caught For Out-Of-Context Ads](https://firsthackersnews.com/164-bombarding-android-app-caught-for-out-of-context-ads/): More than 10million users installed Android apps that showed out-of-context ads. - [Windows 10 Serious Flaw Could Corrupt HardDrive — If You Open A Folder](https://firsthackersnews.com/windows-10-serious-flaw-could-corrupt-harddrive-if-you-open-a-folder/): Microsoft to fix Windows 10 bug that can corrupt a hard drive just by opening a folder or just by looking at an icon. - [Microsoft Released Windows Update — 83 Security Flaws](https://firsthackersnews.com/microsoft-released-windows-update-83-security-flaws/): Patch Tuesday of 2021 addressed 83 flaws spanning as many as 11 products and services. - [4 Zero-Day Infect Windows And Android devices](https://firsthackersnews.com/4-zero-day-infect-windows-and-android-devices/): Attackers infect booby-trapped websites — who visited them. - [Data Breach On Networking Giant Ubiquiti](https://firsthackersnews.com/data-breach-on-networking-giant-ubiquiti/): Ubiquiti, the Networking giant alerts customers to change passwords after a security breach. - [Security Advisory – Fortinet FortiWeb Vulnerability](https://firsthackersnews.com/security-advisory-fortinet-fortiweb-vulnerability/): FortiWeb is vulnerable to a blind SQL injection - [Signal Fixes Verification Delays Caused By WhatsApp Mass Exodus](https://firsthackersnews.com/signal-fixes-verification-delays-caused-by-whatsapp-mass-exodus/): Encrypted messaging service in Signal — verification process delay affecting its new user, recovered. - [Exact Location Of Users Are Exposed — Telegram App Feature](https://firsthackersnews.com/exact-location-of-users-are-exposed-telegram-app-feature/): Nearby Share feature can be exploited by adversaries to spoof GPS and get access to users' exact location. - [NVIDIA Release High-Severity Graphics Driver Flaws](https://firsthackersnews.com/nvidia-release-high-severity-graphics-driver-flaws/): In first update of 2021, NVIDIA patched 16 CVEs across its graphics drivers and vGPU software. - [The U.S. Department of Justice Email Server Breached — SolarWinds](https://firsthackersnews.com/the-us-department-of-justice-email-server-breached-solarwinds/): SolarWinds Hackers accessed Office 365 mailboxes of the U.S. Justice Department’s. - [Critical Android Security Update — Addressed 43 Bugs](https://firsthackersnews.com/critical-android-security-update-addressed-43-bugs/): Google's Android Security Update addressed 43 bugs affecting Android Handsets, including Samsung phones. - [Apache Security Vulnerability Advisory — Code Execution](https://firsthackersnews.com/apache-security-vulnerability-advisory-code-execution/): Apache released patches for some of its products. - [Aware! COVID-19 Vaccine Scams Appearing](https://firsthackersnews.com/aware-covid-19-vaccine-scams-appearing/): Scammers targeting users to get personal details — Federal officials. - [PayPal Phishing Campaign — Steals Sensitive Data](https://firsthackersnews.com/paypal-phishing-campaign-steals-sensitive-data/): A text message from PayPal found as phishing campaign leading to identity theft of the users. - [Backdoor Found In Zyxel Firewalls, VPN Products](https://firsthackersnews.com/backdoor-found-in-zyxel-firewalls-vpn-products/): More than 100,000 Zyxel firewalls, VPN gateways, and access point controllers contain a hardcoded admin-level backdoor account. - [Officially Dead Tomorrow — Adobe Flash Player](https://firsthackersnews.com/officially-dead-tomorrow-adobe-flash-player/): Adobe Flash Player will no longer be supporting Flash Player after 31 December 2020. - [Security Vulnerability —Apache TomEE](https://firsthackersnews.com/security-vulnerability-apache-tomee/):  Apache TomEE Security Bypass Vulnerability. - [Security Vulnerability — Cisco Secure Web Appliance](https://firsthackersnews.com/security-vulnerability-cisco-secure-web-appliance/): Cisco Secure Web Appliance Elevation of Privilege Vulnerability. - [Japan’s Kawasaki Disclosed Data Breach](https://firsthackersnews.com/japans-kawasaki-disclosed-data-breach/): Japanese Aerospace Firm Kawasaki — their data have been stolen following a security breach. - [Google Docs Bug — Hackers Can Access Your Private Documents](https://firsthackersnews.com/google-docs-bug-hackers-can-access-private-documents/): A bug that Google patched, could allow hackers to see your private documents. - [Attack Against App Offered By Vietnam Government](https://firsthackersnews.com/attack-against-app-offered-by-vietnam-government/): A complex Supply-Chain attack hit Vietnam Government Certification Authority (VGCA). - [iCloud Issue Causing Sign-in, Access To Data Problems](https://firsthackersnews.com/icloud-issue-causing-sign-in-access-to-data-problems/): Apple users face trouble in accessing data, setting up and signing in on the device. - [Fake Amazon Gift Cards Delivers Dridex malware](https://firsthackersnews.com/fake-amazon-gift-cards-delivers-dridex-malware/): Attackers target online shoppers using fake Amazon gift cards that deliver the Dridex banking Trojan. - [Security Vulnerability – Apache Pulsar Manager Security Bypass Vulnerability](https://firsthackersnews.com/security-vulnerability-apache-pulsar-manager/): A security bypass vulnerability found in Apache Pulsar. - [North Korea-Linked Threat Actor Attacks Vaccine Research](https://firsthackersnews.com/north-korea-linked-threat-actor-attacks-vaccine-research/): Cyber-attacks against two separate entities related to COVID-19 research. - [FBI & Interpol Taken Down Joker’s Stash Carding Site](https://firsthackersnews.com/fbi-interpol-taken-down-jokers-stash-carding-site/): US FBI and Interpol have seized a small number of servers used by Joker's Stash. - [SUNBURST Malware & SolarWinds Supply Chain Attack](https://firsthackersnews.com/sunburst-malware-solarwinds-supply-chain-attack/): Threat actors compromised the IT monitoring and management software of organizations including SolarWinds’s Orion, Intel, Cisco, Nvidia. - [Security Advisory — Dell Wyse ThinOS](https://firsthackersnews.com/security-advisory-dell-wyse-thinos/): Security researchers discovered vulnerabilities in Dell Wyse Thin client devices. - [Al Jazeera Journalists Hacked Using Israeli Firm’s Spyware](https://firsthackersnews.com/al-jazeera-journalists-hacked-using-israeli-firms-spyware/): iPhones of at least 36 Al Jazeera employees using a no-user-interaction zero-day vulnerability in the iOS iMessage app. - [NVIDIA — Security Vulnerabilities Update](https://firsthackersnews.com/nvidia-security-vulnerabilities-update/): Recently, NVD published a list of Common Vulnerabilities and Exposures(CVE) and their impact metrics - [28 Malicious Extensions Installed On Chrome or Edge](https://firsthackersnews.com/28-malicious-extensions-installed-on-chrome-or-edge/): Researchers identified malware hidden in at least 28 third-party Google Chrome and Microsoft Edge extensions — affects 30 lakh users worldwide. - [Zero-Day Vulnerability Alert — HPE Systems](https://firsthackersnews.com/zero-day-vulnerability-alert-hpe-systems/): Hewlett Packard Enterprise Systems Insight Manager (SIM), AMF Deserialization of Untrusted Data, Remote Code Execution Vulnerability. - [New Spyware Goontact Targeting Android, iPhone Users](https://firsthackersnews.com/new-spyware-targeting-android-iphone-users/): A new malware strain with spying and surveillance capabilities currently available in both Android and iOS versions. - [Medical Details Exposed Online — As Stored Insecurely](https://firsthackersnews.com/medical-details-exposed-online-as-stored-insecurely/): 45 million medical imaging files, personal data left discoverable on the open web, across 67 countries including the US, UK, France, and Germany. - [Google Services Restored After User’s Hit By Outage](https://firsthackersnews.com/google-services-users-hit-by-outage/): Multiple Google services — Gmail, Docs, YouTube have gone down across the world. - [Weak PostgreSQL Databases Targeted By PgMiner](https://firsthackersnews.com/weak-postgresql-databases-targeted-by-pgminer/): PgMiner botnet targets PostgreSQL databases to install a cryptocurrency miner. - [Samsung December 2020 Update – Fixes Critical Bugs](https://firsthackersnews.com/samsung-december-2020-update-fixes-critical-bugs/): Samsung's Android December security updates are rolling out to mobile devices to patch security vulnerabilities. - [16k Webex Accounts Deleted By Former Cisco Engineer](https://firsthackersnews.com/16k-webex-accounts-deleted-former-cisco-engineer/): Former Cisco Engineer's action lost 16k Webex accounts, as he accessed Cisco's AWS accounts and deleted 456 virtual machines, - [Glassdoor Resolved A Critical CSRF Vulnerability](https://firsthackersnews.com/glassdoor-resolved-a-critical-csrf-vulnerability/): A critical flaw resolved in Glassdoor which could be exploited to take over accounts.  - [Cyber-Attack In EU Agency — Incharge of COVID-19 Vaccine Approval](https://firsthackersnews.com/cyber-attack-eu-agency-incharge-covid-19-vaccine-approval/): EMA, the EU regulatory body in charge of approving COVID-19 vaccines, became the victim of a cyber-attack today. - [Vulnerability Affects Generic Electric Healthcare Devices](https://firsthackersnews.com/vulnerability-affects-generic-electric-healthcare-devicesu/): MDhex-Ray is a vulnerability that affects a long list of CT, X-Ray, and MRI imaging systems manufactured by GE Healthcare. - [Microsoft December 2020 Patch Tuesday — 58 Security Fix](https://firsthackersnews.com/microsoft-december-2020-patch-tuesday/): Nine critical bugs and 58 overall fixes mark the last scheduled security advisory of 2020. - [Web Skimmer — Attack Using Social Media Buttons](https://firsthackersnews.com/web-skimmer-attack-using-social-media-buttons-2/): Hackers found new way to attack e-commerce stores, online shoppers and steal credit card details. - [Data Leak From Embraer — Ransomware Attack](https://firsthackersnews.com/data-leak-from-embraer-ransomware-attack/): The Brazilian aerospace conglomerate became the victim of a ransomware attack last month. - [Ransomware Attack On Swiss Helicopter Maker](https://firsthackersnews.com/ransomware-attack-on-swiss-helicopter-maker/): Kopter's data has been published on the LockBit gang's blog, hosted on the dark web. - [Johnson & Johnson Targeted By Hackers — COVID-19 vaccine](https://firsthackersnews.com/johnson-johnson-targeted-by-hackers-covid-19-vaccine/): Johnson & Johnson, are seeing cyber-attacks from nation-state threat actors "every single minute of every single day." - [Critical Oracle WebLogic Bug – PATCH NOW](https://firsthackersnews.com/critical-oracle-weblogic-bug-patch-now/): Multiple botnets exploit through remote code execution vulnerability in Oracle WebLogic Server. - [MacOS Users Targeted With Updated Malware](https://firsthackersnews.com/macos-users-targeted-with-updated-malware/): New malware attacks designed to install a backdoor onto compromised MacOS systems. - [CentOS 7 — Vulnerability Update](https://firsthackersnews.com/centos-7-vulnerability-update/): The remote CentOS Linux host is missing one or more security updates. - [Hacker Sells C-level Executives Email Accounts](https://firsthackersnews.com/hacker-sells-c-level-email-accounts/): Access for Hundreds of C-level (like CEO, CFO, etc) executives is sold for $100 to $1500 per account, depending on the company size and executive role. - [Brazilian COVID-19 Patients Personal Data Exposed Online](https://firsthackersnews.com/brazilian-covid-19-patients-personal-data-exposed-online/): Over 16 million Brazilian COVID-19 patient's personal data exposed online, including Brazil President Jair Bolsonaro, seven ministers, and 17 provincial governors. - [Microsoft Fixes Xbox Website Bug That Would’ve Compromised Users’ Email Address](https://firsthackersnews.com/microsoft-fixes-xbox-website-bug-compromise-users-email-address/): The Xbox flaw allows hackers to compromise the user's real-time identity, If attackers had access to the email address. - [43 Chinese Apps Banned In India](https://firsthackersnews.com/43-chinese-apps-banned-in-india/): Indian government has banned another 43 Chinese mobile applications. - [Baidu’s Android Apps Caught Leaking Sensitive User Data](https://firsthackersnews.com/baidus-android-apps-leak-user-data/): Two popular Android apps from Chinese tech giant Baidu caught collecting sensitive user details. - [VMware Unpatched Critical Flaw Affects Multiple Products](https://firsthackersnews.com/vmware-unpatched-critical-flaw-affects-multiple-products/): VMware has released temporary workarounds to address a critical vulnerability in its products that could be exploited by an attacker to take control of an affected system. - [Google Disclosed High-Security Flaw In GitHub](https://firsthackersnews.com/google-disclosed-github-high-security-flaw/): Google Project Zero reported a high severity security flaw in GitHub. - [A Football Club Discloses Security Breach](https://firsthackersnews.com/a-football-club-discloses-security-breach/): A football club, Manchester United Plc can confirm that the club has experienced a cyber attack on its systems. - [Facebook Messenger Bug – Hackers Spy On Users Call](https://firsthackersnews.com/facebook-messenger-bug-hackers-spy-users-call/): Facebook fixed a major security bug in Facebook messenger for Android application, which let hackers listen before you pick up the call. - [Cisco Webex Bug – Attackers Join Meetings As Ghost Users](https://firsthackersnews.com/cisco-webex-bug-attackers-join-meetings-as-ghost-users/): IBM researchers discovered bugs that allow attackers to sneak in and join Webex meetings as ghost users, invisible to other participants. - [Cisco Security Manager – Vulnerability Update](https://firsthackersnews.com/cisco-security-manager-vulnerability-update/): Cisco has hurried out a patch after a day after proof-of-concept (PoC) exploit code was published for a critical flaw in Cisco Security Manager. - [Adult Sites Were Targeted Via Fake Java Update – Malsmoke](https://firsthackersnews.com/adult-sites-targeted-fake-java-update-malsmoke/): A fake Java update found on various porn sites actually downloads the well-known Zloader malware. - [Hackers Attacking COVID-19 Vaccine Makers – Microsoft Says](https://firsthackersnews.com/hackers-attacking-covid-19-vaccine-makers-microsoft-says/): Microsoft says hackers from Russia and North Korea are attacking COVID-19 vaccine makers. However, the organizations in the target list are not specified. - [New Jupyter Malware Steals Browser Data, Opens Backdoor](https://firsthackersnews.com/new-jupyter-malware-steals-browser-data/): A new malware, named Jupyter that steals information's from the user, and also the malware is used to create a backdoor on the infected device. - [Intel November 2020 Update – Fixes 95 Vulnerability](https://firsthackersnews.com/intel-november-2020-update-fixes-95-vulnerability/): Intel addressed 95 vulnerabilities on November 2020 Patch Tuesday, including critical ones affecting Intel Wireless Bluetooth products and Intel AMT. - [Microsoft Teams ‘FakeUpdates’ – Users Under Attack](https://firsthackersnews.com/microsoft-teams-fakeupdates-users-under-attack/): Microsoft warns that cybercriminals are using Cobalt Strike to infect entire networks beyond the infection point, according to a report. - [Windows 10, iOS, Chrome, Firefox, and Others Hacked – Tianfu Cup Hacking Competition](https://firsthackersnews.com/tianfu-cup-2020-various-platform-hacked/): Multiple operating systems and browsers successfully exploited in minutes by Bug Bounty hunters at Tianfu Cup 2020, a Chinese Hacking competition - [Android November Security Update Tracker](https://firsthackersnews.com/november-android-security-update-tracker/): Android November security update/patch 2020 tracker for all major OEMs and carriers worldwide. - [VMware – Update On Critical Flaw CVE-2020-3992](https://firsthackersnews.com/vmware-update-on-critical-flaw-cve-2020-3992/): An updated fix was issued by VMware for a critical-severity remote code execution flaw in its ESXi hypervisor products. - [GitHub’s Pristine Layout Vanished Off – They Missed To Renew The Certificate](https://firsthackersnews.com/githubs-layout-vanished-missed-to-renew-ssl/): GitHub site layout broken as the company failed to renew the SSL certificate. - [Google Chrome Multiple Vulnerabilities](https://firsthackersnews.com/google-chrome-multiple-vulnerabilities/): Multiple vulnerabilities were found in Google Chrome with High severity. These vulnerabilities can be exploited by an attacker by persuading a victim to visit a specially crafted Web site. Successful exploitation of these vulnerabilities can result in denial of service, security bypass, and arbitrary code execution. - [34 Million User Data From 17 Companies Was Found On Sale](https://firsthackersnews.com/34-million-user-data-from-17-companies-was-found-on-sale/): Hacker is selling account databases containing a total of 34 million user records stolen from 17 companies. - [Microsoft US Election Warning – Netlogon protocol Bug In Windows 10.](https://firsthackersnews.com/microsoft-us-election-warning-bug-in-windows/): Microsoft warned Windows 10 users as they received a "small number of reports" from customers and others on a vulnerability affecting the Netlogon protocol (CVE-2020-1472). - [Oracle WebLogic Flaw Exploit Against Honeypots](https://firsthackersnews.com/oracle-weblogic-vulnerable-against-honeypots/): Oracle fixed a vulnerability as attackers started targeting servers running on Oracle WebLogic instances, vulnerable to a critical flaw that allows attackers to take control of the system without authentication. - [21 Bogus Gaming Apps Found In Google Playstore](https://firsthackersnews.com/21-bogus-gaming-apps-found-in-google-playstore/): A team at Avast has uncovered another set of malicious apps in the Google Play Store. - [Tik Tok With HackerOne Announced Public Bug Bounty Program](https://firsthackersnews.com/tiktok-bug-bounty-hackerone/): This week, the popular Chinese video-sharing social networking service TikTok has launched a public bug bounty program through the HackerOne platform. - [Urgent Chrome Update To New Version](https://firsthackersnews.com/urgent-chrome-update-to-new-version/): Google's web browser has a "zero-day" vulnerability actively exploited. - [Trump’s Twitter Hack in 5 Attempts – Dutch Security Researcher](https://firsthackersnews.com/trumps-twitter-hack-in-5-attempts-dutch-security-researcher/): Donald Trump Twitter account was hacked by a Dutch security researcher, claims he has gained access to US President Donald Trump's Twitter account just days before the 2020 US election. - [Popular Mobile Browsers Found With Multiple Address Bar Spoofing Vulnerabilities](https://firsthackersnews.com/popular-mobile-browsers-found-with-multiple-address-bar-spoofing-vulnerabilities/): Cyber Security researchers disclosed vulnerability details of multiple popular browsers about an Address Bar Spoofing vulnerability affecting mobile browsers leaving the door open for spear-phishing attacks and delivering malware. - [Hackers want to “make the world a better place” By Donating Charities In Cryptocurrency](https://firsthackersnews.com/hackers-want-to-make-the-world-a-better-place-by-donating-charities-in-cryptocurrency/): Security experts were amazed for the first time, as a Hacking group is donating the stolen money to charities. - [Alert! Emotet Malware’s New “Windows Update” Attachment](https://firsthackersnews.com/alert-emotet-malwares-new-windows-update-attachment/): Emotet is a Trojan that is primarily spread through spam emails (malspam). The infection may arrive either via a malicious script, macro-enabled document files, or malicious link.  - [Homeland Security Update – New Windows 10 Remote Hacking Threat](https://firsthackersnews.com/homeland-security-update-new-windows-10-remote-hacking-threat/): The Department of Homeland Security, Cybersecurity Agency, urges Windows 10 users to apply for security updates. - [Over 574K People Data from narendramodi.in was Found in Dark Web](https://firsthackersnews.com/over-574k-people-data-from-narendramodi-in-was-found-in-dark-web/): A cyber security firm alleges that user and donor data of over five lakh people have been stolen from narendramodi.in, the personal website of Prime Minister Modi, and the details are on sale on the dark web. - [Zero-Click Vulnerability in Linux Bluetooth Stack](https://firsthackersnews.com/zero-click-vulnerability-in-linux-bluetooth-stack/): Google researchers warned on a new set of potential security vulnerabilities(allow escalation of privilege or information disclosure) in BlueZ may allow escalation of privilege or information disclosure. BlueZ is releasing Linux kernel fixes to address these potential vulnerabilities. - [London Council Faced a Serious Cyber Attack](https://firsthackersnews.com/london-council-faced-a-serious-cyber-attack/): A serious Cyber Attack hit on the London Council which is affecting many of its services and IT systems. - [Microsoft Released Security Patch for 87 newly discovered Vulnerabilities](https://firsthackersnews.com/microsoft-security-patch-for-87-new-vulnerabilities/): Microsoft released patches for 87 newly discovered vulnerabilities on its October 2020 Patch Tuesday. - [Alert! Microsoft Warns of New Android Ransomware](https://firsthackersnews.com/alert-microsoft-warns-of-new-android-ransomware/): Android users were alerted by Microsoft, as they found a new ransomware MalLocker.B, the ransomware triggers on an infected phone as soon as the victim presses the Home key. - [Vulnerabilities Found in Top AntiVirus Software](https://firsthackersnews.com/vulnerabilities-found-in-top-antivirus-software/): Cyber Security researchers disclosed details of vulnerabilities found in popular Anti-Virus solutions that could enable attackers to elevate their privileges, thereby helping malware sustain its foothold on the compromised systems. - [Ransomware Delete Volume Shadow Copies – Install the Vaccine To Monitor](https://firsthackersnews.com/ransomware-delete-volume-shadow-copies-install-the-vaccine-to-monitor/): Shadow Copy is a technology included in Microsoft Windows that can create backup copies or snapshots of computer files or volumes, even when they are in use. It is implemented as a Windows service called the Volume Shadow Copy service. - [US Hospital Hit By SunCrypt Ransomware – HIPAA Data Leaked](https://firsthackersnews.com/us-hospital-hit-by-suncrypt-ransomware/): University Hospital New Jersey in Newark, New Jersey - Paid a ransom of $670,000 demanded by the attacker to prevent from publishing the stolen data of about 240GB, including patient info. - [Alert! New Android Spyware can SPY Telegram and Threema Apps](https://firsthackersnews.com/alert-new-android-spyware-can-spy-telegram-and-threema-apps/): Two-tailed Scorpion, a hacking group known for its cyberattacks in the Middle East had recently been found to pose itself as legitimate messaging applications such as Telegram and Threema to infect Android devices with a new, previously undocumented malware. - [Disrupt on US Presidential Debate – Twitter removed 130 Iranian Accounts](https://firsthackersnews.com/disrupt-on-us-presidential-debate-twitter-removed-130-iranian-accounts/): Twitter removed some accounts based on the tip provided by the FBI. - [Microsoft Resolved An outage of Office 365](https://firsthackersnews.com/microsoft-resolved-an-outage-of-office-365/): Microsoft says a recent update has affected the processing of authentication requests, making cloud-based services inaccessible. - [Joker – Play Store removes 17 Android Apps](https://firsthackersnews.com/joker-play-store-removes-17-android-apps/): Tech giants from Zscaler ThreatLabZ research team identified 17 apps and alerted Google as those Apps were infected with joker malware app and were reportedly stealing details like SMS, contact details and device information from affected phone's. - [Over 2000 Magento Online Stores were Hacked](https://firsthackersnews.com/over-2000-magento-online-stores-were-hacked/): Over 2,000 Magento stores were compromised over the weekend. The private information of thousands of customers has been hacked in the largest automated campaign to date. - [“Zerologon” Exploit for Netlogon Remote Protocol](https://firsthackersnews.com/zerologon-exploit-for-netlogon-remote-protocol/): An elevation of privilege vulnerability exists when an attacker establishes a vulnerable Netlogon secure channel connection to a domain controller, using the Netlogon Remote Protocol (MS-NRPC), aka 'Netlogon Elevation of Privilege Vulnerability'. - [Porn Sites redirecting to Exploit Kits – Malsmoke Group](https://firsthackersnews.com/exploit-using-porn-sites-by-malsmoke-group/): A cybercrime group named Malsmoke has been targeting porn sites with malicious ads redirecting users to exploit kits. - [O365 Phishing Attack – Performs Real-Time Active Directory (AD) Authentication](https://firsthackersnews.com/o365-phishing-attack/): Attackers got an eye on the Victims O365 credentials in real-time as they enter their credentials into the phishing page, by using Authentication API's. - [Attackers targeted Data Center giant Equinix](https://firsthackersnews.com/attackers-targeted-data-center-giant-equinix/): Data center giant Equinix has been hit by a ransomware attack. - [BLURtooth Vulnerability](https://firsthackersnews.com/blurtooth-vulnerability/): BLURtooth, is referred to the vulnerability for the devices supporting Bluetooth BR/EDR(Bluetooth Basic Rate/ Enhanced Data Rate) and LE(Bluetooth in Low Energy) using Cross-Transport Key Derivation (CTKD) for pairing to key overwrite, which enables an attacker to gain additional access to profiles or services that are not restricted by reducing the encryption key strength or overwriting an authenticated key with an unauthenticated key. - [Microsoft Patch Tuesday](https://firsthackersnews.com/microsoft-patch-tuesday/): The second Tuesday of each month is the one most commonly referred to as Patch Tuesday. That's when Microsoft releases security-related updates for Windows (desktop and server editions), Office, and related products. The fourth Tuesday of each month is reserved for updates that aren't related to security. - [Ransomware frozen Argentina’s Borders](https://firsthackersnews.com/ransomware-frozen-argentinas-borders/): Argentina's official immigration agency, Dirección Nacional de Migraciones, suffered a Netwalker ransomware attack that temporarily halted for 4 hours of the border crossing into and out of the country. - [ProLock Ransomware](https://firsthackersnews.com/prolock-ransomware-second-flash-alert/): Discovered by PeterM, ProLock is a rebranded version of PwndLocker ransomware. This ransomware encrypts files with the RSA-2048 algorithm, modifies filenames, and creates a ransom message. ProLock appends the " .proLock, .pr0Lock or .proL0ck" extension to the filenames of all encrypted files. - [Another Twitter Account Hack – This time its India’s Prime Minister](https://firsthackersnews.com/another-twitter-account-hack-this-time-its-indias-prime-minister/): On July, there was massive Twitter security breach of 130 high-profiles like US presidential hopeful Joe Biden, Tesla founder Elon Musk and Microsoft founder Bill Gates. - [Norway’s Parliament Hit by Email Attack](https://firsthackersnews.com/norways-parliament-hit-by-email-attack/): Norway parliament's non-elected chief administrator - Marianne Andreassen said that "This has been a significant attack" - [](https://firsthackersnews.com/wordpress-file-manager-plugin-security-update/): A remote code execution vulnerability was found in the WordPress File Manager Plugin. The vulnerability can be exploited by an unauthenticated remote attacker by uploading PHP files containing web shells hidden in an image to the wp-content/plugins/wp-file-manager/lib/files/ directory. Successful exploitation can enable an attacker to execute commands and upload malicious files on a target site. - [VMware RabbitMQ – Security Update](https://firsthackersnews.com/vmware-rabbitmq-security-update/): Short Summary:A code execution vulnerability was found in VMware RabbitMQ. The vulnerability is caused due to a Windows-specific binary planting security flaw. This vulnerability can be exploited by an authenticated local attacker by sending a specially-crafted request. Successful exploitation can enable an attacker to execute arbitrary code on the system. - [Magecart Credit-Card Skimmer](https://firsthackersnews.com/magecart-credit-card-skimmer/): Magecart is a consortium of malicious hacker groups who target online shopping cart systems, usually the Magento system, to steal customer payment card information. This is known as a supply chain attack. - [Cisco IOS XR Software – Security Vulnerability](https://firsthackersnews.com/cisco-ios-xr-software-security-vulnerability/): Multiple vulnerabilities were found in the Distance Vector Multicast Routing Protocol (DVMRP) feature of Cisco IOS XR Software. The vulnerabilities are caused due to insufficient queue management for Internet Group Management Protocol (IGMP) packets. An unauthenticated remote attacker can exploit these vulnerabilities by sending crafted IGMP traffic to an affected device. Successful exploitation can enable an attacker to cause memory exhaustion, resulting in instability of other processes. - [Red Hat CloudForms – 2020:3574 – Security Advisory](https://firsthackersnews.com/red-hat-cloudforms-20203574-security-advisory/): A high severity vulnerability was found in all active versions of Red Hat CloudForms before 5.11.7.0. The out of band OS command injection vulnerability can be exploited by authenticated attacker while setuping conversion host through Infrastructure Migration Solution. This flaw allows attacker to execute arbitrary commands on CloudForms server. - [The new Red Dawn Template – Emotet](https://firsthackersnews.com/the-new-red-dawn-template-emotet/): Emotet is a Trojan that is primarily spread through spam emails (malspam). The infection may arrive either via malicious script, macro-enabled document files, or malicious link. Emotet emails may contain familiar branding designed to look like a legitimate email. - [Power of Honesty Saved Tesla](https://firsthackersnews.com/power-of-honesty-saved-tesla/): Have you invested millions of dollars on your security devices? Better spend half for your employer's. The following realistic honesty will let you know why... - [The Return of Qbot Trojan](https://firsthackersnews.com/the-return-of-qbot-trojan/): Malware is any software intentionally designed to cause damage to a computer, server, client, or computer network. A wide variety of malware types exist, including computer viruses, worms, Trojan horses, ransomware, spyware, adware, rogue software, and scareware. - [Fedora Security Patch Update](https://firsthackersnews.com/fedora-security-patch-update/): Name : chromium - [Security Update – IBM Security Guardium](https://firsthackersnews.com/security-update-ibm-security-guardium/): IBM Security Guardium Insights is affected by an Open Redirect vulnerability - [Security Update – IBM Elastic Storager Server](https://firsthackersnews.com/security-update-ibm-elastic-storager-server/): A vulnerability has been identified in IBM Elastic Storager Server where an attacker can cause a denial of service (CVE-2020-4383) - [Lazarus LinkedIn Job Offer- IOC’s Available To Protect](https://firsthackersnews.com/lazarus-linkedin-job-offer-attack-on-professional-forum/): Lazarus Group who are known as APT38 enact themselves as a Job recruitment division for the US Defence Center. Now they are using LinkedIn and targeting the recipients profile by posting the fake job offers - [Critical WordPress Flaw Enables Remote Code Execution](https://firsthackersnews.com/wordpress-xss2shell-flaw/): Security researchers have uncovered a serious vulnerability chain in WordPress Core, tracked as CVE-2026-64638 and known as XSS2Shell. The flaw could allow attackers to escalate from a simple login page attack to remote code execution (RCE) under specific conditions. - [Windows Hello Key Flaw Opens Door to Entra ID Access](https://firsthackersnews.com/windows-hello-for-business-security-flaw/): Security researcher Dirk-jan Mollema has uncovered a new technique that could allow attackers to misuse Windows Hello for Business (WHFB) to authenticate to Microsoft Entra ID services without requiring the victim's password, PIN, or biometric verification. - [Critical Linux Kernel Flaw Grants Root Access](https://firsthackersnews.com/critical-linux-kernel-flaw-root-access/): A newly discovered Linux kernel vulnerability, tracked as CVE-2026-64564 and named SCTPhantom, could allow attackers with local access to gain full root privileges. Security researchers also demonstrated that the flaw can be used to escape containers and compromise the underlying host system, making it a serious risk for Linux environments. - [Top 10 Phishing Email Red Flags You Should Never Ignore](https://firsthackersnews.com/top-10-phishing-email-red-flags/): Phishing remains one of the most successful cyberattack techniques because it exploits human trust rather than technical vulnerabilities. Every day, attackers send fraudulent emails designed to steal credentials, distribute malware, or trick recipients into revealing sensitive information. - [Fake Roblox Hacks Target Discord and Gaming Credentials](https://firsthackersnews.com/fake-roblox-hacks-target-discord-and-gaming-credentials/): Security researchers have uncovered an ongoing malware campaign that uses fake Roblox Xeno cheat tools to infect gamers with a powerful Java-based Remote Access Trojan (RAT). - [Threat Analysis: DarkSword Framework Leverages iOS Exploits for Apple ID Harvesting](https://firsthackersnews.com/darksword-iphone-exploit-fake-apple-id/): DarkSword, a powerful iPhone exploit kit whose source code was leaked online, is now being used by multiple threat actors to launch large-scale cyberattacks. The latest campaigns combine one-click Safari exploits with fake Apple ID login pages, allowing attackers to steal credentials and compromise iPhones in a single attack. - [Critical Vulnerability Disclosed in VS Code, Cursor, and Google Antigravity](https://firsthackersnews.com/vs-code-cursor-google-antigravity-rce-vulnerability/): A recently patched security vulnerability exposed three popular code editors—Microsoft VS Code, Cursor, and Google Antigravity—to a serious remote code execution (RCE) risk. - [Microsoft Takes Action to Strengthen NuGet Supply Chain Security](https://firsthackersnews.com/microsoft-nuget-security-api-key-lifetime/): Microsoft has announced important security updates for NuGet.org aimed at improving software supply chain security and reducing the risk of compromised developer credentials being used to distribute malicious .NET packages. - [Critical Security Flaw Discovered in N-able N-central](https://firsthackersnews.com/n-able-n-central-vulnerability/): N-able has released an emergency hotfix for a critical authentication bypass vulnerability affecting its N-central Remote Monitoring and Management (RMM) platform. The flaw, tracked as CVE-2026-18577, is being actively exploited and could allow attackers to gain unauthorized administrative access to vulnerable N-central servers. - [Critical TP-Link Router Flaw Enables Remote Code Execution](https://firsthackersnews.com/tp-link-router-vulnerability/): TP-Link has released a security advisory for a high-severity vulnerability affecting the TL-WR940N v6 wireless router. The flaw, tracked as CVE-2026-12935, could allow attackers to execute malicious code on vulnerable devices, potentially giving them full control of the router. - [Google Chrome 151 Patches Critical Vulnerabilities](https://firsthackersnews.com/google-chrome-151-security-update/): Google has released Chrome 151 for Windows, macOS, and Linux, bringing an important security update that fixes 370 vulnerabilities across the browser. The update is being rolled out gradually, so it may take a few days before it becomes available to all users. - [Active Exploitation of Cisco Secure Firewall Zero-Day Prompts CISA Alert](https://firsthackersnews.com/cisa-cisco-secure-firewall-vulnerability/): The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued an alert regarding the active exploitation of a critical security vulnerability affecting Cisco Secure Firewall Management Center (FMC). This vulnerability is known as cisa-cisco-secure-firewall-vulnerability. Organizations using the platform are advised to take immediate action to reduce the risk of compromise. - [New AtlasRAT Attack Uses 4-Stage In-Memory Loader to Target WeChat](https://firsthackersnews.com/atlasrat-malware-in-memory-attack/): Security researchers have uncovered AtlasRAT, a sophisticated modular remote access trojan (RAT) that targets Windows systems using a four-stage in-memory attack chain. Instead of relying on files stored on disk, the malware loads its components directly into memory, making it significantly harder for traditional antivirus solutions to detect. - [Critical Rails Vulnerability Exposes Sensitive Data](https://firsthackersnews.com/ruby-on-rails-vulnerability-cve-2026-66066/): A newly disclosed security vulnerability, tracked as CVE-2026-66066, affects Ruby on Rails' Active Storage component and could allow attackers to read sensitive files from vulnerable servers. In some cases, the flaw could lead to remote code execution (RCE), making it a serious risk for organizations using affected Rails applications. - [New Attack Puts Tor Browser Users at Risk](https://firsthackersnews.com/tor-browser-security-attack/): Cybersecurity researchers have revealed that a single malicious webpage can compromise users running an unpatched version of Tor Browser. The attack exploits a high-severity vulnerability, CVE-2026-10702, which allows attackers to execute malicious code simply by convincing a victim to visit a specially crafted website. - [Apple iOS 26.6 Fixes Critical Security Flaws](https://firsthackersnews.com/apple-ios-26-6-security-update/): Apple has released iOS 26.6 and iPadOS 26.6, delivering an important set of security updates for supported iPhones and iPads. The release addresses multiple vulnerabilities that could allow attackers to execute code with kernel privileges, gain root access, or bypass Apple's app sandbox. - [NeedleStealer Targets Crypto Wallets and Browsers](https://firsthackersnews.com/needlestealer-crypto-wallet-browser-theft/): Cybersecurity researchers have discovered new CastleLoader malware campaigns that now deliver NeedleStealer, a malware family designed to steal cryptocurrency wallet recovery phrases, browser sessions, and user credentials. The latest activity shows that attackers are expanding their capabilities with more advanced tools and new programming languages, making these campaigns increasingly difficult to detect. - [Cybercriminals Use Fake Claude Code to Spread Malware](https://firsthackersnews.com/fake-claude-code-installer/): Cybercriminals are running a new malware campaign that targets macOS users searching online for instructions on installing Claude Code. Instead of exploiting software vulnerabilities, the attackers rely on social engineering and trusted websites to trick users into installing the MacSync infostealer. - [Kimi K3 AI Discovers Redis RCE Flaws](https://firsthackersnews.com/kimi-k3-ai-redis-rce-flaws/): Moonshot AI's latest Kimi K3 model is making headlines after demonstrating its ability to automatically identify critical security flaws in Redis. During testing, the AI agent reportedly found multiple remote code execution (RCE) vulnerabilities in several Redis versions within just 27 minutes. - [Apple Strengthens Hide My Email Privacy with New Security Fix](https://firsthackersnews.com/apple-hide-my-email-vulnerability/): Apple has addressed a privacy vulnerability affecting its Hide My Email feature, an iCloud+ service designed to keep users' personal email addresses private. The flaw raised concerns because it could allow an email alias to be linked back to the user's actual email address, reducing the privacy protection the feature was built to provide. This fix reinforces the commitment to user privacy, highlighting the importance of features like Apple Hide My Email. - [Critical RefluXFS Flaw Threatens Linux Systems](https://firsthackersnews.com/refluxfs-linux-vulnerability/): A newly discovered Linux vulnerability, called RefluXFS (CVE-2026-64600), could allow a local user to gain root access by exploiting a flaw in the Linux kernel's XFS filesystem. Security researchers at Qualys Threat Research Unit (TRU) discovered the issue and warned that it can be exploited even when SELinux is running in Enforcing mode. - [Fake AI Skills Fuel SmartLoader Malware Attack: A New Threat](https://firsthackersnews.com/fake-ai-tools-smartloader-stealc-malware/): The growing adoption of AI assistants, Skills, and Model Context Protocol (MCP) servers has created a new attack surface for cybercriminals. Researchers have uncovered a large-scale campaign in which attackers are abusing GitHub repositories, AI capability registries, and trusted developer resources to distribute SmartLoader and StealC malware. - [Microsoft Defender XDR C2 Detection Gap](https://firsthackersnews.com/microsoft-defender-xdr-detection-gap/): Security teams using Microsoft Defender XDR should be aware of a detection gap that can cause command-and-control (C2) traffic to be missed during threat hunting and investigations. The issue is related to how Microsoft Defender XDR classifies certain IP addresses in the DeviceNetworkEvents table. - [Microsoft Ends Copilot Podcasts and Access](https://firsthackersnews.com/microsoft-copilot-podcasts/): Microsoft has announced that it will retire the Podcasts feature in the consumer Copilot app on August 18, 2026. After this date, users will no longer be able to create new AI-generated podcasts or access any podcasts they created previously. - [Attackers Target SonicWall SMA1000 Zero-Days](https://firsthackersnews.com/sonicwall-sma1000-zero-day/): Cybersecurity researchers have uncovered active attacks targeting two critical zero-day vulnerabilities in SonicWall SMA 1000 Series remote access appliances. By combining these flaws, attackers can gain unauthorized access to vulnerable systems and execute commands with root-level privileges, potentially taking complete control of the affected appliance. - [Critical Flaw Found in Shark Robot Vacuums](https://firsthackersnews.com/shark-robot-vacuum-vulnerability/): A newly disclosed security vulnerability could put millions of internet-connected Shark robot vacuums at risk. According to security researchers, the flaw could allow attackers to remotely execute commands, access sensitive device data, and potentially take control of affected vacuums. - [NuGet Packages Deliver Pepesoft Malware](https://firsthackersnews.com/malicious-nuget-packages-2/): Security researchers have identified 11 malicious NuGet packages disguised as game cheats, automation bots, and management tools. Instead of providing the advertised functionality, these packages install a Windows malware known as Pepesoft. - [WinFsp Security Flaw Enables Privilege Escalation](https://firsthackersnews.com/winfsp-vulnerability/): A recently identified security flaw in WinFsp could allow attackers with local access to elevate their privileges and gain SYSTEM-level control of affected Windows machines. The vulnerability, tracked as CVE-2026-3006, impacts WinFsp 2.1.25156 and earlier, and has been addressed in a newer release. - [Thousands of Phishing Domains Target Turkish Banks](https://firsthackersnews.com/turkish-bank-phishing-campaign/): Cybercriminals are running a large-scale phishing campaign targeting Turkish banks through fake banking websites, fraudulent advertisements, and scam loan offers. Researchers found more than 8,400 phishing domains and over 6,600 malicious advertisements on Facebook and Instagram designed to steal banking credentials and personal information. - [Debian 13.6 Brings Major Security Fixes](https://firsthackersnews.com/debian-13-6-security-updates/): The Debian Project has released Debian 13.6, the latest update for the stable Debian 13 "Trixie" release. Published on July 11, 2026, this update includes important security patches, bug fixes, and updated installation images. - [RabbitMQ OAuth Bug Allows Unauthorized Access](https://firsthackersnews.com/rabbitmq-oauth-flaw/): Security researchers have disclosed two access-control vulnerabilities in RabbitMQ, the popular open-source message broker used by organizations worldwide. If exploited, these flaws could allow attackers to gain administrative control of a RabbitMQ server or access sensitive information about queues and users. - [Android VPN Apps Expose User Traffic](https://firsthackersnews.com/android-vpn-apps-security-risks/): The primary purpose of a VPN is to route all internet traffic through an encrypted tunnel, preventing unauthorized parties from monitoring user activity. However, researchers found that many Android VPN apps fail to protect all network traffic. - [Linux FUSE Vulnerability Allows Root Access](https://firsthackersnews.com/linux-fuse-vulnerability-root-access/): newly disclosed Linux kernel vulnerability, tracked as CVE-2026-31694, allows unprivileged local users to gain root privileges on affected systems. The flaw exists in the Linux FUSE (Filesystem in Userspace) subsystem and affects the way directory entries are stored in the kernel page cache. - [GodDamn Ransomware Campaign Uses Legitimate Tools to Evade Detection](https://firsthackersnews.com/goddamn-ransomware-attack/): Ransomware operators continue to evolve their tactics, and the latest GodDamn ransomware campaign highlights how attackers are increasingly relying on legitimate software rather than custom malware to compromise enterprise environments. - [WordPress Plugin Vulnerabilities Enable RCE](https://firsthackersnews.com/wordpress-plugin-vulnerabilities-rce/): A large-scale cyber campaign is actively exploiting known vulnerabilities in content management systems (CMS), with WordPress plugins being the primary target. Attackers are scanning the internet for vulnerable websites and quickly exploiting unpatched systems. - [GitHub Signature Flaw Enables Duplicate Verified Commits](https://firsthackersnews.com/github-signature-flaw/): A recently disclosed security finding has revealed that attackers can create duplicate "Verified" GitHub commits by exploiting a technique known as signature malleability. Although the duplicated commit is assigned a different hash, it contains the same source code, remains cryptographically valid, and continues to display GitHub's trusted "Verified" badge. - [SindriKit 1.3.0 Bypasses EDR Security](https://firsthackersnews.com/sindrikit-1-3-0/): To counter these detection methods, SindriKit 1.3.0 adds dynamic call stack spoofing, allowing malicious execution to appear as though it originated from legitimate Windows components. - [Malicious AI Skills Threaten Enterprise Security](https://firsthackersnews.com/malicious-ai-skills/): Security researchers have discovered that malicious AI agent skills can be designed to steal credentials, extract source code, and install backdoors while avoiding detection by many existing security scanning tools. - [Opera GX Flaw Allows CSS Injection](https://firsthackersnews.com/opera-gx-security-flaw/): Security researchers have uncovered a critical vulnerability in Opera GX that could allow attackers to inject malicious CSS across every webpage a victim visits. - [Critical Veeam Backup Flaw Discovered](https://firsthackersnews.com/veeam-backup-flaw/): Security researchers have discovered a high-severity vulnerability in Veeam Backup & Replication, tracked as CVE-2026-44963, that could allow authenticated domain users to execute remote code on backup servers. - [Parrot 7.3 Launches with New Features](https://firsthackersnews.com/parrot-7-3/): The Parrot Security team has released Parrot 7.3, focusing on performance, usability, and overall system improvements instead of adding a large number of new security tools. - [India Bans Apps Used to Stop E-Rickshaws Remotely](https://firsthackersnews.com/e-rickshaw-apps/): The Indian government has directed Google and Apple to remove three mobile applications—BAT-BMS, Lossigy, and Epoch-i-ion—after they were allegedly misused to remotely disable e-rickshaws while they were carrying passengers. - [Claude Cowork Sandbox Flaw Allows Root Access](https://firsthackersnews.com/claude-cowork-sandbox/): Security researchers have uncovered a vulnerability chain in Anthropic's Claude Cowork Sandbox that allows a local attacker to bypass multiple security protections and execute arbitrary commands as root inside the product's isolated Linux sandbox. - [Fake Installers Spread AsyncRAT Using ScreenConnect](https://firsthackersnews.com/asyncrat-screenconnect/): Cybersecurity researchers have uncovered a large-scale malware campaign in which threat actors are abusing the legitimate ScreenConnect remote access software to deliver AsyncRAT through fake software installers. - [Attackers Target Oracle E-Business Suite Flaw](https://firsthackersnews.com/oracle-ebs-flaw/): Security researchers have identified around 950 internet-facing Oracle EBS Flaw instances following expanded internet scanning, while attackers have already begun exploiting CVE-2026-46817 in real-world attacks. - [New ARToken Panel Targets Microsoft 365 Tokens](https://firsthackersnews.com/artoken-panel-microsoft-365-tokens/): Security researchers at Cisco Talos have uncovered a phishing-as-a-service (PhaaS) platform called ARToken that appears to be closely linked to the previously identified EvilTokens infrastructure. - [CISA Flags SimpleHelp Flaw as Actively Exploited](https://firsthackersnews.com/simplehelp-vulnerability/): The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2026-48558, a critical vulnerability affecting SimpleHelp remote support software, to its Known Exploited Vulnerabilities (KEV) catalog. The listing confirms that the flaw is being actively exploited, and organizations are urged to apply security updates without delay. - [Malicious Extension Swaps Crypto Wallet Addresses](https://firsthackersnews.com/malicious-browser-extension-crypto/): Cybersecurity researchers have uncovered a sophisticated campaign distributing a malicious Chromium-based browser extension that silently replaces cryptocurrency wallet addresses during transactions. Disguised as a lightweight "Google Notes" extension, the malware is designed to steal digital assets without alerting the victim. - [Hackers Exploit Claude Code to Take Over Systems](https://firsthackersnews.com/claude-code-attack/): Researchers from Mozilla's Zero Day Investigative Network (0DIN) have demonstrated a proof-of-concept (PoC) attack showing how a seemingly harmless GitHub repository can manipulate AI coding assistants such as Claude Code into opening a reverse shell on a developer's machine. Notably, the repository itself contains no malicious code, making the attack difficult to identify through a normal code review. - [WhatsApp Introduces Usernames for Private Messaging](https://firsthackersnews.com/whatsapp-usernames/): Unlike many social media platforms, WhatsApp usernames are not searchable through a public directory. Users cannot browse or discover other usernames unless they already know the exact handle, significantly reducing unsolicited messages and unwanted contact. - [Langflow Vulnerability Deploys Monero Miner](https://firsthackersnews.com/langflow-rce-exploit-monero-cryptominer/): Cybersecurity researchers have identified an active campaign exploiting CVE-2026-33017, a critical remote code execution (RCE) vulnerability in Langflow, to compromise internet-facing AI servers and deploy a customized Monero (XMR) cryptominer. - [Splunk Secure Gateway RCE Vulnerability Discovered](https://firsthackersnews.com/splunk-secure-gateway-rce/): A high-severity vulnerability, CVE-2026-20251, has been identified in Splunk Secure Gateway (SSG), potentially allowing authenticated users with low-level privileges to execute arbitrary code on affected systems. The flaw carries a CVSS score of 8.8 and poses a significant risk to organizations using Splunk Secure Gateway in enterprise environments. - [Fake Shopify Invoices Steal User Credentials](https://firsthackersnews.com/shopify-fake-invoice-scam/): Cybersecurity researchers have uncovered a new phishing campaign in which scammers abuse Shopify and its Shop order-tracking app to deliver fake invoices directly to users. Instead of relying on traditional phishing emails, attackers are placing fraudulent purchase notifications inside a trusted shopping application, making the scam appear more convincing. - [Langflow RCE Vulnerability: Unauthenticated Code Execution Risk](https://firsthackersnews.com/langflow-rce-vulnerability/): A critical security vulnerability, CVE-2026-33017, has been discovered in Langflow, an open-source platform used to build AI workflows, large language model (LLM) applications, and Retrieval-Augmented Generation (RAG) pipelines. Researchers report that the flaw is already being actively exploited, allowing attackers to execute arbitrary Python code on vulnerable servers without requiring authentication. - [ManageEngine AD360 Vulnerability Discovered](https://firsthackersnews.com/manageengine-ad360-vulnerability-account-takeover/): ManageEngine has released security updates to address a critical vulnerability, CVE-2026-11374, affecting its AD360 identity and access management platform. The flaw impacts several integrated products that rely on AD360 for single sign-on (SSO), potentially allowing attackers to take over user accounts without valid credentials. - [Microsoft Teams-Themed Attack Deploys Remote Access Tool](https://firsthackersnews.com/microsoft-teams-phishing-remote-access-tools/): Security researchers have uncovered an active phishing campaign that leverages Microsoft Teams-themed lures to distribute legitimate remote access software configured for unauthorized access. By impersonating trusted workplace collaboration services, threat actors are increasing the likelihood that users will interact with malicious links and download compromised installers. This significant threat highlights the dangers of Microsoft Teams phishing. - [Malware Hidden in Fake Android Reader App](https://firsthackersnews.com/fake-document-reader-app-anatsa-malware/): Cybersecurity researchers have uncovered a new Android malware campaign that used a fake document reader application to distribute the Anatsa banking trojan. The app appeared to be a legitimate file-reading utility on the Google Play Store and gained more than 100,000 downloads before malicious functionality was activated. - [Popular Smart TV Apps Found Exploiting User Connections](https://firsthackersnews.com/smart-tv-privacy-risk/): Smart TVs have become a common part of modern households, offering streaming services, gaming, and smart home connectivity. However, new research suggests that some smart TV applications may be doing more than users realize behind the scenes, raising significant Smart TV Privacy Risk. - [LastPass Impacted by Klue OAuth Token Breach](https://firsthackersnews.com/lastpass-data-exposed-klue-supply-chain-attack/): A security incident involving third-party platform Klue has resulted in unauthorized access to a limited amount of customer data belonging to LastPass. The breach was not caused by a direct compromise of LastPass systems but instead stemmed from attackers abusing OAuth tokens connected to enterprise integrations. This incident has led to significant concerns about the LastPass Data Exposed. - [Scope Squatting Vulnerability Exposed in ClawHub Plugin Registry](https://firsthackersnews.com/clawhub-scope-squatting/): A recently disclosed supply chain weakness in ClawHub's plugin registry allowed third-party developers to publish plugins under organizational namespaces they did not own. As a result, unofficial plugins appeared to be legitimate OpenClaw or ClawHub integrations, creating a significant trust and security concern for users. - [Critical Splunk AI Toolkit Vulnerability Discovered](https://firsthackersnews.com/splunk-ai-toolkit-vulnerability/): Splunk has released a security update to address a critical vulnerability in its AI Toolkit that could allow attackers with administrative access to run unauthorized operating system commands on affected servers. The issue poses a significant risk to organizations that use Splunk for security monitoring, analytics, and automation. - [F5 NGINX Vulnerabilities Patched in Critical Security Update](https://firsthackersnews.com/f5-nginx-vulnerabilities-patched/): F5 has issued an emergency security advisory addressing several vulnerabilities affecting NGINX products and related components. The flaws could allow attackers to disrupt services, crash applications, or potentially execute malicious code in vulnerable environments. - [Hackers Use GitHub Pages for Phishing Attacks](https://firsthackersnews.com/github-pages-phishing/): Researchers have uncovered a sophisticated phishing campaign targeting banking customers in Mexico through a highly scalable and resilient attack infrastructure. The operation leverages GitHub Pages to host convincing phishing websites designed to steal login credentials, payment card information, and customer data. - [Sapphire Sleet Targets macOS With Multi-Stage Malware](https://firsthackersnews.com/sapphire-sleet-macos-malware/): Researchers have uncovered a new macOS malware campaign linked to the North Korean threat group known as Sapphire Sleet. The attackers are using fake software update files disguised as Zoom and Microsoft Teams SDK updates to trick users into infecting their systems. - [Rokarolla Android Malware Disables Google Play Protect to Gain Full Device Control](https://firsthackersnews.com/rokarolla-android-malware-device-control/): Security researchers have identified Rokarolla, a sophisticated Android malware that disables Google Play Protect and abuses accessibility services to gain extensive control over infected devices. Once deployed, the malware can facilitate remote access, steal sensitive information, and bypass built-in Android security protections. - [UNC3753 Exploits Screen-Sharing Sessions and RMM Tools to Steal Sensitive Legal Data](https://firsthackersnews.com/unc3753-rmm-legal-data-theft/): UNC3753 is targeting legal organizations by exploiting screen-sharing sessions and RMM software to steal sensitive data. The campaign demonstrates the growing use of legitimate remote access tools in modern cyber espionage and data theft operations. - [PRC-Linked Threat Actors Target REDCap Servers to Spy on U.S. Medical Research Organizations](https://firsthackersnews.com/prc-redcap-medical-espionage/): PRC-linked hackers are targeting REDCap servers to conduct cyber espionage against U.S. medical research organizations. The campaign underscores the increasing risks facing healthcare, research, and academic sectors as threat actors seek access to valuable scientific and medical data. - [Critical LiteSpeed cPanel Plugin Vulnerability Enables Root Privilege Escalation Attacks](https://firsthackersnews.com/litespeed-cpanel-root-escalation/): CISA has warned of active exploitation targeting a critical LiteSpeed cPanel plugin vulnerability that enables root privilege escalation. Security teams are urged to patch affected systems immediately to prevent unauthorized access and potential server compromise. - [New Sniper Dz Scam Operation Exploits MENA Users with Fraudulent Facebook Offers](https://firsthackersnews.com/sniper-dz-mena-facebook-scam/): A new Sniper Dz scam campaign is targeting users across the Middle East and North Africa (MENA) through fraudulent Facebook offers and deceptive browser alerts. Researchers warn that the operation uses social engineering tactics to lure victims into financial scams, credential theft, and other online fraud activities. - [Hidden Ad Tracking Operations Found Across 152 Chrome Browser Extensions](https://firsthackersnews.com/chrome-extension-ad-tracking/): Security researchers discovered 152 Chrome browser extensions secretly conducting ad tracking and generating fake Google search traffic, highlighting growing concerns around browser extension security and user privacy. - [Critical Oracle PeopleSoft Zero-Day RCE Vulnerability Actively Exploited by ShinyHunters](https://firsthackersnews.com/oracle-peoplesoft-zero-day-rce/): Cybersecurity researchers have identified an active exploitation campaign targeting Oracle PeopleSoft environments through a critical Remote Code Execution (RCE) vulnerability tracked as CVE-2026-35273. The flaw affects Oracle PeopleSoft PeopleTools and can be exploited remotely without authentication, making it a high-risk threat for organizations running vulnerable instances. - [Critical GreatXML Vulnerability Enables Windows BitLocker Bypass via Recovery Partition XML Files](https://firsthackersnews.com/greatxml-bitlocker-bypass/): A newly disclosed Windows security vulnerability known as GreatXML has raised concerns among cybersecurity professionals. The exploit allows attackers to potentially bypass Microsoft BitLocker by abusing XML files stored within the Windows Recovery Environment (WinRE) recovery partition. Researchers found that files created by Microsoft Defender Offline Scan can be manipulated to obtain a SYSTEM-level command shell while the device is in recovery mode. - [Internet Explorer Component Flaw Enables RCE Attacks](https://firsthackersnews.com/ie-security-flaw-rce/): Although Internet Explorer has been retired, some of its underlying components are still present in many Windows applications. Security researchers have now demonstrated how these legacy components can be abused to turn simple user actions into remote code execution attacks. - [Google Patches 429 Chrome Security Flaws](https://firsthackersnews.com/chrome-vulnerabilities-patched/): Google has released Chrome 149 for Windows, macOS, and Linux, fixing a large number of security vulnerabilities across the browser. The update addresses a total of 429 security issues, including 22 critical vulnerabilities and several other Chrome Vulnerabilities that could potentially be exploited by attackers. - [VMware Stored XSS Flaws Put Enterprise Environments at Risk](https://firsthackersnews.com/vmware-stored-xss-flaws/): VMware has disclosed three high-severity security vulnerabilities affecting VMware Cloud Foundation (VCF) Operations that could allow attackers to inject malicious scripts into management interfaces. - [Hackers Exploit Trusted Tools Malware for Attacks](https://firsthackersnews.com/trusted-tools-malware/): Cybercriminals are increasingly abusing legitimate system tools to launch Trusted Tools Malware attacks while avoiding detection. According to a recent Q1 2026 Cyber Risk Report from ANY.RUN, attackers are relying more heavily on trusted Windows utilities to gain access, steal credentials, and deploy malware without triggering traditional security defenses. - [Critical UniFi OS Vulnerabilities Allow Root RCE](https://firsthackersnews.com/unifi-os-vulnerabilities-root-rce/): Ubiquiti has released security updates for three critical vulnerabilities affecting UniFi OS that could allow attackers to gain full control of vulnerable systems without needing a username, password, or any user interaction. These vulnerabilities are recognized as significant UniFi OS Vulnerabilities. - [Stolen Gemini API Keys Power Automated Telegram Campaign](https://firsthackersnews.com/stolen-gemini-api-keys/): Researchers have uncovered a long-running operation in which a single threat actor used stolen Google Gemini API keys and modified AI tools to automate content creation, fraud activities, and online infrastructure management. - [Meta AI Flaw Linked to Instagram Password Resets](https://firsthackersnews.com/meta-ai-vulnerability-instagram/): A recently disclosed issue involving Meta’s AI-powered support system has raised concerns about the security of Instagram accounts. Researchers claim that attackers were able to abuse the platform’s account recovery process to request password reset codes without properly verifying ownership of the targeted account. - [Microsoft Denies Lawsuit Threats Against Researchers](https://firsthackersnews.com/microsoft-security-researchers-clarification/): Microsoft has publicly stated that it does not plan to take legal action against security researchers who responsibly discover and share vulnerabilities. - [Magento Cache Plugin Vulnerability Enables RCE Attacks](https://firsthackersnews.com/magento-cache-plugin-vulnerability-rce/): A newly disclosed security vulnerability in a popular Magento caching extension could allow attackers to take complete control of affected online stores. - [New FROST Technique Lets Websites Monitor SSD Activity](https://firsthackersnews.com/frost-ssd-timing-attack/): Security researchers have discovered a new browser-based side-channel attack called FROST SSD Timing Attack that allows malicious websites to monitor SSD activity and potentially track what users are doing on their devices. - [Anthropic Launches Claude Opus 4.8 for Advanced Coding Tasks](https://firsthackersnews.com/claude-opus-4-8-released/): Anthropic has introduced Claude Opus 4.8, the latest version of its flagship AI model designed to handle complex software engineering tasks with greater accuracy, autonomy, and efficiency. - [Hidden Motorola App Redirects Amazon Traffic](https://firsthackersnews.com/motorola-amazon-affiliate-redirect-privacy-concerns/): A hidden application discovered on Motorola smartphones has sparked privacy and security concerns after researchers found it quietly rerouting Amazon app launches through affiliate tracking links. - [Angular Language Service Vulnerabilities Enable RCE Attacks](https://firsthackersnews.com/angular-language-service-vulnerabilities-enable-rce-attacks/): Angular Language Service Vulnerabilities have exposed developers to serious remote code execution risks through malicious VS Code projects and unsafe extension behavior. - [EU Moves Closer to Major Fine Against Google](https://firsthackersnews.com/google-dma-fine-eu-search-practices/): The European Union is preparing a major penalty against Google under the Digital Markets Act (DMA), increasing pressure on large technology companies over competition and platform fairness. - [WhatsApp Chat Data Found Stored Without Encryption](https://firsthackersnews.com/whatsapp-chats-exposed-unencrypted-storage/): Security researchers have raised concerns about how WhatsApp stores chat data on macOS and iOS devices. According to recent findings, message databases may be stored in plaintext inside shared app group containers, potentially exposing sensitive conversations under certain conditions. - [Cloud Atlas APT Uses Modified termsrv.dll to Enable Hidden RDP Access](https://firsthackersnews.com/cloud-atlas-apt-patches-termsrvdll-hidden-rdp-access/): The Cloud Atlas advanced persistent threat (APT) group, also referred to as Cloud Atlas APT, has been linked to a sophisticated cyber espionage campaign that abuses the Windows termsrv.dll library to enable multiple Remote Desktop Protocol (RDP) sessions on compromised systems. - [Microsoft Defender Zero-Day Discovered](https://firsthackersnews.com/microsoft-defender-zero-day-exploited/): Microsoft Defender zero-day vulnerabilities tracked as CVE-2026-41091 and CVE-2026-45498 are actively being exploited in real-world attacks. The flaws could allow privilege escalation and denial-of-service attacks on affected systems. - [Apache OFBiz Vulnerability Enables Authentication Bypass](https://firsthackersnews.com/apache-ofbiz-vulnerability-authentication-bypass/): An Apache OFBiz vulnerability tracked as CVE-2026-45434 could allow attackers to bypass authentication protections and execute malicious code on vulnerable servers through a crafted HTTP request. The flaw, tracked as CVE-2026-45434, affects all Apache OFBiz versions before 24.09.06 and carries a high CVSS score of 8.8. - [ExifTool Flaw Allows Mac System Compromise](https://firsthackersnews.com/exiftool-vulnerability-mac-compromise/): A newly discovered vulnerability in ExifTool could allow attackers to execute malicious commands on macOS systems through specially crafted image files. The ExifTool vulnerability, tracked as CVE-2026-3102, affects ExifTool versions 13.49 and earlier and raises serious concerns for organizations that process large volumes of media files. - [VoidStealer Steals Chrome Browser Data](https://firsthackersnews.com/voidstealer-malware-chrome-data/): A newly discovered infostealer known as VoidStealer is drawing attention from security researchers after demonstrating the ability to bypass browser protections designed to secure sensitive Chrome data. The malware targets Google Chrome’s App-Bound Encryption (ABE), a security feature introduced to better protect stored credentials and session cookies. - [NGINX Vulnerability Enables Remote Code Execution](https://firsthackersnews.com/nginx-vulnerability-rce/): An NGINX vulnerability tracked as CVE-2026-42945 is being actively exploited by attackers. The flaw affects NGINX Open Source and NGINX Plus and could lead to server crashes or remote code execution under specific conditions. - [Gamaredon Phishing Attacks Use GammaDrop Malware](https://firsthackersnews.com/gamaredon-phishing-attacks/): A sustained cyber-espionage campaign linked to the Gamaredon threat group is actively targeting Ukrainian government organizations through large-scale phishing attacks and multi-stage malware delivery chains. The operation combines social engineering, abuse of trusted infrastructure, and custom malware loaders to maintain long-term access to compromised systems. - [Gunra Ransomware Expands Through RaaS Operations](https://firsthackersnews.com/gunra-ransomware-raas/): Gunra ransomware is rapidly evolving into a more mature and organized cybercrime operation following its transition from a Conti-based ransomware variant to a dedicated Ransomware-as-a-Service (RaaS) platform. Since emerging in 2025, the group has steadily expanded its operational capabilities, increasing both the scale and sophistication of its attacks. - [WordPress Plugin Bug Exposes Websites](https://firsthackersnews.com/wordpress-plugin-vulnerability-access/): A critical vulnerability in a popular WordPress plugin has put more than 200,000 websites at risk of unauthorized access. The issue was discovered in the Burst Statistics plugin, a privacy-focused analytics tool widely used across WordPress environments. - [MongoDB Vulnerability Allows Arbitrary Code Execution](https://firsthackersnews.com/mongodb-vulnerability-code-execution/): A critical vulnerability in MongoDB, tracked as CVE-2026-8053, could allow attackers to execute arbitrary code on affected database servers. This issue poses a serious risk to organizations relying on MongoDB for handling sensitive data and backend operations. - [Zoom Vulnerability Allows Privilege Escalation Attacks](https://firsthackersnews.com/zoom-vulnerability-privilege-escalation/): Zoom has addressed a set of newly discovered vulnerabilities in its software that could be exploited to gain elevated access or expose sensitive information. These flaws affect Zoom applications on Windows and iOS, with the most critical risks centered around privilege escalation in enterprise environments. - [Microsoft 365 Copilot Bug Risks Data Exposure](https://firsthackersnews.com/microsoft-365-copilot-bug-risks-data-exposure/): Microsoft has disclosed three high-severity information disclosure vulnerabilities affecting Microsoft 365 Copilot and Copilot Chat in Microsoft Edge. These flaws could allow attackers to bypass logical security boundaries and access sensitive enterprise data handled by the AI system. - [DeepSeek Repositories Scam Spreads Malware](https://firsthackersnews.com/fake-deepseek-malware-github/): Hackers are again targeting developers and AI users by creating fake versions of popular tools on GitHub. This time, they are impersonating DeepSeek TUI, a real terminal-based tool that lets users interact with DeepSeek AI models from the command line. This rise in deceptive practices is a clear indication of the threat posed by Fake DeepSeek malware. ## Pages - [About Us](https://firsthackersnews.com/aboutus/): First Hackers News is a global cybersecurity news platform dedicated to delivering the latest updates on cyber attacks, security vulnerabilities, hacking incidents, data breaches, and emerging technology threats. - [Careers](https://firsthackersnews.com/careers/): For Employee - [Contact](https://firsthackersnews.com/contact/): If you would like to get in touch with for any reasons, use the contact form given below. - [PODCASTS](https://firsthackersnews.com/podcast/): The FirstHackersNews Podcast brings together leading voices from the global cybersecurity community to discuss the most critical topics shaping the digital security landscape. - [Security Training – SOC BUCKS](https://firsthackersnews.com/security-training/): The Security Training powered by SOC Bucks is a professional cybersecurity learning platform designed to develop the next generation of security defenders, SOC analysts, and cybersecurity professionals. - [Security Advisories](https://firsthackersnews.com/securityadvisory/): The Security Advisory section of FirstHackersNews delivers timely, research-driven cybersecurity alerts to help organizations, security professionals, and technology leaders stay ahead of emerging digital threats. - [Blog](https://firsthackersnews.com/blog/) - [Home](https://firsthackersnews.com/https-firsthackersnews-com/)