Google’s New XRefer Tool to Analyze More Complex Malware Samples

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Google’s Mandiant FLARE team has unveiled XRefer, a cutting-edge tool designed to streamline the complex process of malware analysis. This innovative plugin for IDA Pro aims to revolutionize how analysts navigate and understand increasingly sophisticated malware samples, particularly those written …

CISA Issues Best Practices to Secure Microsoft 365 Cloud Environments

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The Cybersecurity and Infrastructure Security Agency (CISA) has released Binding Operational Directive (BOD) 25-01, mandating federal civilian agencies to enhance the security of their Microsoft 365 cloud environments. This directive is part of CISA’s broader effort to mitigate risks associated …

New DDoS Malware “cShell” Exploit Linux Tools to Attack SSH Servers

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The AhnLab Security Intelligence Center (ASEC) has uncovered a new strain of DDoS malware, named cShell, targeting poorly managed Linux SSH servers (screen and hping3). The malware exploits weak SSH credentials and leverages Linux tools to execute sophisticated DDoS attacks. …

Apache Struts RCE Vulnerability Actively Exploited in Wild Using Public PoC

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical security vulnerability has been identified in Apache Struts, a popular open-source framework for building Java-based web applications actively used in attacks leveraging publish PoC that allows attackers to execute malicious files on the server. Apache Struts is a free, …

Azure Data Factory And Apache Airflow Integration Flaws Let Attackers Gain Write Access

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Researchers uncovered new security vulnerabilities in the Azure Data Factory Apache Airflow integration dubbed “Dirty DAG”, which allow attackers to get unauthorized write permissions to a directed acyclic graph (DAG) file or use a compromised service principal. The vulnerabilities can …

FBI Warns Of HiatusRAT Attacking Web Cameras & DVRs To Gain Full Access

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The Federal Bureau of Investigation (FBI) has issued a Private Industry Notification (PIN) alerting cybersecurity professionals and system administrators about a new threat targeting web cameras and digital video recorders (DVRs). The malware, known as HiatusRAT, is actively scanning for …

RCE Vulnerability in 1,000,000 WordPress Sites Lets Attackers Gain Control Over Backend

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical Remote Code Execution (RCE) vulnerability (CVE-2024-6386), affecting over 1,000,000 active installations of the WordPress Multilingual Plugin (WPML). This flaw, stemming from a Server-Side Template Injection (SSTI) vulnerability in the Twig template engine, allowed attackers to execute arbitrary code …

Hackers Exploit Microsoft Management Console to Drop Backdoor Payloads on Windows

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Securonix Threat Research team has uncovered a sophisticated tax-related phishing campaign that employs Microsoft Common Console Document (MSC) files and advanced obfuscation techniques to deliver a stealthy backdoor payload. Dubbed the “FLUX#CONSOLE campaign,” this attack demonstrates the continued evolution of …

Hackers Leverage Red Team Tools in RDP Attacks Via TOR & VPN for Data Exfiltration

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

In a striking display of cyber sophistication, the advanced persistent threat (APT) group Earth Koshchei, also tracked as APT29 or Midnight Blizzard, has been linked to a massive rogue Remote Desktop Protocol (RDP) campaign. Earth Koshchei employs innovative tactics and …

1-Click RCE Attack in Kerio Control UTM Let Attackers Gain Root Access To the Firewall

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Researchers have identified a critical set of HTTP Response Splitting vulnerabilities in Kerio Control, a widely used Unified Threat Management (UTM) solution developed by GFI Software. The impact is severe, potentially enabling attackers to escalate low-severity issues into one-click remote …