-->
#1 Trusted Cybersecurity News Platform
Followed by 5.20+ million
The Hacker News Logo
Subscribe – Get Latest News
Security Service Edge

The Hacker News | #1 Trusted Source for Cybersecurity News — Index Page

Two more Comodo registration authority accounts compromised !

Two more Comodo registration authority accounts compromised !

Mar 30, 2011
Two more Comodo registration authority accounts compromised ! Certification company’s humiliation drags on as hacker scalps two more Comodo registration authority accounts The Iranian hacker that managed to trick Comodo into issuing nine fraudulent certificates appears to have compromised two more registration authority accounts, raising questions of what exactly is going on at the certificate authority. “Two further RA accounts have since been compromised,” wrote Robin Alden, CTO of Comodo Security, on the mozilla-dev-security-policy mailing list. The partners have had their registration authority privileges withdrawn, Alden said. Comodo Retrofitting Broken Padlocks Alden made the announcement in an email addressing questions posed by the members of the mailing list. “No further mis-issued certificates have resulted from these compromises,” Alden said. The self-identified Comodo hacker (writing under the name Janam Fadaye Rahbar) claimed in a follow-up message on Pastebin to...
National Security Agency (NSA) to Investigate Nasdaq Hack

National Security Agency (NSA) to Investigate Nasdaq Hack

Mar 30, 2011
The National Security Agency has been called in to help investigate recent hack attacks against the company that runs the Nasdaq stock market, according to a news report. The agency’s precise role in the investigation hasn’t been disclosed, but its involvement suggests the October 2010 attacks may have been more severe than Nasdaq OMX Group has admitted, or it could have involved a nation-state, according to sources that spoke with Businessweek. “By bringing in the NSA, that means they think they’re either dealing with a state-sponsored attack or it’s an extraordinarily capable criminal organization,” Joel Brenner, former head of U.S. counterintelligence in the Bush and Obama administrations, told the publication. He added that the agency rarely gets involved in investigations of company breaches. Last year, the NSA was called in by Google to help the company secure its network after it was targeted in a sophisticated attack. Regarding the Nasdaq breach, in addition to the Secr...
Facebook Web Search Box May Be Dangerous

Facebook Web Search Box May Be Dangerous

Mar 30, 2011
Facebook users be warned: If you see a second search box at the top of your personal page, don’t use it. “ We are not testing the placement of a separate Web search field and have no plans to do so ,” a Facebook representative told the blog Search Engine Land. An image of a Facebook page with two search boxes has been making its way around the Internet for the past few days. In the image, the standard box that lets you search Facebook is visible at the top of the page, but just to the right of it is another search box reading “Search the Web.” Some tech news sites and blogs speculated that Facebook was testing out its own search engine, perhaps to challenge Google or to partner with a Google competitor such as Blekko or Microsoft’s Bing. The Facebook representative, however, said it’s likely a hack. “We believe the second search field or ‘ Search the We b’ box appeared on people’s accounts as the result of unknown actions by a third party targeting the browser (potentially a ...
cyber security

5 Cloud Security Risks You Can’t Afford to Ignore

websiteSentinelOneEnterprise Security / Cloud Security
Get expert analysis, attacker insights, and case studies in our 2025 risk report.
cyber security

Red Report 2026: Analysis of 1.1M Malicious Files and 15.5M Actions

websitePicus SecurityAttack Surface / Cloud Security
New research shows 80% of top ATT&CK techniques now target evasion to remain undetected. Get your copy now.
Anonymous Hackers Shut Down Music Industry Website Over $75 Trillion Lawsuit

Anonymous Hackers Shut Down Music Industry Website Over $75 Trillion Lawsuit

Mar 30, 2011
The Recording Industry Association of America (RIAA) website was hit by a distributed denial-of-service (DDoS) attack at the hands of the hacktivist group Anonymous. The DDoS attack was launched to protest the RIAA’s demand for $75 trillion in damages from the peer-to-peer music-sharing network LimeWire, the security firm Sophos reported. The attack occurred last Friday (March 25) at 7 p.m. EDT and brought down the RIAA site for about five hours. The site is back online now. According to Computerworld, Judge Kimba Wood of the U.S. District Court for the Southern District of New York rejected the RIAA’s lawsuit against LimeWire earlier this month, calling it “absurd” that the RIAA asked for up to $150,000 for 11,000 copyrighted songs made available for free on LimeWire. (Last October, Judge Wood ordered LimeWire to be taken down due to copyright infringement). The $75 trillion figure would be “more money than the entire music industry has made since Edison’s invention of the phono...
NASA Computer Networks Have Potentially Catastrophic Security Holes !

NASA Computer Networks Have Potentially Catastrophic Security Holes !

Mar 30, 2011
NASA’s internal computer network is full of holes and is extremely vulnerable to an external cyberattack, an audit by the Office of the Inspector General has found. Even worse, it appears several of the vulnerabilities have been known for months, yet remained unpatched. “Six computer servers associated with IT [information technology] assets that control spacecraft and contain critical data had vulnerabilities that would allow a remote attacker to take control of or render them unavailable,” the audit report released today (March 28) by Inspector General Paul K. Martin said. “The attacker could use the compromised computers to exploit other weaknesses we identified, a situation that could severely degrade or cripple NASA’s operations,” the report continued. “We also found network servers that revealed encryption keys, encrypted passwords, and user account information to potential attackers.” It is not unusual for previously unknown network security holes to be found in large orga...
20 pakistan sites defaced by APH

20 pakistan sites defaced by APH

Mar 30, 2011
20 pakistan sites defaced by APH defacers: hell hax0r, hell b3ind3r and crash viper ( must put these names) Sites defaces: here are the mirrors  http://ates-hatti.com/attack/? id=4096 http://ates-hatti.com/attack/? id=4097 http://ates-hatti.com/attack/? id=4098 http://ates-hatti.com/attack/? id=4099 http://ates-hatti.com/attack/? id=4100 http://ates-hatti.com/attack/? id=4101 http://ates-hatti.com/attack/? id=4102 http://ates-hatti.com/attack/? id=4103 http://ates-hatti.com/attack/? id=4104 http://ates-hatti.com/attack/? id=4105 http://ates-hatti.com/attack/? id=4106 http://ates-hatti.com/attack/? id=4107 http://ates-hatti.com/attack/? id=4108 http://ates-hatti.com/attack/? id=4109 http://ates-hatti.com/attack/? id=4110 http://ates-hatti.com/attack/? id=4111 http://ates-hatti.com/attack/? id=4112
University of Regina's web server hacked by SecurityBus

University of Regina's web server hacked by SecurityBus

Mar 29, 2011
University of Regina 's web server hacked by SecurityBus On Monday an intruder to the University of Regina's main web server was detected. As a result, the U of R took immediate steps to deal with the situation and the institution's website is currently unavailable. Some essential services are available for faculty, staff and students through a temporary website at www.uregina.ca. In a press release, the U of R stated that after an initial assessment it's believed that house, personal and student records including financial records have not been affected.
Facebook Vulnerability - Beware of A New XSS on Facebook !

Facebook Vulnerability - Beware of A New XSS on Facebook !

Mar 29, 2011
Facebook Vulnerability - Beware of A New XSS on Facebook ! Url :   https://m.facebook.com/connect/prompt_feed.php?display=wap&user_message_prompt=%3Cscript%3Ealert%281 %29%3C/script%3E New Cross-site scripting vulnerability has been detected on Facebook and widely exploited in the mobile API version, this vulnerability allows a malicious user to include JavaScript content into a website and redirect victim’s browser to the prepared URL. I have already saw this flaw in the last few days, many of my friend list are posting some strange things on the wall and by Just visiting the infected website is enough to post a message that the attacker has chosen. Therefore it should be of no surprise that some of those messages are spreading very fast through Facebook. Some are posting links to infected websites, creating XSS worms that spread from user to user. There is no user interaction required, so the messages are spreading through Facebook at a fast pace. Facebook’s securit...
Multiple Vulnerability in McAfee Website , XSS and Other Attacks !

Multiple Vulnerability in McAfee Website , XSS and Other Attacks !

Mar 29, 2011
Multiple Vulnerability in McAfee Website , XSS and Other Attacks ! Researchers at the YGN Ethical Hacker Group have revealed multiple security vulnerabilities found in the McAfee.com website that leaves the company's portal susceptible to attacks and data leakage. The group found that the McAfee website contains flaws that also pose a threat to users, such as a cross-site scripting (XSS) vulnerability in the site where customers can download software. XSS vulnerabilities allow attackers to bypass controls and inject script, meaning a hacker could potentially lead users to download malicious files when they believe they are accessing approved McAfee software. The YGN Ethical Hacker Group also found eighteen instances of source code disclosure which gives attackers an advantage in preparing attacks, as they can search for flaws in how the application handles data in the user interface, as well as allow the attacker to set up a practice version of the application for experimenta...
Expert Insights Articles Videos
Cybersecurity Resources