هکرنیوز|Hacker News
Открыть в Telegram
🛡هکر نیوز | اخبار سایبری 💻 اخبار حملات و تهدیدات سایبری 👥 رصد گروههای هکری و فعالیتهای سایبری 🚨 مهمترین رویدادهای امنیت سایبری 📩 ارسال خبر و گزارش: @HackerNewsAdmin
Больше4 294
Подписчики
-2024 часа
-2137 дней
-82330 дней
Архив постов
4 294
⭕این ایمیل حاوی یک کد QR است که به طور هدفمند شکسته شده است، در تلاشی برای اجبار کردن پاسخ از طرف گیرنده درخواست پیوند جایگزین.
⭕اگر قربانی پاسخ دهد، استار بلیزارد ایمیل دیگری با پیوند کوتاه «t.ly» ارسال میکند که او را به یک صفحه وب جعلی هدایت میکند که یک صفحه دعوت قانونی واتساپ را با یک کد QR جدید تقلید میکند.
⭕وب سایت مخرب با این حال، کد QR جدید برای پیوند یک دستگاه جدید، مهاجم، به حساب WhatsApp قربانی است.
⭕اگر هدف از دستورالعملهای موجود در این صفحه پیروی کند، عامل تهدید میتواند به پیامهای موجود در حساب واتساپ خود دسترسی پیدا کند و این قابلیت را داشته باشد که این دادهها را با استفاده از افزونههای مرورگر موجود، که برای صادرات پیامهای واتساپ از حسابی که از طریق واتساپ به آن دسترسی دارد، استخراج کند. وب، مایکروسافت توضیح می دهد.
⭕همچنین ایده خوبی است که دستگاه های مرتبط با حساب WhatsApp خود را بررسی کنید. این از گزینههای «دستگاههای مرتبط» در برنامه در دستگاه تلفن همراه (iPhone یا Android) امکانپذیر است و هر دستگاهی را که نمیشناسید از سیستم خارج شوید.
⭕این کمپین فیشینگ نشان میدهد که اختلال فعالیت Star Blizzard در اکتبر 2024، زمانی که مایکروسافت و وزارت دادگستری ایالات متحده بیش از 180 دامنه مورد استفاده توسط گروه تهدید روسی را توقیف یا حذف کردند، تأثیر طولانیمدتی نداشت و هکرها به عملیات خود ادامه دادند. با کاوش سایر بردارهای حمله.
The email contains a QR code that has been purposefully hacked, in an attempt to force a response from the recipient of the alternative link request. If the victim responds, Star Blizzard sends another email with a shortened “t.ly” link that redirects them to a fake web page that mimics a legitimate WhatsApp invitation page with a new QR code. The malicious website, however, uses the new QR code to link a new device, the attacker, to the victim’s WhatsApp account. If the target follows the instructions on the page, the threat actor can access the messages in their WhatsApp account and extract this data using existing browser extensions, which are designed to export WhatsApp messages from the account they access via WhatsApp. Web, Microsoft explains. It’s also a good idea to check the devices associated with your WhatsApp account. This is possible from the “Related Devices” options in the app on your mobile device (iPhone or Android) and log out of any devices you don’t recognize. This phishing campaign shows that the Star Blizzard disruption in October 2024, when Microsoft and the US Department of Justice seized or removed more than 180 domains used by the Russian threat group, had no long-term impact and the hackers continued their operations. By exploring other attack vectors.🚨@hackernewscyber
4 294
🔴دعوت نامه مخرب واتس اپ
🔺هکر نیوز ؛ Star Blizzard حمله را با جعل هویت یک مقام دولت ایالات متحده در پیام های ایمیلی به هدف آغاز می کند. فریب دعوتی برای پیوستن به یک گروه واتساپ مرتبط با طرحهای غیردولتی حامی اوکراین است.
🚨 @Hackernewscyber
4 294
🔴هکرهای tar Blizzard از واتس اپ برای هدف قرار دادن دیپلمات های با ارزش سوء استفاده می کنند
🔺 هکر های دولت ملی روسیه، یک کمپین جدید فیشینگ نیزهای را برای به خطر انداختن حسابهای واتساپ از اهداف در دولت، دیپلماسی، سیاست دفاعی، روابط بینالملل و سازمانهای امدادی اوکراین اجرا کرده است.
🔺بر اساس گزارشی از Microsoft Threat Intelligence، این کمپین در اواسط نوامبر 2024 مشاهده شد و نشان دهنده یک تغییر تاکتیکی برای Star Blizzard به عنوان پاسخی به افشای اخیر تاکتیک ها، تکنیک ها و رویه های عامل تهدید است.
🔴Star Blizzard hackers exploit WhatsApp to target high-value diplomats
🔺 Russian national government hackers have launched a new spear phishing campaign to compromise WhatsApp accounts of targets in the Ukrainian government, diplomacy, defense policy, international relations, and relief organizations.
🔺According to a report from Microsoft Threat Intelligence, the campaign was observed in mid-November 2024 and represents a tactical shift for Star Blizzard in response to recent disclosures of the threat actor’s tactics, techniques, and procedures.
🚨 @Hackernewscyber
4 294
🔴 وضعیت امنیت سایبری زیرساخت های حیاتی
🔺در 25 سپتامبر، CISA یادآوری آشکاری صادر کرد که زیرساخت های حیاتی همچنان هدف اصلی حملات سایبری است. سیستمهای آسیبپذیر در بخشهای صنعتی، از جمله شرکتهای آب، به دلیل شیوههای بهداشت سایبری ضعیف همچنان مورد بهرهبرداری قرار میگیرند. با استفاده از روشهای پیچیده مانند حملات brute-force و استفاده از رمزهای عبور پیشفرض، عوامل تهدید بارها موفق شدهاند فناوری عملیاتی (OT) و سیستمهای کنترل صنعتی (ICS) را به خطر بیندازند.
🔺حملات به بخش صنعتی بسیار پرهزینه بوده است. گزارش IBM Cost of a Data Breach در سال 2024 نشان داد که میانگین کل هزینه نقض داده در بخش صنعتی 5.56 میلیون دلار است — افزایشی 18 درصدی برای صنعت در مقایسه با سال 2023. این نشان دهنده بالاترین افزایش هزینه نقض داده در بین تمام صنایع مورد بررسی است. این گزارش، به طور متوسط 830000 دلار به ازای هر نقض نسبت به سال گذشته افزایش یافته است.
🔺آسیبپذیریهای مداوم تهدیدی جدی برای امنیت عمومی و امنیت ملی است، بهویژه که سیستمهای آب و سایر تأمینکنندگان زیرساختهای حیاتی در چشمانداز تهدید کنونی آمادگی لازم را ندارند. بیایید نگاهی دقیقتر به وضعیت فعلی امنیت زیرساختهای حیاتی بیندازیم، حوادث اخیر، تلاشها برای رسیدگی به آسیبپذیریها و نیاز به همکاری بیشتر بین دولت و بخشهای خصوصی را برجسته کنیم.
🔴The state of critical infrastructure cybersecurity
🔺On September 25, CISA issued a stark reminder that critical infrastructure remains a primary target for cyberattacks. Vulnerable systems in industrial sectors, including water utilities, continue to be exploited due to poor cyber hygiene practices. Using unsophisticated methods like brute-force attacks and leveraging default passwords, threat actors have repeatedly managed to compromise operational technology (OT) and industrial control systems (ICS).
🔺Attacks on the industrial sector have been particularly costly. The 2024 IBM Cost of a Data Breach report found the average total cost of a data breach in the industrial sector was $5.56 million — an 18% increase for the industry compared to 2023. This represents the highest data breach cost increase of all industries surveyed in the report, rising by an average of $830,000 per breach over last year.🔺Ongoing vulnerabilities pose a serious threat to public safety and national security, especially as water systems and other critical infrastructure providers remain underprepared in the current threat landscape. Let’s take a closer look at the current state of critical infrastructure security, highlighting recent incidents, efforts to address vulnerabilities and the need for further collaboration between the government and private sectors. 🚨 @Hackernewscyber
4 294
🔴مسدود کردن Tiktok در ایالات متحده در حال اجرا است، حدود 170 میلیون کاربر مطلع شده اند که این برنامه به طور موقت غیرفعال شده است.
🔺شرکت ByteDance تصمیم گرفت این برنامه را غیرفعال کند در صورتی که دولت بایدن اعلام کرد که دستور تعطیلی را اجرا نخواهد کرد.
🔺به نظر میرسد هدف تیکتاک تحت فشار قرار دادن دولت ترامپ است که حتی قبل از شروع به کار اعلام کرد که به Tiktok یک تمدید 90 روزه قبل از تعطیلی کامل در ایالات متحده داده است.
🔴The TikTok block is underway in the United States, with around 170 million users notified that the app has been temporarily disabled.
🔺ByteDance decided to disable the app if the Biden administration announced that it would not enforce the shutdown order.
🔺TikTok's goal seems to be to pressure the Trump administration, which even before taking office announced that it had given TikTok a 90-day extension before a full shutdown in the United States.
🚨 @Hackernewscyber
4 294
🔴چهار وب سایت اسرائیل توسط گروه هکری (Lulzsecblack) مورد حمله سایبری قرار گرفت.
🔘 dev.ivy.co.il
🔘 crm.ivy.co.il
🔘 ivy.co.il
🔘 new.ivy.co.il
✅ check:
🔘 https://mirror-h.org/search/hacker/73151/
🚨 @Hackernewscyber
4 294
🔴تعدادی از وب سایت های اسرائیل توسط گروه هکری (Indohaxsec) مورد حمله سایبری قرار گرفت
🔘 https://amanae.co.il
🔘 https://netaofer.co.il
🔘 http://pigen.co.il
🔘 https://timnat-energy.co.il
🔘 http://shitzer.co.il
🔘 http://endocrinology.co.il
🔘 https://landbankamerica.com
🚨 @Hackernewscyber
4 294
🔴آمریکا شرکت امنیت سایبری چین را به دلیل هک خزانه داری مرتبط با طوفان ابریشم تحریم کرد
🔺تحریم هایی علیه بازیگران چینی به دلیل هک وزارت خزانه داری که شامل 3000 پرونده سرقت شده و نقض مخابرات است.
🚨 @Hackernewscyber
4 294
🔴در روز های گذشته تعدادی از وب سایت های اسرائیل مورد حمله سایبری قرار گرفت است.
🔴In recent days, a number of Israeli websites have been subjected to cyberattacks
🔘 elbitsystems.com
🔘 slo.org.il
🔘 kiryat4.org.il
🔘 ymath.haifa.ac.il
🔘 nevedavid.org.il
🔘 bnpparibas.co.il
🔘 egged.co.il
🔘 meir.org.il
🔘 nta.co.il
🔘 assutaashdod.co.il
🔘 szmc.org.il
🔘 rail.co.il
🔘 hadassah.org.il
🔘 delek-group.com
🔘 bezeqint.net
🔘 account.cgov.gov.il
🔘 israelpost.co.il
🔘 ibank.org.il
🔘 israir.co.il
🔘 arkia.co.il
🔘 hot.net.il
🔘 unionbank.co.il
🔘 bankjerusalem.co.il
🔘 mercantile.co.il
🔘 caa.gov.il
🔘 partner.co.il
🔘 hymc.org.il
🔘 ravkavonline.co.il
🔘 drachim.co.il
🔘 histadrut.org.il
🔘 nta.co.il
🔘 meir.org.il
🚨 @HackerNewscyber
4 294
🔴 New FireScam data-stealing malware for Android is a fake Telegram Premium app
🔴 New Android malware called FireScam is being distributed under the guise of a premium version of the Telegram app via phishing sites on GitHub that mimic RuStore, a Russian mobile app marketplace.
📣 According to Cyfirma researchers, the malicious GitHub page that mimics RuStore first offers a dropper module called GetAppsRu.apk.
⭕ APK Dropper is obfuscated to avoid detection by DexGuard and is granted permissions that allow it to identify installed apps, grant them access to device storage, and install additional packages.
⭕It then extracts and installs the main malware file “Telegram Premium.apk,” which requests permission to monitor notifications, clipboard data, text messages, and phone services, among other things.
🚨 @HackerNewscyber
4 294
🔴بدافزار جدید سرقت اطلاعات FireScam برای اندروید جعل اپلیکیشن Telegram Premium است
🔴بدافزار جدید اندرویدی به نام FireScam تحت عنوان نسخه پریمیوم برنامه تلگرام از طریق سایتهای فیشینگ در GitHub توزیع میشود که از RuStore، یک بازار اپلیکیشن موبایل روسی تقلید میکنند.
📣به گفته محققان Cyfirma، صفحه مخرب GitHub که RuStore را تقلید می کند، ابتدا یک ماژول قطره چکان به نام GetAppsRu.apk ارائه می دهد.
⭕در ادامه: APK Dropper برای جلوگیری از شناسایی با DexGuard مبهم است و مجوزهایی به آن اعطا می شود که به آن اجازه می دهد برنامه های نصب شده را شناسایی کند، به آنها اجازه دسترسی به فضای ذخیره سازی دستگاه و نصب بسته های اضافی را بدهد.
⭕سپس فایل بدافزار اصلی «Telegram Premium.apk» را استخراج و نصب میکند که از جمله موارد دیگر، اجازه نظارت بر اعلانها، دادههای کلیپبورد، پیامکها و خدمات تلفن را میخواهد.
🚨 @HackerNewscyber
4 294
🔴وب سایت San Diego Light ایالات متحده آمریکا توسط گروه هکری DXPLOIT مورد حمله سایبری قرار گرفت.
🔴San Diego Light website in the United States was cyber-attacked by the DXPLOIT hacking group
🔘https://sandiegodelight.com/DXP.html
🔘https://www.zone-h.org/mirror/id/41314648
🚨 @HackerNewscyber
4 294
Telefónica confirms internal ticketing system breach after data leak
Spanish telecommunications company Telefónica confirms its internal ticketing system was breached after stolen data was leaked on a hacking forum.
Telefónica is a Spanish multinational telecommunications company operating in twelve countries with over 104,000 employees. The company is the largest telecommunications firm in Spain, operating under the name Movistar.
https://www.bleepingcomputer.com/news/security/telefonica-confirms-internal-ticketing-system-breach-after-data-leak/
📡@cRyPtHoN_INFOSEC_IT
📡@cRyPtHoN_INFOSEC_FR
📡@cRyPtHoN_INFOSEC_EN
📡@cRyPtHoN_INFOSEC_DE
📡@BlackBox_Archiv
4 294
🔴شرکت ارتباطی اسرائیل Orange/SCADA توسط گروه هکری RipperSec مورد حمله سایبری قرار گرفت
🔴Israeli telecommunications company Orange/SCADA hit by cyberattack by RipperSec hacking group
🔘https://www.orange.net.il
🚨 @HackerNewscyber
4 294
🔴شرکت ارتباطی اسرائیل Orange/SCADA توسط گروه هکری RipperSec مورد حمله سایبری قرار گرفت
🔘https://www.orange.net.il
🚨 @HackerNewscyber
4 294
Repost from DEFACER KAMPUNG
+1
#OP_SWIS
site : https://plessl.sia-dev.ch/test
#DEFACER_KAMPUNG
#savepalestine
#Z_BL4CK_H4T
#opindian
#opisrael
4 294
🚨Breaking: Mohammad Wissam Al-Daama has been killed, and several others injured, following an Israeli airstrike targeting a group of civilians in Jabalia Al-Balad, northern Gaza Strip.
4 294
♨️هکرها ده ها افزونه VPN و AI را برای Google Chrome هدف قرار می دهند تا داده ها را به خطر بیندازند
▪️محققان امنیت سایبری دهها حمله را کشف کردهاند که شامل بهروزرسانیهای مخرب برای افزونههای مرورگر کروم است، یک هفته پس از اینکه یک شرکت امنیتی در حادثهای مشابه در معرض خطر قرار گرفت.
▪️طبق گزارش ExtensionTotal، پلتفرمی که افزونههای فهرست شده را تجزیه و تحلیل میکند، تا چهارشنبه، در مجموع 36 افزونه کروم که با کد سرقت داده تزریق شدهاند، شناسایی شدهاند که بیشتر مربوط به ابزارهای هوش مصنوعی (AI) و شبکههای خصوصی مجازی (VPN) است. در بازارهای مختلف و دفاتر ثبت عمومی.
@HackerNewscyber
4 294
⭕وب سایت شرکت اتوبوسرانی اسرائیل هک شد!
🔗https://www.egged.co.il/
🔗https://check-host.net/check-report/21eb3812k62b
🚨 @HackerNewscyber
4 294
🔥وب سایت آمریکا مورد حمله سایبری قرار گرفت
🔘https://estatebuyers4america.com/index/
🔘https://mirror-h.org/zone/5817698/
🚨 @HackerNewscyber
