Operation Destabilise, Authorities Dismateled Cybercriminals Money Laundering Network

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

In a major international operation codenamed “Operation Destabilise,” law enforcement agencies have successfully dismantled sophisticated Russian money laundering networks that served cybercriminals, drug traffickers, and sanctioned Russian elites worldwide. The operation, led by the National Crime Agency (NCA), exposed two …

Hackers Exploit Docker Remote API Servers To Inject Gafgyt Malware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The Gafgyt malware (often referred to as Bashlite or Lizkebab) has expanded its attack scope by targeting publicly exposed Docker Remote API servers. Gafgyt malware, also known as Bashlite, and Mirai have targeted millions of vulnerable IoT devices in recent …

U.S. Offered $10M for Hacker Just Arrested by Russia

Blog WriterCybersecurity News - Original News Source is krebsonsecurity.com

In January 2022, KrebsOnSecurity identified a Russian man named Mikhail Matveev as “Wazawaka,” a cybercriminal who was deeply involved in the formation and operation of multiple ransomware groups. The U.S. government indicted Matveev as a top ransomware purveyor a year …

SolarWinds Platform XSS Vulnerability Let Attackers Inject Malicious Code

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical security vulnerability has been recently disclosed by SolarWinds in its Platform product, a major player in IT management software. The flaw, identified as CVE-2024-45717, allows authenticated attackers to inject malicious code through a cross-site scripting (XSS) vulnerability. This …

HR & IT-Related Phishing Emails Are Top-Clicked Among Phishing Email Types

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Phishing emails masquerading as HR and IT-related communications are the most likely to be clicked on by employees as unveiled in a recent study, posing a significant cybersecurity risk to organizations across various industries. The 2024 Phishing by Industry Benchmarking …

HackSynth An Autonomous Penetration Testing Framework For Simulating Cyber-Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The introduction of HackSynth marks a significant advancement in the field of autonomous penetration testing. Developed by researchers at Eotvos Lorand University, HackSynth leverages Large Language Models (LLMs) to autonomously conduct penetration tests, simulating cyber-attacks to identify vulnerabilities in systems …

Cloudflare Developer Domains Abused For Cyber Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cloudflare developer domains are actively abused by the threat actors for several illicit malicious purposes, as reported by the security analysts at FORTRA. Recent investigations have uncovered a significant surge in attacks targeting Cloudflare Pages and Cloudflare Workers, two popular …

New TLDs Like .shop, .top And .xyz Attracting Phishers

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A significant surge in phishing attacks has been unveiled by a recent study conducted by Interisle Consulting, with a nearly 40% increase in the year ending August 2024. The research highlights that much of this growth is concentrated in a …

Google Chrome Type Confusion Vulnerability Let Attackers Execute Remote Code

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A high-severity type confusion vulnerability in the V8 JavaScript engine of Google Chrome was recently discovered by independent researchers. As a result of this discovery, Google Chrome users are urged to update their browsers immediately. The flaw, identified as CVE-2024-12053, …

PoC Exploit Released For Progress WhatsUp Gold Vulnerability

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical security flaw in Progress WhatsUp Gold, a popular network monitoring tool, has been exposed with the release of a proof-of-concept (PoC) exploit. The vulnerability, identified as CVE-2024-8785, affects versions of WhatsUp Gold prior to 24.0.1 and poses a …