GoldenJackal Using Custom Toolset To Attack Air-Gapped Systems

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Air-gapped systems are security measures that isolate “computers” and “networks” from external connections (like the “internet”) to block ‘unauthorized access’ and ‘cyber threats.’ ⁤ ⁤This isolation can be done via “physical disconnection” or “logical configurations” that restrict the network traffic. …

Russia Bans Discord Following Illegal Content Issues

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The Russian Federal Service for Supervision of Communications, Information Technologies, and Mass Media has officially blocked the popular communication platform Discord within the country. This decision came after Discord was found to violate Russian laws regarding monitoring and removing unlawful …

DumpForums Claims to Have Stolen 10TB Data from Cybersecurity Firm Dr.Web

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A notable hacking forum, DumpForums, has claimed responsibility for a massive data breach targeting Dr.Web, a prominent Russian cybersecurity company. The hackers allege that they have exfiltrated a staggering 10 terabytes of sensitive data from the firm’s infrastructure, which has …

Chrome Security Update: Patch for Type Confusion Vulnerabilities

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Google has released a critical security update for its Chrome browser, addressing several vulnerabilities, including two high-severity type confusion flaws in the V8 JavaScript engine. The update, which brings Chrome to version 129.0.6668.100/.101 for Windows and Mac and 129.0.6668.100 for …

Microsoft Security Updates: 5 Zero-Days & 118 Vulnerabilities Patched

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

In its latest Patch Tuesday release, Microsoft addressed 118 vulnerabilities, including five zero-day flaws, two of which attackers are actively exploiting. The updates cover various Microsoft products, including Windows, Office, Azure, .NET, and Visual Studio. Zero-Day Vulnerabilities Among the five zero-day vulnerabilities patched, two were …

Patch Tuesday, October 2024 Edition

Blog WriterCybersecurity News - Original News Source is krebsonsecurity.com

Microsoft today released security updates to fix at least 117 security holes in Windows computers and other software, including two vulnerabilities that are already seeing active attacks. Also, Adobe plugged 52 security holes across a range of products, and Apple …

North Korean APT Hackers Exploiting DMARC Misconfigs For Phishing Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

DMARC is an email authentication protocol that helps domain owners protect against unauthorized use like “email spoofing” and “phishing attacks.” By leveraging existing protocols like “SPF” and “DKIM,” DMARC enables domain owners to publish policies in their “DNS records” that …

LemonDuck Malware Exploiting SMB Vulnerabilities To Attack Windows Servers

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

LemonDuck malware has evolved from a cryptocurrency mining botnet into a “versatile malware” that is capable of “stealing credentials,” “disabling security measures,” and “propagating through various methods.”  It targets both “Windows” and “Linux” systems by using techniques like ‘brute-force attacks’ …

Ukrainian Hackers Attack Russian Media Following Putin’s Birthday

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Ukrainian hackers launched a large-scale attack on Russian state media company VGTRK on October 7, coinciding with President Vladimir Putin’s 72nd birthday. The attack, described as “unprecedented” by Kremlin officials, disrupted the online broadcasting and streaming services of major television …

Hackers Exploiting DNS Tunneling Service To Bypass Network Firewalls

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

DNS tunneling is a hacking technique that hides information by taking advantage of the DNS protocol. This attack enables threat actors to evade firewalls and security measures.  Hackers retrieve information usually encoded in DNS queries and responses. This allows them …