Tag: hacked

Russian Hackers Target Ukrainian Organizations Using Stealthy Living-Off-the-Land Tactics
News

Russian Hackers Target Ukrainian Organizations Using Stealthy Living-Off-the-Land Tactics

Russian-origin threat actors have targeted Ukrainian organizations in an effort to steal confidential information and keep ongoing access to compromised networks. According to a recent assessment from the Symantec and Carbon Black Threat Hunter Team, the activity targeted a local government organization in the nation for a week and a large commercial services organization for two months. In order to minimize digital footprints and remain undiscovered for extended periods of time, the attackers mostly used dual-use tools and living-off-the-land (LotL) strategies, in conjunction with limited malware. The cybersecurity teams controlled by Broadcom said in a study published with The Hacker News that the attackers obtained access to the business services organization by installing web...
Hackers Access SonicWall Cloud Firewall Backups, Spark Urgent Security Checks
News

Hackers Access SonicWall Cloud Firewall Backups, Spark Urgent Security Checks

On Wednesday, SonicWall revealed that all customers who had utilized the cloud backup service had their firewall configuration backup files accessed by an unauthorized party. According to the firm, having access to the files could raise the possibility of targeted assaults even though encryption is still in place. The files contain encrypted credentials and configuration data. Additionally, it mentioned that it has provided tools to help with device assessment and remediation and that it is trying to contact all partners and customers. Users are also being urged by the firm to log in and look for their gadgets. The change was made a few weeks after SonicWall advised users to reset their credentials following a security breach that affected MySonicWall accounts and exposed their f...
Oxford City Council suffers breach exposing two decades of data
News

Oxford City Council suffers breach exposing two decades of data

According to Oxford City Council, there was a data breach that allowed hackers to access personally identifiable information stored in legacy systems. As stated on the website, the incident also resulted in a disruption of ICT services. While the majority of the affected systems have been restored to operation, the residual backlogs can still create delays. In Oxford, England, Oxford City Council is the local government body in charge of overseeing vital public services such housing, planning, waste management, environmental health, and elections. Although the city has a population of about 155,000, the authority has a greater impact because of its international renown because to the University of Oxford, tourism, and research facilities. According to a statement on its websit...
Iranian Hacker Pleads Guilty in $19 Million Robbinhood Ransomware Attack on Baltimore
News

Iranian Hacker Pleads Guilty in $19 Million Robbinhood Ransomware Attack on Baltimore

Due to his involvement in a global ransomware and extortion conspiracy involving the Robbinhood malware, an Iranian national entered a guilty plea in the United States. According to reports, 37-year-old Sina Gholinejad (also known as Sina Ghaaf) and his accomplices broke into the computer networks of several US firms and used Robbinhood ransomware to encrypt files in order to extort Bitcoin ransom payments. After being taken into custody in North Carolina at the beginning of January, Gholinejad entered a guilty plea to one count of conspiracy to commit wire fraud and one count of computer fraud and abuse. He might be imprisoned for up to 30 years. In August 2025, he will be sentenced. The City of Greenville, North Carolina, and the City of Baltimore, Maryland, suffered tens of mi...
Russian Hackers Breach 20+ NGOs Using Evilginx Phishing via Fake Microsoft Entra Pages
News

Russian Hackers Breach 20+ NGOs Using Evilginx Phishing via Fake Microsoft Entra Pages

Microsoft has revealed a hitherto unreported cluster of malicious behavior that it claims is related to global cloud exploitation and comes from a threat actor with ties to Russia called Void Blizzard (also known as Laundry Bear). The hacking group, which has been active since at least April 2024, is associated with espionage activities that primarily target organizations that are crucial to Russian government goals, such as those in the European and North American government, defense, transportation, media, non-governmental organizations (NGOs), and healthcare sectors. According to a report released today by the Microsoft Threat Intelligence team, they frequently use stolen sign-in credentials that they most likely purchase from online marketplaces to enter companies. They steal a ...
ChatGPT is finally adding Download as PDF for Deep Research
News

ChatGPT is finally adding Download as PDF for Deep Research

The ability to save the report as a PDF is finally being added to ChatGPT's Deep Research feature, which enables you to perform multi-step research for challenging assignments. You can let the AI agent handle the task on your own with ChatGPT's Deep Research. After receiving your alert, ChatGPT reads hundreds of webpages and does an internet scan to produce an extensive report. You can choose to copy a report after it has been created, but the problem with the "copy" button is that the formatting is lost. According to BleepingComputer's tests, the formatting of ChatGPT's deep research report is distorted when it is copied into a Word document. A fresh download as PDF might resolve this. Tibor on X noticed that ChatGPT's "Download as PDF" feature is now being tested on the online ...
Fake Security Plugin on WordPress Enables Remote Admin Access for Attackers
News

Fake Security Plugin on WordPress Enables Remote Admin Access for Attackers

Researchers studying cybersecurity have revealed a new campaign that poses as a security plugin and targets WordPress websites. The plugin, called "WP-antymalwary-bot.php," has several functions to execute remote code, conceal itself from the admin dashboard, and preserve access. According to a research by Marco Wotschka of Wordfence, it also includes code that aids in the propagation of malware into other directories and inserts malicious JavaScript that serves advertisements, as well as pinging capability that can report back to a command-and-control (C&C) server. Since its initial discovery in late January 2025 during a site cleanup, numerous versions of the malware have been found in the wild. Several more names for the plugin read more about Fake Security Plugin on WordP...
Pakistan-Linked Hackers Expand Targets in India with CurlBack RAT and Spark RAT
Business

Pakistan-Linked Hackers Expand Targets in India with CurlBack RAT and Spark RAT

A Pakistani threat actor has been seen using remote access trojans such as Xeno RAT, Spark RAT, and CurlBack RAT, a family of malware that has not yet been identified, to attack different sectors in India. The hacking crew's targeting footprint was extended outside the government, defense, maritime, and academic sectors when SEQRITE discovered the activity in December 2024. It targeted Indian companies under the ministries of railway, oil and gas, and external affairs. One significant change in recent campaigns is the use of Microsoft Installer (MSI) packages as the main staging technique instead of HTML Application (HTA) files, according to security researcher Sathwik Ram Prakki. SideCopy is thought to be a Transparent Tribe (also known as APT36) sub-cluster that has been operat...
Hackers exploit Four-Faith router flaw to open reverse shells
News

Hackers exploit Four-Faith router flaw to open reverse shells

Threat actors are opening reverse shells back to the attackers by taking use of a post-authentication remote command injection vulnerability in Four-Faith routers, identified as CVE-2024-12856. On December 20, 2024, VulnCheck notified Four-Faith of the active exploitation after discovering the malicious activities. It is unclear, though, if there are any security fixes available at this time for the vulnerability. On December 20, 2024, we informed Four-Faith and our clients of this problem. Four-Faith should be contacted with any questions regarding fixes, impacted models, and impacted firmware versions read more about Hackers exploit Four-Faith router flaw to open reverse shells. Get up to date on the latest cybersecurity news and enhance your knowledge of cyberse...
Hackers Weaponize Visual Studio Code Remote Tunnels for Cyber Espionage
News

Hackers Weaponize Visual Studio Code Remote Tunnels for Cyber Espionage

As part of a campaign codenamed Operation Digital Eye, a suspected cyber espionage group with ties to China has been implicated in attacks against major business-to-business IT service providers in Southern Europe. In a joint report provided to The Hacker News, cybersecurity firms SentinelOne SentinelLabs and Tinexta Cyber stated that the intrusions occurred between late June and mid-July 2024. They also noted that the operations were identified and stopped before they could reach the data exfiltration stage. According to security researchers Luigi Martire and Aleksandar Milenkoski, the hacks might have given the enemies the opportunity to compromise downstream organizations and create strategic footholds read more about Hackers Weaponize Visual Studio Code Remote Tunnels for Cyber ...