Tag: hackers news

Hackers Exploit Critical WordPress Theme Flaw to Hijack Sites via Remote Plugin Install
News

Hackers Exploit Critical WordPress Theme Flaw to Hijack Sites via Remote Plugin Install

A serious security hole in the "Alone – Charity Multipurpose Non-profit WordPress Theme" is being actively used by threat actors to take control of vulnerable websites. The vulnerability has a CVSS score of 9.8 and is tagged as CVE-2025-5394. The bug's discovery and reporting are attributed to security researcher Thái An. Wordfence claims that the flaw is related to an arbitrary file upload that impacts all plugin versions before and including 7.8.3. Version 7.8.5, which was made available on June 16, 2025, addressed it. Originating from a plugin installation function called "alone_import_pack_install_plugin()" and resulting from a missing capability check, CVE-2025-5394 enables unauthenticated users to execute malware by deploying arbitrary plugins from external sources using AJ...
Hackers Exploit Zero-Day in cnPilot Routers to Deploy AIRASHI DDoS Botnet
News

Hackers Exploit Zero-Day in cnPilot Routers to Deploy AIRASHI DDoS Botnet

Threat actors are using a variation of the AISURU botnet known as AIRASHI to launch distributed denial-of-service (DDoS) attacks by taking advantage of an unidentified zero-day vulnerability in Cambium Networks' cnPilot routers. QiAnXin XLab claims that starting June 2024, the attackers have taken advantage of the security vulnerability. To stop additional misuse, other information regarding the flaws has been kept secret. The distributed denial-of-service (DDoS) botnet has also weaponized vulnerabilities that affect AVTECH IP cameras, LILIN DVRs, and Shenzhen TVT devices, including CVE-2013-3307, CVE-2016-20016, CVE-2017-5259, CVE-2018-14558, CVE-2020-25499, CVE-2020-8515, CVE-2022-3573, CVE-2022-40005, CVE-2022-44149, and CVE-2023-28771. According to XLab, the operator of AIRAS...
Hackers Weaponize Visual Studio Code Remote Tunnels for Cyber Espionage
News

Hackers Weaponize Visual Studio Code Remote Tunnels for Cyber Espionage

As part of a campaign codenamed Operation Digital Eye, a suspected cyber espionage group with ties to China has been implicated in attacks against major business-to-business IT service providers in Southern Europe. In a joint report provided to The Hacker News, cybersecurity firms SentinelOne SentinelLabs and Tinexta Cyber stated that the intrusions occurred between late June and mid-July 2024. They also noted that the operations were identified and stopped before they could reach the data exfiltration stage. According to security researchers Luigi Martire and Aleksandar Milenkoski, the hacks might have given the enemies the opportunity to compromise downstream organizations and create strategic footholds read more about Hackers Weaponize Visual Studio Code Remote Tunnels for Cyber ...
Hackers Leveraging Cloudflare Tunnels DNS Fast-Flux to Hide GammaDrop Malware
News

Hackers Leveraging Cloudflare Tunnels DNS Fast-Flux to Hide GammaDrop Malware

Cloudflare Tunnels have been used by the threat actor Gamaredon to hide its staging infrastructure, which is home to the malware GammaDrop. According to a new investigation by Recorded Future's Insikt Group, the activity is a part of a spear-phishing effort that has been targeting Ukrainian companies since at least early 2024 with the goal of releasing the Visual Basic Script virus. Under the alias BlueAlpha—also known as Aqua Blizzard, Armageddon, Hive0051, Iron Tilden, Primitive Bear, Shuckworm, Trident Ursa, UAC-0010, UNC530, and Winterflounder—the cybersecurity firm is monitoring the threat actor. The group is associated with Russia's Federal Security Service (FSB) and is thought to have been operating since 2014 read more about Hackers Leveraging Cloudflare Tunnels DNS Fast-Flu...
Iranian Hackers Deploy WezRat Malware in Attacks Targeting Israeli Organizations
News

Iranian Hackers Deploy WezRat Malware in Attacks Targeting Israeli Organizations

A novel remote access trojan and information stealer that Iranian state-sponsored attackers employ to survey compromised endpoints and carry out malicious orders has been made public by cybersecurity experts. The malware has been identified in the wild since at least September 1, 2023, according to artifacts published to the VirusTotal database, and the cybersecurity firm Check Point has dubbed it WezRat. According to a technical report, WezRat has the ability to carry out keylogging, upload files, capture screenshots, execute commands, and steal cookie files and clipboard items. The primary component of the backdoor is less suspicious because distinct modules carry out some tasks read more about Iranian Hackers Deploy WezRat Malware in Attacks Targeting Israeli Organizations. Ge...
High-Severity Flaw in Allows Hackers to Exploit Environment Variables
News

High-Severity Flaw in Allows Hackers to Exploit Environment Variables

A high-severity security hole in the PostgreSQL open-source database system has been discovered by cybersecurity researchers. This flaw might allow unauthorized users to change environment variables, which could result in code execution or information leakage. The issue has a CVSS score of 8.8 and is tracked as CVE-2024-10979. Without requiring them to be hard-coded, environment variables are user-defined values that enable a program to dynamically get different types of data during runtime, including software installation paths and access keys. They are initialized during the startup phase of some operating systems. An unprivileged database user can alter sensitive process environment variables read more about High-Severity Flaw in PostgreSQL Allows Hackers to Exploit Environmen...
Hackers now use ZIP file concatenation to evade detection
News

Hackers now use ZIP file concatenation to evade detection

The ZIP file concatenation technique is being used by hackers to target Windows computers and deliver malicious payloads in compressed files that are undetectable by security solutions. The solution takes use of the various ways archive managers and ZIP parsers handle concatenated ZIP files. Perception Point noticed this new tendency as they were examining a phishing attempt that tricked users with a phony delivery notice and found a concatenated ZIP archive containing a trojan read more about Hackers now use ZIP file concatenation to evade detection. Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.
Hackers blackmail Globe Life after stealing customer data
News

Hackers blackmail Globe Life after stealing customer data

Globe Life, a large insurance business, reports that an unidentified threat actor tried to demand money in return for not disclosing information that had been taken from its computers earlier this year. Established in 1900, Globe Life has a market valuation of $12 billion and a total revenue exceeding $5.3 billion, making it one of the biggest providers of life and health insurance plans in the United States. After learning they had been infiltrated while looking over possible weaknesses with regard to access rights and user identity management for their web portal, Global Life first announced a data breach on June 13 read more about Hackers blackmail Globe Life after stealing customer data. Get up to date on the latest cybersecurity news and enhance your knowledge...
Hackers Abuse EDRSilencer Tool to Bypass Security and Hide Malicious Activity
News

Hackers Abuse EDRSilencer Tool to Bypass Security and Hide Malicious Activity

The open-source EDRSilencer program is being abused by threat actors in an attempt to tamper with endpoint detection and response (EDR) solutions and conceal harmful activities. Trend Micro claimed to have identified "threat actors attempting to integrate EDRSilencer in their attacks, repurposing it as a means of evading detection." EDRSilencer uses the Windows Filtering Platform (WFP) to restrict outgoing traffic from running EDR processes. It was inspired by the NightHawk FireBlock tool from MDSec. Terminating different EDR product-related processes is supported by Palo Alto Networks read more about Hackers Abuse EDRSilencer Tool to Bypass Security and Hide Malicious Activity. Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with ou...
U.K. Hacker Charged in $3.75 Million Insider Trading Scheme Using Hacked Executive Emails
News

U.K. Hacker Charged in $3.75 Million Insider Trading Scheme Using Hacked Executive Emails

The U.S. Department of Justice (DoJ) has charged a 39-year-old U.K. national for perpetrating a hack-to-trade fraud scheme that netted him nearly $3.75 million in illegal profits. Robert Westbrook of London was arrested last week and is expected to be extradited to the U.S. to face charges related to securities fraud, wire fraud, and five counts of computer fraud. According to the court documents, Westbrook is believed to have executed a fraudulent scheme between January 2019 and May 2020 that allowed him to generate millions in profits by gaining unauthorized access to Microsoft 365 accounts belonging to corporate executives read more about U.K. Hacker Charged in $3.75 Million Insider Trading Scheme Using Hacked Executive Emails. Get up to date on the latest cybersecurity news a...