Category: CyberSecurityNews

New Cookie Sandwich Technique Let Attackers Bypass HttpOnly Flag On Servers
23
Jan
2025

New Cookie Sandwich Technique Let Attackers Bypass HttpOnly Flag On Servers

A newly discovered attack technique, dubbed the “cookie sandwich,” enables attackers to bypass the HttpOnly flag on certain servers, exposing…

New Supply Chain Attack Targeting Chrome Extensions To Inject Malicious Code
23
Jan
2025

New Supply Chain Attack Targeting Chrome Extensions To Inject Malicious Code

A sophisticated supply chain attack targeting Chrome browser extensions has compromised at least 35 Chrome extensions, potentially exposing over 2.6…

Helldown Ransomware Exploiting Zyxel Devices Using Zero-Day Vulnerability
22
Jan
2025

Helldown Ransomware Exploiting Zyxel Devices Using Zero-Day Vulnerability

A new ransomware threat dubbed “Helldown” has emerged, actively exploiting vulnerabilities in Zyxel firewall devices to breach corporate networks. Cybersecurity…

Malicious VS Code Mimic As Zoom App Steals Cookies From Chrome
22
Jan
2025

Malicious VS Code Mimic As Zoom App Steals Cookies From Chrome

Cybersecurity researchers have uncovered a new threat targeting developers using Visual Studio Code (VS Code). A malicious extension masquerading as…

AWS Releases Best Security Practices To Mitigate Ransomware Attacks
22
Jan
2025

AWS Releases Best Security Practices To Mitigate Ransomware Attacks

Amazon Web Services (AWS) has announced a set of best practices aimed at helping customers protect their cloud environments against…

Ex-CIA Analyst Pleads Guilty To Leaking National Defense Information
22
Jan
2025

Ex-CIA Analyst Pleads Guilty To Leaking National Defense Information

A former CIA analyst, Asif William Rahman, 34, pleaded guilty today to unlawfully retaining and transmitting Top Secret National Defense…

China Hackers Compromised VPN Service Provider in Supply-Chain Attack
22
Jan
2025

China Hackers Compromised VPN Service Provider in Supply-Chain Attack

A sophisticated supply-chain attack targeting a South Korean VPN provider. The attack has been attributed to a previously undisclosed China-aligned…

Threat Actors Delivering Ransomware Via Microsoft Teams Using Voice Calls
22
Jan
2025

Threat Actors Delivering Ransomware Via Microsoft Teams Using Voice Calls

Sophos Managed Detection and Response (MDR) has uncovered two distinct ransomware campaigns exploiting Microsoft Teams to gain unauthorized access to…

318 Vulnerabilities Patched in January 2025 Oracle Critical Security Update
22
Jan
2025

318 Vulnerabilities Patched in January 2025 Oracle Critical Security Update

Oracle has released its January 2025 Critical Patch Update (CPU), addressing 318 newly discovered security vulnerabilities across its extensive product…

Attackers Exploit IBM i Access Client Solutions on Windows 11 To Steal Passwords
22
Jan
2025

Attackers Exploit IBM i Access Client Solutions on Windows 11 To Steal Passwords

A recent investigation has revealed that attackers are exploiting vulnerabilities in IBM i Access Client Solutions (ACS) to steal Windows…

0-Click Deanonymization Attack Exploits Telegram, Signal, Discord & Other Apps
22
Jan
2025

0-Click Deanonymization Attack Exploits Telegram, Signal, Discord & Other Apps

0-Click Deanonymization Attack Exploits Telegram, Signal, Discord, & Other AppsA new zero-click deanonymization attack has been discovered that can potentially…

Record-breaking 5.6 Tbps DDoS Attack From 13,000 Mirai Hacked Devices
22
Jan
2025

Record-breaking 5.6 Tbps DDoS Attack From 13,000 Mirai Hacked Devices

Cloudflare recently thwarted the largest distributed denial-of-service (DDoS) attack ever recorded, peaking at an unprecedented 5.6 terabits per second (Tbps)….