When Good Extensions Go Bad: Takeaways from the Campaign Targeting Browser Extensions

30/12/2024 0 Comments 0 tags

News has been making headlines over the weekend of the extensive attack campaign targeting browser extensions and injecting them with malicious code to steal user credentials. Currently, over 25 extensions,

⚡ THN Weekly Recap: Top Cybersecurity Threats, Tools and Tips

30/12/2024 0 Comments 0 tags

Every week, the digital world faces new challenges and changes. Hackers are always finding new ways to breach systems, while defenders work hard to keep our data safe. Whether it’s

New HIPAA Rules Mandate 72-Hour Data Restoration and Annual Compliance Audits

30/12/2024 0 Comments 0 tags

The United States Department of Health and Human Services’ (HHS) Office for Civil Rights (OCR) has proposed new cybersecurity requirements for healthcare organizations with an aim to safeguard patients’ data

16 Chrome Extensions Hacked, Exposing Over 600,000 Users to Data Theft

29/12/2024 0 Comments 0 tags

A new attack campaign has targeted known Chrome browser extensions, leading to at least 16 extensions being compromised and exposing over 600,000 users to data exposure and credential theft. The

15,000+ Four-Faith Routers Exposed to New Exploit Due to Default Credentials

28/12/2024 0 Comments 0 tags

A high-severity flaw impacting select Four-Faith routers has come under active exploitation in the wild, according to new findings from VulnCheck. The vulnerability, tracked as CVE-2024-12856 (CVSS score: 7.2), has

North Korean Hackers Deploy OtterCookie Malware in Contagious Interview Campaign

28/12/2024 0 Comments 0 tags

North Korean threat actors behind the ongoing Contagious Interview campaign have been observed dropping a new JavaScript malware called OtterCookie. Contagious Interview (aka DeceptiveDevelopment) refers to a persistent attack campaign

Apache MINA CVE-2024-52046: CVSS 10.0 Flaw Enables RCE via Unsafe Serialization

27/12/2024 0 Comments 0 tags

The Apache Software Foundation (ASF) has released patches to address a maximum severity vulnerability in the MINA Java network application framework that could result in remote code execution under specific

FICORA and Kaiten Botnets Exploit Old D-Link Vulnerabilities for Global Attacks

27/12/2024 0 Comments 0 tags

Cybersecurity researchers are warning about a spike in malicious activity that involves roping vulnerable D-Link routers into two different botnets, a Mirai variant dubbed FICORA and a Kaiten (aka Tsunami)

Palo Alto Releases Patch for PAN-OS DoS Flaw — Update Immediately

27/12/2024 0 Comments 0 tags

Palo Alto Networks has disclosed a high-severity vulnerability impacting PAN-OS software that could cause a denial-of-service (DoS) condition on susceptible devices. The flaw, tracked as CVE-2024-3393 (CVSS score: 8.7), impacts

Cloud Atlas Deploys VBCloud Malware: Over 80% of Targets Found in Russia

27/12/2024 0 Comments 0 tags

The threat actor known as Cloud Atlas has been observed using a previously undocumented malware called VBCloud as part of its cyber attack campaigns targeting “several dozen users” in 2024.