New DDoS Malware “cShell” Exploit Linux Tools to Attack SSH Servers

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The AhnLab Security Intelligence Center (ASEC) has uncovered a new strain of DDoS malware, named cShell, targeting poorly managed Linux SSH servers (screen and hping3). The malware exploits weak SSH credentials and leverages Linux tools to execute sophisticated DDoS attacks. …

Apache Struts RCE Vulnerability Actively Exploited in Wild Using Public PoC

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical security vulnerability has been identified in Apache Struts, a popular open-source framework for building Java-based web applications actively used in attacks leveraging publish PoC that allows attackers to execute malicious files on the server. Apache Struts is a free, …

Azure Data Factory And Apache Airflow Integration Flaws Let Attackers Gain Write Access

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Researchers uncovered new security vulnerabilities in the Azure Data Factory Apache Airflow integration dubbed “Dirty DAG”, which allow attackers to get unauthorized write permissions to a directed acyclic graph (DAG) file or use a compromised service principal. The vulnerabilities can …

FBI Warns Of HiatusRAT Attacking Web Cameras & DVRs To Gain Full Access

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The Federal Bureau of Investigation (FBI) has issued a Private Industry Notification (PIN) alerting cybersecurity professionals and system administrators about a new threat targeting web cameras and digital video recorders (DVRs). The malware, known as HiatusRAT, is actively scanning for …

RCE Vulnerability in 1,000,000 WordPress Sites Lets Attackers Gain Control Over Backend

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical Remote Code Execution (RCE) vulnerability (CVE-2024-6386), affecting over 1,000,000 active installations of the WordPress Multilingual Plugin (WPML). This flaw, stemming from a Server-Side Template Injection (SSTI) vulnerability in the Twig template engine, allowed attackers to execute arbitrary code …

Hackers Exploit Microsoft Management Console to Drop Backdoor Payloads on Windows

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Securonix Threat Research team has uncovered a sophisticated tax-related phishing campaign that employs Microsoft Common Console Document (MSC) files and advanced obfuscation techniques to deliver a stealthy backdoor payload. Dubbed the “FLUX#CONSOLE campaign,” this attack demonstrates the continued evolution of …

Hackers Leverage Red Team Tools in RDP Attacks Via TOR & VPN for Data Exfiltration

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

In a striking display of cyber sophistication, the advanced persistent threat (APT) group Earth Koshchei, also tracked as APT29 or Midnight Blizzard, has been linked to a massive rogue Remote Desktop Protocol (RDP) campaign. Earth Koshchei employs innovative tactics and …

1-Click RCE Attack in Kerio Control UTM Let Attackers Gain Root Access To the Firewall

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Researchers have identified a critical set of HTTP Response Splitting vulnerabilities in Kerio Control, a widely used Unified Threat Management (UTM) solution developed by GFI Software. The impact is severe, potentially enabling attackers to escalate low-severity issues into one-click remote …

Cisco to Acquire Threat Detection Company SnapAttack to Power Splunk

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cisco has announced its acquisition of the threat detection company SnapAttack. This acquisition aims to supercharge Cisco’s ever-expanding security portfolio, particularly by enhancing Splunk—Cisco’s leading Security Information and Event Management (SIEM) platform. The merger underscores Cisco’s commitment to empowering organizations in …

CISA Warns of Adobe & Windows Kernel Driver Exploited in Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The Cybersecurity and Infrastructure Security Agency (CISA) has issued an important warning after adding two critical vulnerabilities to its Known Exploited Vulnerabilities Catalog. These vulnerabilities flagged due to active evidence of exploitation, highlight the ongoing threat landscape for organizations of …