Sudanese Brothers Arrested in ‘AnonSudan’ Takedown

Blog WriterCybersecurity News - Original News Source is krebsonsecurity.com

The U.S. government on Wednesday announced the arrest and charging of two Sudanese brothers accused of running Anonymous Sudan (a.k.a. AnonSudan), a cybercrime business known for launching powerful distributed denial-of-service (DDoS) attacks against a range of targets, including dozens of …

ANY.RUN’s Upgraded Linux Sandbox for Fast and Secure Malware Analysis

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

ANY.RUN upgraded its Linux sandbox with features to enhance malware analysis. It now uses a stable Chrome browser for smoother interaction with suspicious websites, while lag in the process tree view is eliminated, allowing for faster exploration of running processes.  Users can …

Authorities take down Gang Behind ATM Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Dutch, French, and German police forces arrested three members of a notorious criminal network responsible for a series of violent attacks on ATMs across Europe. The coordinated operation occurred in the early hours of October 16, 2024, marking a pivotal …

Multihomed Linux Devices Flaw Allows Spoof of Internal Communication

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical vulnerability has been discovered in multihomed Linux devices. It allows attackers to spoof and inject packets into internal communication streams via an external or public interface. Security researchers uncovered the flaw during several assessments, and it has been …

Iranian actors selling Login Access to Organizations networks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

International security agencies have raised alarms about Iranian cyber actors compromising networks across critical infrastructure sectors. These actors reportedly sell login access to these networks, posing significant risks to global cybersecurity. This article delves into the methods used by these …

Trend Micro Cloud Edge Vulnerability Let Attackers Execute Arbitrary Code

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Trend Micro has issued an urgent security bulletin warning users of a critical vulnerability in its Cloud Edge appliance that could allow remote attackers to execute arbitrary code without authentication. The vulnerability tracked as CVE-2024-48904 has been assigned a CVSS …

VMware HCX Vulnerability Let Attackers Inject Malicious SQL Queries

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

VMware has disclosed a critical security vulnerability in its HCX platform, a key component for hybrid cloud extension solutions. The flaw, identified as CVE-2024-38814, allows authenticated users with non-administrator privileges to perform SQL injection attacks, potentially leading to unauthorized remote …

Anonymous Sudan Hackers Charged for Cyber Attacks on Critical Infrastructure

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A federal grand jury indictment unsealed today charges two Sudanese nationals with operating and controlling Anonymous Sudan, an online cybercriminal group responsible for tens of thousands of Distributed Denial of Service (DDoS) attacks against critical infrastructure, corporate networks, and government …

Top 10 Best Insider Risk Management Solutions – 2024

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Insider Risk is the amount of damage any event can cause due to an insider threat activity. According to a study by The Ponemon Institute, the average cost of an insider threat to an organization increases by 76%.  Data is …

What is Certificate-Based Authentication? How it Works!

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Certificate-Based Authentication (CBA) is a robust security mechanism that has been a cornerstone in high-security environments for decades. It leverages digital certificates to verify the identity of users, devices, or machines before granting access to resources. This article delves into …