hrtng: A Powerful IDA Pro Plugin for Malware Reverse Engineering

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Researchers from Kaspersky’s Global Research and Analysis Team have released a powerful new IDA Pro plugin called “hrtng,” designed to streamline and simplify the complex process of malware reverse engineering. This open-source tool, now available on GitHub under the GPLv3 …

One Identity Named Winner of the Coveted Top InfoSec Innovator Awards for 2024

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

One Identity named Hot Company: Privileged Access Management (PAM) in 12th Cyber Defense Magazine’s Annual InfoSec Awards during CyberDefenseCon 2024. One Identity proudly announces it has been named a winner in the Hot Company: Privileged Access Management (PAM) category in …

U.S. Organization In China Attacked By China-Based Hackers

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A large U.S. organization with significant operations in China fell victim to a sophisticated cyber attack, likely orchestrated by China-based hackers. The intrusion, which lasted for four months from April to August 2024, allowed the attackers to maintain a persistent …

Examples of Phishing Attacks and How to Effectively Analyze Them

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Analyzing phishing attacks have become challenging as these threats continue to evolve in complexity, employing more sophisticated techniques to bypass traditional defenses.  The tools used to analyze such attacks must also adapt, requiring constant improvement to keep up with the …

WordPress Gutenberg Editor Vulnerability Let Attackers Inject Malicious Scripts

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A newly disclosed vulnerability in the Gutentor – Gutenberg Blocks – Page Builder for Gutenberg Editor plugin for WordPress has raised concerns among website administrators and developers. The flaw, identified as CVE-2024-10178, allows attackers with contributor-level access or higher to …

Sophisticated Celestial Stealer Attacking Browsers to Steal Login Credentials

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Celestial Stealer, a JavaScript-based infostealer packaged either as an Electron application, has been spotted targeting both Chromium and Gecko-based browsers to steal browser data. The stealer is specifically targeting the system’s browsers attempting to steal the browser’s history, saved passwords, …

New DroidBot Malware Attacking 77 Banks And Cryptocurrency Exchange Services

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

DroidBot is an advanced Android Remote Access Trojan (RAT) that targets 77 different organizations, including national organizations, cryptocurrency exchanges, and banks.  Active campaigns have been detected in countries including the United Kingdom, Italy, France, Spain, and Portugal, indicating a potential …

HCL DevOps Deploy & Launch Vulnerable To HTML Injection Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A recently disclosed vulnerability in HCL Software’s DevOps Deploy and Launch platforms has raised security concerns. Identified as CVE-2024-42195, this vulnerability allows attackers to embed arbitrary HTML tags within the web user interface (UI), potentially leading to sensitive information disclosure. …

Fuji Electric Indonesia Hit By Ransomware Attack, Business Information Compromised

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

In a concerning development, Fuji Electric Indonesia (FEID) has fallen victim to a ransomware attack, potentially exposing sensitive business partner information. The incident, which occurred on Wednesday, November 27th, has left several of FEID’s PCs and servers inoperable, raising alarms …

Mitel MiCollab Zero-Day Vulnerability Let Attackers Bypass Authentication

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Security researchers have uncovered a critical zero-day vulnerability in Mitel MiCollab, a popular unified communications solution. The flaw, which remains unpatched, allows attackers to perform arbitrary file reads on the server’s filesystem, potentially compromising sensitive information and system security. The …