§Source · The Hacker News
The Hacker News
Every dispatch we have aggregated from The Hacker News.
All dispatches
Loading
§Source · The Hacker News
Every dispatch we have aggregated from The Hacker News.
All dispatchesA three-stage path (SearchLeak) enables exfiltration of emails and MFA data via trusted Copilot links. Restrict Copilot usage and tighten monitoring.
New cPanel vulnerability exploited to target government and MSP networks. Patch immediately and audit exposure.
Progress Software patches a critical MOVEit Automation flaw that could bypass authentication. Immediate action recommended to apply updates.
VECT 2.0 acts more as a data wiper due to encryption nonce flaws; recovery unlikely even for attackers.
Flawed Entra ID role could enable privilege escalation; Microsoft issued patches after discovery by researchers.
New destructive wiper targeting energy utilities; review backups and incident response playbooks.
External tooling compromise allowed unauthorized access; assess third-party risk and tighten vendor controls.
A cluster of 108 malicious Chrome extensions communicates with a shared C2 to steal data and inject ads/JS on pages. Mitigation includes extension reviews and disabling suspicious add-ons.
A cluster of 108 malicious Chrome extensions communicates with a shared C2 to steal data and inject ads/JS on pages. Mitigation includes extension reviews and disabling suspicious add-ons.
Get these articles delivered to your inbox.
Subscribe free