New NAPLISTENER Malware by REF2924 Group is Leaving Networks Vulnerable!

The Hacker News Daily Updates
Newsletter
cover

THN Webinar: Master the Six Phases of Incident Response

React fast, respond smart: Master the six phases of Incident Response with Cynet's IR Leader!

Download Now Sponsored
LATEST NEWS Mar 22, 2023

Preventing Insider Threats in Your Active Directory

Active Directory (AD) is a powerful authentication and directory service used by organizations worldwide. With this ubiquity and power comes the potential for abuse. Insider threats offer some of the most potentials for destruction. Many internal users have over-provisioned access and visibility into the internal network. Insiders' level of access and trust in a network leads to ...

Read More
Twitter Facebook LinkedIn

Rogue NuGet Packages Infect .NET Developers with Crypto-Stealing Malware

The NuGet repository is the target of a new "sophisticated and highly-malicious attack" aiming to infect .NET developer systems with cryptocurrency stealer malware. The 13 rogue packages, which were downloaded more than 160,000 times over the past month, have since been taken down. "The packages contained a PowerShell script that would execute upon installation and trigger a download of a ...

Read More
Twitter Facebook LinkedIn

NAPLISTENER: New Malware in REF2924 Group's Arsenal for Bypassing Detection

The threat group tracked as REF2924 has been observed deploying previously unseen malware in its attacks aimed at entities in South and Southeast Asia. The malware, dubbed NAPLISTENER by Elastic Security Labs, is an HTTP listener programmed in C# and is designed to evade "network-based forms of detection." REF2924 is the moniker assigned to an activity cluster linked to attacks against an ...

Read More
Twitter Facebook LinkedIn

BreachForums Administrator Baphomet Shuts Down Infamous Hacking Forum

In a sudden turn of events, Baphomet, the current administrator of BreachForums, said in an update on March 21, 2023, that the hacking forum has been officially taken down but emphasized that "it's not the end." "You are allowed to hate me, and disagree with my decision but I promise what is to come will be better for us all," Baphomet noted in a message posted on the BreachForums ...

Read More
Twitter Facebook LinkedIn

New 'Bad Magic' Cyber Threat Disrupt Ukraine's Key Sectors Amid War

Amid the ongoing war between Russia and Ukraine, government, agriculture, and transportation organizations located in Donetsk, Lugansk, and Crimea have been attacked as part of an active campaign that drops a previously unseen, modular framework dubbed CommonMagic. "Although the initial vector of compromise is unclear, the details of the next stage imply the use of spear phishing or ...

Read More
Twitter Facebook LinkedIn

New ShellBot DDoS Malware Variants Targeting Poorly Managed Linux Servers

Poorly managed Linux SSH servers are being targeted as part of a new campaign that deploys different variants of a malware called ShellBot. "ShellBot, also known as PerlBot, is a DDoS Bot malware developed in Perl and characteristically uses IRC protocol to communicate with the C&C server," AhnLab Security Emergency response Center (ASEC) said in a report. ShellBot is installed on servers ...

Read More
Twitter Facebook LinkedIn

The Best Defense Against Cyber Threats for Lean Security Teams

H0lyGh0st, Magecart, and a slew of state-sponsored hacker groups are diversifying their tactics and shifting their focus to… You. That is, if you're in charge of cybersecurity for a small-to-midsize enterprise (SME). Why? Bad actors know that SMEs typically have a smaller security budget, less infosec manpower, and possibly weak or missing security controls to protect their data ...

Read More
Twitter Facebook LinkedIn

From Ransomware to Cyber Espionage: 55 Zero-Day Vulnerabilities Weaponized in 2022

As many as 55 zero-day vulnerabilities were exploited in the wild in 2022, with most of the flaws discovered in software from Microsoft, Google, and Apple. While this figure represents a decrease from the year before, when a staggering 81 zero-days were weaponized, it still represents a significant uptick in recent years of threat actors leveraging unknown security flaws to their advantage. ...

Read More
Twitter Facebook LinkedIn
cover

THN Webinar: Master the Six Phases of Incident Response

React fast, respond smart: Master the six phases of Incident Response with Cynet's IR Leader!

Download Now Sponsored

This email was sent to you. You are receiving this newsletter because you opted-in to receive relevant communications from The Hacker News. To manage your email newsletter preferences, please click here.

Contact The Hacker News: info@thehackernews.com
Unsubscribe

The Hacker News | Pearls Omaxe, Netaji Subash Place, Pitampura, Delhi 110034 India

Key phrases

Older messages

Hackers Stole $1.6 Million from Crypto ATMs via Zero-Day Vulnerability

Tuesday, March 21, 2023

The Hacker News Daily Updates Newsletter cover Guide to Open Source Software Security How to gain visibility to all your security risks Download Now Sponsored LATEST NEWS Mar 21, 2023 New ShellBot DDoS

Researchers Shed Light on CatB Ransomware's Evasion Techniques

Monday, March 20, 2023

The Hacker News Daily Updates Newsletter cover THN Webinar: Master the Six Phases of Incident Response React fast, respond smart: Master the six phases of Incident Response with Cynet's IR Leader!

Cyber Kingpin – BreachForums' Mastermind Finally Caught in New York!

Saturday, March 18, 2023

The Hacker News Daily Updates Newsletter cover THN Webinar: 3 Research-Backed Ways to Secure Your Identity Perimeter Don't Let Cybercriminals Sneak in Through the Identity Perimeter: Get Actionable

Attention Samsung Users! Google Uncovers 18 Alarming Security Flaws in Exynos Chips

Friday, March 17, 2023

The Hacker News Daily Updates Newsletter cover THN Webinar: Master the Six Phases of Incident Response React fast, respond smart: Master the six phases of Incident Response with Cynet's IR Leader!

Act Now: Microsoft's New Security Patches Address 80 Flaws — Two Under Active Attack!

Thursday, March 16, 2023

The Hacker News Daily Updates Newsletter cover SBOM and Connected Device Security When it comes to device firmware and connected device security, where does a manufacturer or buyer start? Here's

JSK Daily for Sep 25, 2023

Monday, September 25, 2023

JSK Daily for Sep 25, 2023 View this email in your browser A community curated daily e-mail of JavaScript news Mastering Strictly Typed Reactive Forms in Angular: A Step-by-Step Guide In this article,

Max Q - Things got disrupted

Monday, September 25, 2023

TechCrunch Newsletter TechCrunch logo Max Q logo By Aria Alamalhodaei Monday, September 25, 2023 Hello and welcome back to Max Q! I'm finally home after attending TechCrunch Disrupt, our flagship

Daily Coding Problem: Problem #1223 [Hard]

Monday, September 25, 2023

Daily Coding Problem Good morning! Here's your coding interview problem for today. This problem was asked by LinkedIn. You are given a binary tree in a peculiar string representation. Each node is

Visualized | Which Companies Own the Most Satellites? 🛰️

Monday, September 25, 2023

Despite Starlink's dominance in the satellite industry, the company is set to face intense competition in the coming years. View Online | Subscribe Presented by: How close is the US electricity

Wrapping up in SF, managing your data and more... | September 25

Monday, September 25, 2023

What's happening at TechCrunch this week TechCrunch events roundup Things are slowly returning to "normal" here in TechCrunch-land after an explosive TechCrunch Disrupt last week in San

Noonification: Model Quantization in Deep Neural Networks

Monday, September 25, 2023

Top Tech Content sent at Noon! 15k+ Startups Scaled Their Data Infrastructure with Segment. Apply Now! How are you, @hacker? 🪐 What's happening in tech this week: The Noonification by HackerNoon

The collapse of Microsoft Surface

Monday, September 25, 2023

How to fix IT burnout; Fedora 39 is lightning fast; FaceTime voicemails -- ZDNET ZDNET Tech Today - US September 25, 2023 placeholder Can Microsoft recover from the collapse of its Surface business?

Digest #117: Pre-Commit Hooks for Terraform 🤖

Monday, September 25, 2023

Digest #117: Pre-Commit Hooks for Terraform 🤖 #117: Pre-Commit Hooks for Terraform Hey there, DevOps enthusiasts! 👋🏻 We're back, and oh boy, do we have some juicy bits for you this week in the

😺 NEW from Microsoft

Monday, September 25, 2023

Amazon is stepping up its rivalry with Microsoft, Meta, Google, and more by agreeing to potentially invest $4 billion in... Product Hunt Read in browser AMAZON HAS ENTERED THE CHAT... Amazon is

From Watering Hole to Spyware: EvilBamboo Targets Tibetans, Uyghurs, and Taiwanese

Monday, September 25, 2023

The Hacker News Daily Updates Newsletter cover Safeguarding Servers We know servers to be an attacker's ultimate target, but while they do store or process large amounts of sensitive data, the