LastPass Warns of Hackers Misusing Reviews for Fake Support Numbers

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

LastPass, the popular password management service, has issued an urgent warning to its users about an ongoing social engineering campaign targeting customers through fake reviews on the Chrome Web Store. The company has discovered that threat actors post fraudulent 5-star …

Okta AD/LDAP Authentication Vulnerability Allows Unauthorized Access

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Okta, a leading company in identity and access management, has recently addressed a critical vulnerability in its AD/LDAP Delegated Authentication system. Okta’s security team internally discovered and promptly addressed the flaw, which could potentially allow unauthorized access to user accounts. …

DDoS Attacks Service Provider Websites Seized by Authorities

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

In a coordinated international effort, authorities have conducted a significant crackdown on cybercrime, arresting two suspects, seizing online platforms used for narcotics trafficking, and executing DDoS attacks. Two individuals, aged 19 and 28, from Darmstadt and the Rhein-Lahn district, were …

Azure Virtual Desktop May Experience 30 mins Black Screen During Logon

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Microsoft has warned Azure Virtual Desktop (AVD) users about potential black screen issues lasting up to 30 minutes when logging in after installing the July 2024 non-security preview update (KB5040525) or subsequent updates. This problem primarily affects enterprise users in …

Booking.com Phishers May Leave You With Reservations

Blog WriterCybersecurity News - Original News Source is krebsonsecurity.com

A number of cybercriminal innovations are making it easier for scammers to cash in on your upcoming travel plans. This story examines a recent spear-phishing campaign that ensued when a California hotel had its booking.com credentials stolen. We’ll also explore …

Email Phishing Playbook for Efficient Phishing Handling: Attack That’s Hard to Ignore

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Let’s not sugarcoat it: phishing is one of the most effective ways cybercriminals worm their way into your network. Why? Simple. As Stephanie Carruthers, a social engineering expert, bluntly puts it, “It works.” It’s easy to think that fancy firewalls …

FakeCall Malware Employs Vishing to Gain Full Control Over Mobile Devices

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A new variant of the notorious FakeCall malware has been discovered, using advanced vishing (voice phishing) techniques to deceive users and take near-total control of their mobile devices. Zimperium’s research team has raised alarms over this sophisticated threat, which targets …

Hackers Exploiting SharePoint RCE Vulnerability to Compromise Entire Domain

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated attack that compromised an entire domain by exploiting a critical vulnerability in Microsoft SharePoint. The attack, which remained undetected for two weeks, showcases threat actors’ evolving tactics and the importance of robust security measures. The attackers gained initial …

Hikvision Network Camera Flaw Let Attackers Intercept Dynamic DNS Credentials

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical security flaw has been discovered in Hikvision network cameras that could allow attackers to intercept Dynamic DNS (DDNS) credentials transmitted in cleartext, potentially exposing thousands of devices to unauthorized access and manipulation. The vulnerability affected multiple Hikvision camera …

Critical qBittorrent RCE Vulnerability Let Attackers Inject Malicious Script

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A severe security vulnerability in qBittorrent, affecting versions 3.2.1 through 5.0.0, has been discovered that allowed attackers to perform remote code execution (RCE) through multiple attack vectors. The flaw, which has gone unnoticed since April 2010, allows attackers to inject …