Ivanti Warns of CSA Vulnerability Actively Exploited in Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Ivanti has warned about a critical vulnerability in its Cloud Services Appliance (CSA) 4.6, which has been actively exploited in attacks. The vulnerability, identified as CVE-2024-8963, is a path traversal flaw that allows remote unauthenticated attackers to access restricted functionality. …

This Windows PowerShell Phish Has Scary Potential

Blog WriterCybersecurity News - Original News Source is krebsonsecurity.com

September 19, 2024 0 Comments Many GitHub users this week received a novel phishing email warning of critical security holes in their code. Those who clicked the link for details were asked to distinguish themselves from bots by pressing a …

Why Cynet’s All-in-One Platform Is a Game-Changer for MSPs

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Managed Services Providers (MSPs) are increasingly looking to provide cybersecurity services based on heightened demand from their current clients. Though the revenue potential is lucrative, the road for many MSPs to transition into a Managed Security Services Provider (MSSP) is …

Threat Actors Weaponized Splinter Post-Exploitation Red Team Tool Discovered

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Unit 42 cybersecurity researchers have identified a new post-exploitation red team tool, Splinter, using Advanced WildFire’s memory scanning tools. This tool, developed in Rust, a programming language known for its memory safety features, has been found on several customer systems, …

Attention Travelers! Beware of Booking.com Themed Phishing Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Phishing attacks are a type of social engineering scam where attackers trick victims into revealing sensitive information.  In phishing attacks, the attackers often impersonate trusted entities like banks or companies in emails, texts, or calls to trick victims into clicking …

Fox Kitten’s Hidden Infrastructure & New IOCs Uncovered

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Fox Kitten (aka Pioneer Kitten or Parisite) is an Iranian cyber threat group that has been active since at least 2017. This group primarily targets both U.S. and international organizations. Matt Lembright, the Global Lead of Censys Data/Search, recently uncovered …

Hackers Using Supershell Malware To Attack Linux SSH Servers

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Supershell is a command-and-control (C2) remote control platform that operates through web services. It allows users to establish a reverse SSH tunnel, enabling a fully interactive shell session. Recently, ASEC researchers discovered that hackers have been actively using Supershell malware …

Open Source C2 Frameworks Used In Red Teaming Vulnerable To RCE Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A C2 framework is an architecture that controls and maintains access to compromised systems. Its purpose is to allow you to run commands on other people’s computers, but many C2 frameworks are vulnerable to illegal command execution. Some cases may …

New Raptor Train Botnet Hacked 200,000+ Devices WorldWide

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A botnet is a network of compromised devices, such as computers and IoT devices, infected with malware and controlled by a central entity known as a “bot herder.”  These infected devices are often referred to as “bots,” and they can …

Microsoft Warns Of Vanilla Tempest Hackers Attacking Healthcare Sectors

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Vanilla Tempest is a ransomware group that has recently targeted U.S. healthcare organizations using a new ransomware strain. This group has been active since at least June 2021 and has been linked to various cyberattacks across multiple sectors like education …