NestDaddy
Web Global News Local News Financial News Tech News Images Maps TravelHub
Research AI Tools Games Software
Showing 20 of 82 tech news articles in Cybersecurity
Iran's 'MuddyWater' Levels Up With MuddyViper Backdoor Cybersecurity
Darkreading 3 days ago

Iran's 'MuddyWater' Levels Up With MuddyViper Backdoor

New Fooder loader and memory-only tactics suggest MuddyWater has evolved from its usual noisy ops to more stealthy espionage operations.

Researchers Use Poetry to Jailbreak AI Models Cybersecurity
Darkreading 3 days ago

Researchers Use Poetry to Jailbreak AI Models

When prompts were presented in poetic rather than prose form, attack success rates increased from 8% to 43%, on average — a fivefold increase.

India Orders Messaging Apps to Work Only With Active SIM Cards to Prevent Fraud and Misuse Cybersecurity
Thehackernews 3 days ago

India Orders Messaging Apps to Work Only With Active SIM Cards to Prevent Fraud and Misuse

India's Department of Telecommunications (DoT) has issued directions to app-based communication service providers to ensure that the platforms cannot be used without an active SIM card linked to the user's mobile number. To that end, messaging apps like WhatsApp, Telegram, Snapchat, Arattai, Sharech

New Raptor Framework Uses Agentic Workflows to Create Patches Cybersecurity
Darkreading 3 days ago

New Raptor Framework Uses Agentic Workflows to Create Patches

Researchers used prompts and large language models to develop an open source AI framework capable of generating both vulnerability exploits and patches.

Researchers Capture Lazarus APT's Remote-Worker Scheme Live on Camera Cybersecurity
Thehackernews 3 days ago

Researchers Capture Lazarus APT's Remote-Worker Scheme Live on Camera

A joint investigation led by Mauro Eldritch, founder of BCA LTD, conducted together with threat-intel initiative NorthScan and ANY.RUN, a solution for interactive malware analysis and threat intelligence, has uncovered one of North Korea’s most persistent infiltration schemes: a network of remote IT

GlassWorm Returns with 24 Malicious Extensions Impersonating Popular Developer Tools Cybersecurity
Thehackernews 3 days ago

GlassWorm Returns with 24 Malicious Extensions Impersonating Popular Developer Tools

The supply chain campaign known as GlassWorm has once again reared its head, infiltrating both Microsoft Visual Studio Marketplace and Open VSX with 24 extensions impersonating popular developer tools and frameworks like Flutter, React, Tailwind, Vim, and Vue. GlassWorm was first documented in Octob

Malicious npm Package Uses Hidden Prompt and Script to Evade AI Security Tools Cybersecurity
Thehackernews 3 days ago

Malicious npm Package Uses Hidden Prompt and Script to Evade AI Security Tools

Cybersecurity researchers have disclosed details of an npm package that attempts to influence artificial intelligence (AI)-driven security scanners. The package in question is eslint-plugin-unicorn-ts-2, which masquerades as a TypeScript extension of the popular ESLint plugin. It was uploaded to the

Iran-Linked Hackers Hit Israeli Sectors with New MuddyViper Backdoor in Targeted Attacks Cybersecurity
Thehackernews 3 days ago

Iran-Linked Hackers Hit Israeli Sectors with New MuddyViper Backdoor in Targeted Attacks

Israeli entities spanning academia, engineering, local government, manufacturing, technology, transportation, and utilities sectors have emerged as the target of a new set of attacks undertaken by Iranian nation-state actors that have delivered a previously undocumented backdoor called MuddyViper. T

DPRK's 'Contagious Interview' Spawns Malicious Npm Package Factory Cybersecurity
Darkreading 3 days ago

DPRK's 'Contagious Interview' Spawns Malicious Npm Package Factory

North Korean attackers have delivered more than 197 malicious packages with 31K-plus downloads since Oct. 10, as part of ongoing state-sponsored activity to compromise software developers.

SecAlerts Cuts Through the Noise with a Smarter, Faster Way to Track Vulnerabilities Cybersecurity
Thehackernews 3 days ago

SecAlerts Cuts Through the Noise with a Smarter, Faster Way to Track Vulnerabilities

Vulnerability management is a core component of every cybersecurity strategy. However, businesses often use thousands of software without realising it (when was the last time you checked?), and keeping track of all the vulnerability alerts, notifications, and updates can be a burden on resources and

Google Patches 107 Android Flaws, Including Two Framework Bugs Exploited in the Wild Cybersecurity
Thehackernews 4 days ago

Google Patches 107 Android Flaws, Including Two Framework Bugs Exploited in the Wild

Google on Monday released monthly security updates for the Android operating system, including two vulnerabilities that it said have been exploited in the wild. The patch addresses a total of 107 security flaws spanning different components, including Framework, System, Kernel, as well as those from

Tomiris Unleashes 'Havoc' With New Tools, Tactics Cybersecurity
Darkreading 4 days ago

Tomiris Unleashes 'Havoc' With New Tools, Tactics

The Russian-speaking group is targeting government and diplomatic entities in CIS member states and Central Asia in its latest cyber-espionage campaign.

CodeRED Emergency Alert Platform Shut Down Following Cyberattack Cybersecurity
Darkreading 4 days ago

CodeRED Emergency Alert Platform Shut Down Following Cyberattack

The Inc ransomware gang took responsibility for the attack earlier this month and claimed it stole sensitive subscriber data.

Police Disrupt 'Cryptomixer,' Seize Millions in Crypto Cybersecurity
Darkreading 4 days ago

Police Disrupt 'Cryptomixer,' Seize Millions in Crypto

Multiple European law enforcement agencies recently disrupted Cryptomixer, a service allegedly used by cybercriminals to launder ill-gotten gains from ransomware and other cyber activities.

India Orders Phone Makers to Pre-Install Government App to Tackle Telecom Fraud Cybersecurity
Thehackernews 4 days ago

India Orders Phone Makers to Pre-Install Government App to Tackle Telecom Fraud

India's telecommunications ministry has ordered major mobile device manufacturers to preload a government-backed cybersecurity app named Sanchar Saathi on all new phones within 90 days. According to a report from Reuters, the app cannot be deleted or disabled from users' devices. Sanchar Saathi, ava

ShadyPanda Turns Popular Browser Extensions with 4.3 Million Installs Into Spyware Cybersecurity
Thehackernews 4 days ago

ShadyPanda Turns Popular Browser Extensions with 4.3 Million Installs Into Spyware

A threat actor known as ShadyPanda has been linked to a seven-year-long browser extension campaign that has amassed over 4.3 million installations over time. Five of these extensions started off as legitimate programs before malicious changes were introduced in mid-2024, according to a report from K

⚡ Weekly Recap: Hot CVEs, npm Worm Returns, Firefox RCE, M365 Email Raid & More Cybersecurity
Thehackernews 4 days ago

⚡ Weekly Recap: Hot CVEs, npm Worm Returns, Firefox RCE, M365 Email Raid & More

Hackers aren’t kicking down the door anymore. They just use the same tools we use every day — code packages, cloud accounts, email, chat, phones, and “trusted” partners — and turn them against us. One bad download can leak your keys. One weak vendor can expose many customers at once. One guest invit

Webinar: The "Agentic" Trojan Horse: Why the New AI Browsers War is a Nightmare for Security Teams Cybersecurity
Thehackernews 4 days ago

Webinar: The "Agentic" Trojan Horse: Why the New AI Browsers War is a Nightmare for Security Teams

The AI browser wars are coming to a desktop near you, and you need to start worrying about their security challenges. For the last two decades, whether you used Chrome, Edge, or Firefox, the fundamental paradigm remained the same: a passive window through which a human user viewed and interacted wit

Shai-hulud 2.0 Variant Threatens Cloud Ecosystem Cybersecurity
Darkreading 4 days ago

Shai-hulud 2.0 Variant Threatens Cloud Ecosystem

The latest attack from the self-replicating npm-package poisoning worm can also steal credentials and secrets from AWS, Google Cloud Platform, and Azure.

New Albiriox MaaS Malware Targets 400+ Apps for On-Device Fraud and Screen Control Cybersecurity
Thehackernews 4 days ago

New Albiriox MaaS Malware Targets 400+ Apps for On-Device Fraud and Screen Control

A new Android malware named Albiriox has been advertised under a malware-as-a-service (MaaS) model to offer a "full spectrum" of features to facilitate on-device fraud (ODF), screen manipulation, and real-time interaction with infected devices. The malware embeds a hard-coded list comprising over 40