14 North Korean IT Workers Charged, US to Offer $5 Million Rewards for Info

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A federal court in St. Louis, Missouri, has indicted 14 North Korean nationals in a sophisticated scheme involving IT workers who allegedly defrauded US companies and funneled millions of dollars to North Korea’s weapons programs. The indictment, unsealed on Wednesday, …

Bitcoin ATM Operator Hacked, 58,000 Users’ Personal Data Compromised

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Byte Federal, one of the largest Bitcoin ATM operators in the United States, has reported a significant data breach affecting approximately 58,000 customers. In a recent security incident, Byte Federal, a prominent provider of financial services, disclosed that it experienced …

Vulnerabilities in Skoda & Volkswagen Cars Let Hackers Remotely Track Users

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cybersecurity researchers have discovered several vulnerabilities in the infotainment systems of certain Skoda and Volkswagen car models. These vulnerabilities may allow hackers to track and access sensitive user data remotely. PCAutomotive, a specialized automotive cybersecurity firm, recently disclosed 12 new …

Nova Keylogger – A Snake Malware Steal Credentials and Capture Screenshorts From Windows

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Security researchers have uncovered Nova, a sophisticated evolution of the Snake Keylogger malware family, demonstrating advanced data stealing capabilities and improved evasion techniques. This new variant represents a significant advancement in malware development, posing increased risks to both personal and …

iOS Facebook Messenger Group Call DoS Vulnerability Exploited Using Emoji

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A newly discovered vulnerability in Facebook Messenger for iOS has revealed a critical flaw that could disrupt group calls by exploiting emoji reactions. This denial-of-service (DoS) bug, identified by Signal 11 Research in version 472.0.0 and analyzed in version 477.0.0, …

Europol Shuts Down 27 DDoS Attack Platform Providers, Admins Arrested

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Law enforcement agencies worldwide have disrupted a holiday tradition of launching Distributed Denial-of-Service (DDoS) attacks in a major blow to cybercriminals. As part of Operation PowerOFF, an ongoing international crackdown coordinated by Europol, authorities have seized 27 of the most …

ChatGPT Down Globally, Services Restored After Hours Of Outage

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

In a significant disruption, OpenAI’s popular AI chatbot, ChatGPT, experienced a global outage on Thursday morning, leaving millions of users unable to access its services for nearly three hours. The outage, which began shortly before 7 PM ET (5:30 AM …

Malichus Malware Exploiting Cleo 0-day Vulnerability In Wild

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Threat actors are actively exploiting a critical zero-day vulnerability (CVE-2024-50623) in Cleo’s file transfer products Harmony, VLTrader, and LexiComis. The flaw, stemming from an unrestricted file upload and download vulnerability, allows unauthenticated remote code execution (RCE), posing a severe risk …

New BadRAM Attack Exploits AMD SEV Protections, Threatens Cloud Security

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Researchers have uncovered a critical vulnerability in AMD’s Secure Encrypted Virtualization (SEV) technology that could compromise sensitive data in cloud environments. Dubbed “BadRAM,” this attack leverages rogue memory modules to bypass SEV protections, including the latest SEV-SNP version, undermining the …

Splunk Secure Gateway App Vulnerability Let Attackers Execute Remote Code

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical vulnerability has been discovered in the Splunk Secure Gateway app, potentially allowing low-privileged users to execute arbitrary code remotely. The flaw, identified as CVE-2024-53247, affects multiple versions of Splunk Enterprise and the Splunk Secure Gateway app on the …