Elfin Hacking Group Targets Multiple U.S. and Saudi Arabian Firms

An Iran-linked cyber-espionage group that has been found targeting critical infrastructure, energy and military sectors in Saudi Arabia and the United States two years ago continues targeting organizations in the two nations, Symantec reported on Wedne… Continue reading Elfin Hacking Group Targets Multiple U.S. and Saudi Arabian Firms

Lazarus rises in Israel with attempted hack of defense company, researchers say

A notorious hacking group experts have tied to the North Korean government has targeted an Israeli defense company, according to new research outlining what appears to be one of the group’s first attacks on an Israeli entity. The unnamed company makes products used in the military and aerospace industries, and the hackers could have been after commercial secrets or more traditional espionage, according to ClearSky, the cybersecurity firm that exposed the operation. The suspected culprit is Lazarus Group, an industry term for a broad set of hackers associated with Pyongyang. “We cannot be sure what the objective of the attackers [was],”  Eyal Sela, head of threat intelligence at ClearSky, told CyberScoop in an email. “[It] could be industrial/commercial espionage but could be military espionage, for example.” North Korean dictator Kim Jim Un has set ambitious economic goals, and some cybersecurity analysts have predicted he will unleash the Pyongyang-affiliated hackers to meet those deadlines by targeting multinational companies’ trade […]

The post Lazarus rises in Israel with attempted hack of defense company, researchers say appeared first on CyberScoop.

Continue reading Lazarus rises in Israel with attempted hack of defense company, researchers say

Hackers are using 19-year-old WinRar bug to install nasty malware

By Waqas
By using the bug, hackers are desperately dropping persistent malware through generic trojan on systems using the old version of WinRar. McAfee security firm’s researcher Craig Schmugar has identified that the world famous and commonly used co… Continue reading Hackers are using 19-year-old WinRar bug to install nasty malware

Patched WinRAR Bug Still Under Active Attack—Thanks to No Auto-Updates

Various cyber criminal groups and individual hackers are still exploiting a recently patched critical code execution vulnerability in WinRAR, a popular Windows file compression application with 500 million users worldwide.

Why? Because the WinRAR soft… Continue reading Patched WinRAR Bug Still Under Active Attack—Thanks to No Auto-Updates

Latest WinRAR Flaw Being Exploited in the Wild to Hack Windows Computers

It’s not just the critical Drupal vulnerability that is being exploited by in the wild cybercriminals to attack vulnerable websites that have not yet applied patches already available by its developers, but hackers are also exploiting a critical WinRAR… Continue reading Latest WinRAR Flaw Being Exploited in the Wild to Hack Windows Computers

Latest WinRAR, Drupal flaws under active exploitation

CVE-2018-20250, a WinRAR vulnerability that allows attackers to extract a malicious executable to one of the Windows Startup folder to be executed every time the system is booted, and CVE-2019-6340, the remote execution flaw affecting the popular Drupa… Continue reading Latest WinRAR, Drupal flaws under active exploitation

Passwords, Splunk, & Nest Microphones – Paul’s Security Weekly #595

    In the Security News, password managers leaking data in memory, security analysts are only human, Splunk changes position of Russian customers, Google admits error over hidden microphone, and a nasty code-execution bug in WinRAR threatened millions… Continue reading Passwords, Splunk, & Nest Microphones – Paul’s Security Weekly #595