-->
#1 Trusted Cybersecurity News Platform
Followed by 5.70+ million
The Hacker News Logo
Get the Latest News
cybersecurity

The Hacker News | #1 Trusted Source for Cybersecurity News — Index Page

Unpatched Flaw in IE Bypasses Key Windows Security Features

Unpatched Flaw in IE Bypasses Key Windows Security Features

Dec 23, 2010
An exploit exploiting an unpatched vulnerability in Internet Explorer (IE) has gone public. Security researcher Shahin Ramezany announced in a Tuesday tweet that he successfully exploited the flaw, which involves how IE handles CSS style sheets on Windows 7 and Vista machines. Offensive Security, a provider of security tools and training, posted a video demonstrating the code execution on Monday. On Wednesday, the exploit code was added to the open-source Metasploit hacking toolkit. This flaw can bypass two built-in Windows security features: Data Execution Prevention (DEP) and Address Space Layout Randomization (ASLR), according to Ramezany. Microsoft has not yet confirmed the vulnerability. "We're currently unaware of any attacks trying to use the claimed vulnerability or of customer impact," said Dave Forstrom, director of trustworthy computing at Microsoft, in an email to SCMagazineUS.com on Wednesday. "Once we're done investigating, we will take appropriat...
CitySights NY Data Breach Exposes 110,000 Customers' Personal Information

CitySights NY Data Breach Exposes 110,000 Customers' Personal Information

Dec 23, 2010
CitySights NY, a company that organizes New York City tours on double-decker buses, has experienced a significant data breach. The personal information of 110,000 customers, including names, addresses, email addresses, credit card numbers, expiration dates, and Card Verification Value (CVV2) codes, was stolen. The breach likely occurred on September 26, when attackers used an SQL injection to upload a malicious script to the web server. The intrusion was discovered on October 25 by a web programmer who found the unauthorized script. According to a breach notification letter sent to and published by New Hampshire's attorney general, Twin America, CitySights NY's parent company, confirmed the compromise. In response to the breach, Twin America has taken several steps to enhance data security, including: Changing all administrative-level passwords to more complex ones. Restricting access to the administration panel and server to a few pre-approved IP addresses. Patching scri...
PandaLabs Predicts Major Cybersecurity Trends for 2011

PandaLabs Predicts Major Cybersecurity Trends for 2011

Dec 23, 2010
PandaLabs, the antimalware laboratory of Panda Security, has predicted several major cybersecurity threats for 2011. These include hacktivism, cyber warfare, profit-driven malware, social engineering, and adaptive malicious codes. Additionally, there will be increased threats to Mac users, new attacks on 64-bit systems, and more zero-day exploits. Here is a summary of PandaLabs' top ten security trends for 2011: Malware Creation : In 2010, PandaLabs observed significant growth in malware, identifying 20 million new strains, more than in 2009. Currently, Panda’s Collective Intelligence database contains over 60 million classified threats. Although the year-on-year growth rate has peaked, it was 50% in 2010, down from over 100% in previous years. Cyber Warfare : Incidents like Stuxnet and the WikiLeaks cables, which suggested Chinese government involvement in cyber-attacks on Google, marked a turning point in cyber conflicts. Stuxnet targeted uranium centrifuges in nuclear pl...
cyber security

State of AI in the Cloud 2026: How AI is Reshaping Cloud Attack Surface

websiteWizAI Security / Cloud Security
Join Wiz Research on June 16 to explore key findings from the State of AI in the Cloud 2026 report, covering AI adoption trends, evolving cloud risks, and how attackers are leveraging AI to exploit misconfigurations.
cyber security

Free Assessment: Identify Hidden Internal Risk

websiteBitdefenderAttack Surface / Threat Detection
Discover unnecessary user access to risky tools, shadow IT, based on real user behavior.
W32.Yimfoca Worm Targets Facebook Users via Yahoo! Messenger

W32.Yimfoca Worm Targets Facebook Users via Yahoo! Messenger

Dec 23, 2010
A new computer worm is denying Facebook users access to their accounts. The worm, named "W32.Yimfoca" by the security company Symantec, spreads through Yahoo! Messenger and specifically targets Facebook users. It forces them to complete surveys before they can log into their profiles. The worm begins by sending an instant message containing a corrupted link. When a user clicks the link, the worm installs malware on their system. Later, when users visit Facebook, they see a message stating, "Your account is suspended. To make your account active, you need to complete one of these surveys," followed by a list of options like "Test Your Celebrity IQ here" and "Win a FREE iPhone 4." If users choose to fill out a survey, another message appears: "You have only 3 minutes to fill out the selected survey or you will not have access to your account." Each time a survey is completed, the creators of the worm earn $1, according to Symantec. The ...
January: Prime Month for Mail Theft and Identity Fraud

January: Prime Month for Mail Theft and Identity Fraud

Dec 23, 2010
Checking the mail in December is typically a pleasant experience, filled with holiday cards and packages. Then comes January. Besides the Christmas bills, mailboxes begin to overflow with W-2s, 1099s, statements from financial institutions, and IRS forms. It's no wonder John Ulzheimer, president of consumer education for Smartcredit.com, calls January the most dangerous month for mail. “January is a high-value month for thieves,” he said. It's particularly easy for thieves to dip into someone’s mailbox, take the envelopes, and gain all the information needed to steal someone else’s identity. How to best protect mail, short of meeting the mail carrier at the mailbox each day, is a significant challenge. You shouldn’t stop your mail because many items are time-sensitive. Creating an alternative delivery destination, like a P.O. box, could cause more trouble than it’s worth, said Ulzheimer. The first step is to know what tax-related statements you s...
Expert Insights Articles Videos
Cybersecurity Resources