Breaking: Mexican Banks Hit by FiXS ATM Malware

The Hacker News Daily Updates
Newsletter
cover

The Hacker News Webinar: A MythBusting Special -- 9 Myths about File-based Threats

Say goodbye to the myths and hello to the facts - Register for our webinar on file-based threats now!

Download Now Sponsored
LATEST NEWS Mar 4, 2023

Security and IT Teams No Longer Need To Pay For SaaS-Shadow IT Discovery

This past January, a SaaS Security Posture Management (SSPM) company named Wing Security (Wing) made waves with the launch of its free SaaS-Shadow IT discovery solution. Cloud-based companies were invited to gain insight into their employees' SaaS usage through a completely free, self-service product that operates on a "freemium" model. If a user is impressed with the solution and wants to ...

Read More
Twitter Facebook LinkedIn

New FiXS ATM Malware Targeting Mexican Banks

A new ATM malware strain dubbed FiXS has been observed targeting Mexican banks since the start of February 2023. "The ATM malware is hidden inside another not-malicious-looking program," Latin American cybersecurity firm Metabase Q said in a report shared with The Hacker News. Besides requiring interaction via an external keyboard, the Windows-based ATM malware is also vendor-agnostic and ...

Read More
Twitter Facebook LinkedIn

New Flaws in TPM 2.0 Library Pose Threat to Billions of IoT and Enterprise Devices

A pair of serious security defects has been disclosed in the Trusted Platform Module (TPM) 2.0 reference library specification that could potentially lead to information disclosure or privilege escalation. One of the vulnerabilities, CVE-2023-1017, concerns an out-of-bounds write, while the other, CVE-2023-1018, is described as an out-of-bounds read. Credited with discovering and reporting ...

Read More
Twitter Facebook LinkedIn

Chinese Hackers Targeting European Entities with New MQsTTang Backdoor

The China-aligned Mustang Panda actor has been observed using a hitherto unseen custom backdoor called MQsTTang as part of an ongoing social engineering campaign that commenced in January 2023. "Unlike most of the group's malware, MQsTTang doesn't seem to be based on existing families or publicly available projects," ESET researcher Alexandre Côté Cyr said in a new report. Attack ...

Read More
Twitter Facebook LinkedIn

U.S. Cybersecurity Agency Raises Alarm Over Royal Ransomware's Deadly Capabilities

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has released a new advisory about Royal ransomware, which emerged in the threat landscape last year. "After gaining access to victims' networks, Royal actors disable antivirus software and exfiltrate large amounts of data before ultimately deploying the ransomware and encrypting the systems," CISA said. The ...

Read More
Twitter Facebook LinkedIn

Hackers Exploit Containerized Environments to Steal Proprietary Data and Software

A sophisticated attack campaign dubbed SCARLETEEL is targeting containerized environments to perpetrate theft of proprietary data and software. "The attacker exploited a containerized workload and then leveraged it to perform privilege escalation into an AWS account in order to steal proprietary software and credentials," Sysdig said in a new report. The advanced cloud attack also entailed ...

Read More
Twitter Facebook LinkedIn

New Cryptojacking Campaign Leverages Misconfigured Redis Database Servers

Misconfigured Redis database servers are the target of a novel cryptojacking campaign that leverages a legitimate and open source command-line file transfer service to implement its attack. "Underpinning this campaign was the use of transfer[.]sh," Cado Security said in a report shared with The Hacker News. "It's possible that it's an attempt at evading detections based on other common ...

Read More
Twitter Facebook LinkedIn

2023 Browser Security Report Uncovers Major Browsing Risks and Blind Spots

As a primary working interface, the browser plays a significant role in today's corporate environment. The browser is constantly used by employees to access websites, SaaS applications and internal applications, from both managed and unmanaged devices. A new report published by LayerX, a browser security vendor, finds that attackers are exploiting this reality and are targeting it in ...

Read More
Twitter Facebook LinkedIn
cover

The Hacker News Webinar: A MythBusting Special -- 9 Myths about File-based Threats

Say goodbye to the myths and hello to the facts - Register for our webinar on file-based threats now!

Download Now Sponsored

This email was sent to you. You are receiving this newsletter because you opted-in to receive relevant communications from The Hacker News. To manage your email newsletter preferences, please click here.

Contact The Hacker News: info@thehackernews.com
Unsubscribe

The Hacker News | Pearls Omaxe, Netaji Subash Place, Pitampura, Delhi 110034 India

Key phrases

Older messages

ALERT: New Flaws in TPM 2.0 Library Could Be Putting Your Business and IoT Devices in Danger!

Friday, March 3, 2023

The Hacker News Daily Updates Newsletter cover Why EDR isn't Enough to Stop Cyberattacks How CyberArk Endpoint Privilege Manager™ Tackles EDR Gaps Download Now Sponsored LATEST NEWS Mar 3, 2023 New

Linux Users Beware - SysUpdate Malware Strikes Again with Sneaky Evasion Tactics!

Thursday, March 2, 2023

The Hacker News Daily Updates Newsletter cover The Hacker News Webinar: A MythBusting Special -- 9 Myths about File-based Threats Say goodbye to the myths and hello to the facts - Register for our

BlackLotus UEFI Bootkit Malware Successfully Bypasses Windows 11 Secure Boot

Wednesday, March 1, 2023

The Hacker News Daily Updates Newsletter cover The Hacker News Webinar: A MythBusting Special -- 9 Myths about File-based Threats Say goodbye to the myths and hello to the facts - Register for our

BREAKING: LastPass Reveals Second Attack Resulting in Breach of Encrypted Password Vaults

Tuesday, February 28, 2023

The Hacker News eBook Update Newsletter Cybersecurity Webinar: How to Tackle the Top SaaS Security Challenges of 2023 Download For Free Don't let your SaaS apps become the next target - Join our

BREAKING: LastPass Reveals Second Attack Resulting in Breach of Encrypted Password Vaults

Tuesday, February 28, 2023

The Hacker News Daily Updates Newsletter cover Cybersecurity Webinar: How to Tackle the Top SaaS Security Challenges of 2023 Don't let your SaaS apps become the next target - Join our expert-led

Charted | Which Countries Hold the Most U.S. Debt? 💸

Friday, March 24, 2023

Foreign investors hold $7.3 trillion of the national US debt. These holdings declined 6% in 2022 amid a strong US dollar and rising rates. View Online | Subscribe FEATURED STORY Which Countries Hold

SWLW #539: Navigating the unpredictability of everything, The Ambiguous Zone, and more.

Friday, March 24, 2023

Weekly articles & videos about people, culture and leadership: everything you need to design the org that makes the product. A weekly newsletter by Oren Ellenbogen with the best content I found

Spring is here and so are our updates

Friday, March 24, 2023

New season, new features New season, new features: Spring is here and so are our updates! Read the Full Product Update Here 💚 Hey there, Hackers 👋 Last couple of months have been filled with new

Two new tips: DevTools and VS Code

Friday, March 24, 2023

Some handy tips to use in with DevTools and VS Code Two fresh video tips Hey everyone! Here are two new tips for you - you can watch the videos or read the text posts. VS Code: Automatically convert

😓 Challenges of product leadership

Friday, March 24, 2023

Challenges of Being a Product Leader When you get that promotion into product leadership there's a lot of excitement about the opportunity to have a bigger impact in your company and your

Daily Coding Problem: Problem #1054 [Medium]

Friday, March 24, 2023

Daily Coding Problem Good morning! Here's your coding interview problem for today. This problem was asked by Microsoft. Implement the singleton pattern with a twist. First, instead of storing one

What’s new in the Jetpack Compose March ’23 release

Friday, March 24, 2023

View in browser 🔖 Articles What's new in the Jetpack Compose March '23 release This release contains new features like Pager and Flow Layouts, and new ways to style your text, such as

How to spot investment-worthy founders in a down market

Friday, March 24, 2023

TechCrunch+ Newsletter TechCrunch+ logo TechCrunch+ Roundup logo By Walter Thompson Friday, March 24, 2023 Welcome to TechCrunch+ Friday Image Credits: Carol Yepes / Getty Images The quickening pace of

7 days until the TC Early Stage early bird flies away

Friday, March 24, 2023

TC Early Stage - Boston, MA - April 20, 2023 TechCrunch Early Stage 2023 Don't miss out on early bird savings Don't miss out on early bird savings Budget-minded entrepreneurs and early-stage

Why Internet Speed Tests Don't Really Matter (and What Does)

Friday, March 24, 2023

Did You Know?: The surname of iconic Nintendo character Mario is also Mario, making his full name Mario Mario. Read in Browser Logo for How-To Geek March 24, 2023 Did You Know? The surname of iconic