The Hacker News

GitHub Desktop Vulnerability Risks Credential Leaks via Malicious Remote URLs

Multiple security vulnerabilities have been disclosed in GitHub Desktop as well as other Git-related projects that, if successfully exploited, could permit an attacker to gain unauthorized access to a user's Git credentials.

RANsacked: Over 100 Security Flaws Found in LTE and 5G Network Implementations

A group of academics has disclosed details of over 100 security vulnerabilities impacting LTE and 5G implementations that could be exploited by an attacker to disrupt access to service and even gain a foothold into the cellular core network.

Fake CAPTCHA Campaign Spreads Lumma Stealer in Multi-Industry Attacks

"The campaign spans multiple industries, including healthcare, banking, and marketing, with the telecom industry having the highest number of organizations targeted," warned NetSkope researchers.

CISA Adds Five-Year-Old jQuery XSS Flaw to Exploited Vulnerabilities List

The medium-severity vulnerability is CVE-2020-11023 (CVSS score: 6.1/6.9), a nearly five-year-old cross-site scripting (XSS) bug that could be exploited to achieve arbitrary code execution.

Palo Alto Firewalls Found Vulnerable to Secure Boot Bypass and Firmware Exploits

Researchers uncovered multiple vulnerabilities, dubbed PANdora’s Box, in Palo Alto Networks firewalls, enabling Secure Boot bypass and firmware exploits. These flaws reportedly require specific conditions and have not yet been maliciously exploited.

TRIPLESTRENGTH Hits Cloud for Cryptojacking, On-Premises Systems for Ransomware

Google on Wednesday shed light on a financially motivated threat actor named TRIPLESTRENGTH for its opportunistic targeting of cloud environments for cryptojacking and on-premise ransomware attacks.

QakBot-Linked BC Malware Adds Enhanced Remote Access and Data Gathering Features

Cybersecurity researchers have disclosed details of a new BackConnect (BC) malware that has been developed by threat actors linked to the infamous QakBot loader. The BackConnect(s) in use include 'DarkVNC,' alongside the IcedID BackConnect (KeyHole).

Cisco Fixes Critical Privilege Escalation Flaw in Meeting Management (CVSS 9.9)

Cisco has released software updates to address a critical security flaw impacting Meeting Management that could permit a remote, authenticated attacker to gain administrator privileges on susceptible instances.

SonicWall Urges Immediate Patch for Critical CVE-2025-23006 Flaw Amid Likely Exploitation

SonicWall warned of a critical security flaw, tracked as CVE-2025-23006 and with a CVSS score of 9.8/10, impacting its Secure Mobile Access (SMA) 1000 Series appliances that it said has been likely exploited in the wild as a zero-day.

Mirai Botnet Launches Record 5.6 Tbps DDoS Attack with 13,000+ IoT Devices

The UDP protocol-based attack took place on October 29, 2024, targeting one of its customers, an unnamed internet service provider (ISP) from Eastern Asia. The activity originated from a Mirai-variant botnet.

Defend Against Threats with Cyber Fusion

Cyware is the leading provider of cyber fusion solutions that power threat intelligence sharing , end-to-end automation and 360-degree threat response.

Trending Tags