Category: CyberSecurityNews

Google’s New XRefer Tool to Analyze More Complex Malware Samples
18
Dec
2024

Google’s New XRefer Tool to Analyze More Complex Malware Samples

Google’s Mandiant FLARE team has unveiled XRefer, a cutting-edge tool designed to streamline the complex process of malware analysis. This…

CISA Issues Best Practices to Secure Microsoft 365 Cloud Environments
18
Dec
2024

CISA Issues Best Practices to Secure Microsoft 365 Cloud Environments

The Cybersecurity and Infrastructure Security Agency (CISA) has released Binding Operational Directive (BOD) 25-01, mandating federal civilian agencies to enhance…

cShell DDOS MALWARE
17
Dec
2024

New DDoS Malware “cShell” Exploit Linux Tools to Attack SSH Servers

The AhnLab Security Intelligence Center (ASEC) has uncovered a new strain of DDoS malware, named cShell, targeting poorly managed Linux…

Apache Struts RCE Vulnerability Actively Exploited in Wild Using Public PoC
17
Dec
2024

Critical RCE Vulnerability in Apache Struts Actively Exploited using Public PoC

A critical security vulnerability has been identified in Apache Struts, a popular open-source framework for building Java-based web applications actively…

FBI Warns Of HiatusRAT Attacking Web Cameras & DVRs To Gain Full Access
17
Dec
2024

FBI Warns Of HiatusRAT Attacking Web Cameras And DVRs To Gain Full Access

The Federal Bureau of Investigation (FBI) has issued a Private Industry Notification (PIN) alerting cybersecurity professionals and system administrators about…

Azure Data Factory And Apache Airflow Integration Flaws Let Attackers Gain Write Access
17
Dec
2024

Azure Data Factory And Apache Airflow Integration Flaws Let Attackers Gain Write Access

Researchers uncovered new security vulnerabilities in the Azure Data Factory Apache Airflow integration dubbed “Dirty DAG”, which allow attackers to…

WordPress Site vulnerability
17
Dec
2024

RCE Vulnerability in 1,000,000 WordPress Sites Lets Hackers Take Full Control

A critical Remote Code Execution (RCE) vulnerability (CVE-2024-6386), affecting over 1,000,000 active installations of the WordPress Multilingual Plugin (WPML). This…

Hackers Exploit Microsoft Management Console to Drop Backdoor Payloads on Windows
17
Dec
2024

Hackers Exploit Microsoft Management Console to Drop Backdoor on Windows

Securonix Threat Research team has uncovered a sophisticated tax-related phishing campaign that employs Microsoft Common Console Document (MSC) files and…

Red Team Tools in RDP Attacks
17
Dec
2024

Hackers Leverage Red Team Tools in RDP Attacks Via TOR & VPN for Data Exfiltration

In a striking display of cyber sophistication, the advanced persistent threat (APT) group Earth Koshchei, also tracked as APT29 or…

Kerio Control Firewall
17
Dec
2024

1-Click RCE Attack in Kerio Control Firewall Let Attackers Take Full Control Remotely

Researchers have identified a critical set of HTTP Response Splitting vulnerabilities in Kerio Control, a widely used Unified Threat Management…

CISA Warns of Adobe & Windows Kernel Driver Exploited in Attacks
17
Dec
2024

CISA Warns of Adobe & Windows Kernel Driver Exploited in Attacks

The Cybersecurity and Infrastructure Security Agency (CISA) has issued an important warning after adding two critical vulnerabilities to its Known…

Cisco to Acquire Threat Detection Company SnapAttack to Power Splunk
17
Dec
2024

Cisco to Acquire Threat Detection Company SnapAttack to Power Splunk

Cisco has announced its acquisition of the threat detection company SnapAttack. This acquisition aims to supercharge Cisco’s ever-expanding security portfolio, particularly…