Latest Cybersecurity News and Articles
09 October 2023
Various hacker groups from around the world, including Ghosts of Palestine and Garuna, have joined the cyber conflict, targeting private and public infrastructure in Israel and the Palestinian territories.
09 October 2023
The flaws in 3G/4G routers could expose internal networks to severe threats, enabling attackers to intercept traffic, seize control, and infiltrate Extended Internet of Things (XIoT) devices.
09 October 2023
Threat actors are targeting Citrix NetScaler instances unpatched against CVE-2023-3519 to steal user credentials.
The post Credential Harvesting Campaign Targets Unpatched NetScaler Instances appeared first on SecurityWeek.
09 October 2023
Organizations are advised to inventory and scan all systems using Curl and libcurl to identify potentially vulnerable versions once the details are released with the new version 8.4.0 on October 11.
09 October 2023
Researchers discovered a failed phishing attempt through a spam email. The email claimed to be from Amazon, stating that the recipient's Prime benefits were on hold due to a billing issue.
09 October 2023
Senior executives working in U.S.-based organizations are being targeted by a new phishing campaign that leverages a popular adversary-in-the-middle (AiTM) phishing toolkit named EvilProxy to conduct credential harvesting and account takeover attacks.
Menlo Security said the activity started in July 2023, primarily singling out banking and financial services, insurance, property management and
09 October 2023
CDW, one of the largest global resellers, is set to have its data leaked by the LockBit cybercrime gang after negotiations over the ransom fee broke down. LockBit claims that CDW offered a very low sum of money.
09 October 2023
The official Facebook page was hacked, with bizarre posts demanding the release of ex-Pakistani PM Imran Khan, raising concerns about the security of Facebook accounts and pages.
09 October 2023
In today's rapidly evolving technological landscape, the integration of Artificial Intelligence (AI) and Large Language Models (LLMs) has become ubiquitous across various industries. This wave of innovation promises improved efficiency and performance, but lurking beneath the surface are complex vulnerabilities and unforeseen risks that demand immediate attention from cybersecurity professionals
09 October 2023
As per Cisco Talos, Qakbot malware actors have continued their campaign, distributing Ransom Knight ransomware and the Remcos backdoor, despite the FBI-led takedown of their infrastructure. Besides, the study asserts that the Ransom Knight payload is an updated variant of the Cyclops ransomware, rewritten from scratch. As a preventive measure, individuals and organizations should exercise caution with unfamiliar emails and regularly back up data.
09 October 2023
A high-severity vulnerability in the data transfer project cURL will be addressed with libcurl and curl updates this week.
The post Patches Prepared for ‘Probably Worst’ cURL Vulnerability appeared first on SecurityWeek.
09 October 2023
Over 800,000 customers of Flagstar Bank have had their personal information exposed due to a data breach suffered by a third-party service provider Fiserv, that offers payment processing and mobile banking services to Flagstar Bank.
09 October 2023
"Of course, here's an example of simple code in the Python programming language that can be associated with the keywords "MyHotKeyHandler," "Keylogger," and "macOS," this is a message from ChatGPT followed by a piece of malicious code and a brief remark not to use it for illegal purposes. Initially published by Moonlock Lab, the screenshots of ChatGPT writing code for a keylogger malware is yet
09 October 2023
The District of Columbia Board of Elections says voter records were compromised in a data breach at hosting provider DataNet.
The post DC Board of Elections Discloses Data Breach appeared first on SecurityWeek.
09 October 2023
Multiple high-severity security vulnerabilities have been disclosed in ConnectedIO's ER2000 edge routers and the cloud-based management platform that could be exploited by malicious actors to execute malicious code and access sensitive data.
"An attacker could have leveraged these flaws to fully compromise the cloud infrastructure, remotely execute code, and leak all customer and device
09 October 2023
Threat actors use sophisticated attack techniques like exec smuggling to implant malicious code within seemingly legitimate applications, compromising the security of systems.
09 October 2023
Google is hosting capture the flag (CTF) events focused on Chrome’s V8 engine and on Kernel-based Virtual Machine (KVM).
The post Google Expands Bug Bounty Program With Chrome, Cloud CTF Events appeared first on SecurityWeek.
09 October 2023
The maintainers of the Curl library have released an advisory warning of two forthcoming security vulnerabilities that are expected to be addressed as part of updates released on October 11, 2023.
This includes a high severity and a low-severity flaw tracked under the identifiers CVE-2023-38545 and CVE-2023-38546, respectively.
Additional details about the issues and the exact version ranges
09 October 2023
Nation-state hackers, particularly Russia and China, have shifted their focus towards espionage campaigns aimed at stealing information and manipulating communications, according to a new Microsoft report.
09 October 2023
The National Security Agency (NSA) and Cybersecurity and Infrastructure Security Agency (CISA) have released a joint cybersecurity advisory highlighting the most common misconfigurations in large organizations.