Corona Mirai Botnet Exploiting RCE Zero-Day To Hire New Bots

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A botnet is exploiting a new zero-day vulnerability, CVE-2024-7029, in AVTECH CCTV cameras to spread a Mirai variant, which is a command injection vulnerability in the brightness function that allows for remote code execution.  It leverages this vulnerability to gain …

Hackers Could Exploit Dell BIOS Flaw Let Hackers Execute Arbitrary Code

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical vulnerability in the Dell Client Platform BIOS has been identified, potentially allowing hackers to hijack compromised systems. This flaw, identified as CVE-2024-39584, is classified as a “Use of Default Cryptographic Key” vulnerability. It poses a significant risk, with …

Check Point to Acquire Cyberint Technologies to Enhance Threat Intelligence

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Check Point® Software Technologies Ltd. (NASDAQ: CHKP), a prominent player in the cybersecurity industry, has announced a definitive agreement to acquire Cyberint Technologies Ltd. This strategic acquisition aims to enhance Check Point’s Security Operations Center (SOC) capabilities and expand its …

Wireshark 4.4.0 Released – What’s New!

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The Wireshark Foundation has announced the release of Wireshark 4.4.0, bringing a host of new features, improvements, and bug fixes to the popular open-source network protocol analyzer. This latest version introduces significant enhancements to graphing capabilities, display filter functionality, and …

When Get-Out-The-Vote Efforts Look Like Phishing

Blog WriterCybersecurity News - Original News Source is krebsonsecurity.com

August 28, 2024 0 Comments Multiple media reports this week warned Americans to be on guard against a new phishing scam that arrives in a text message informing recipients they are not yet registered to vote. A bit of digging …

BlackByte Hackers Exploiting VMware ESXi Auth Bypass Flaw to Deploy Ransomware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Security researchers have discovered that the BlackByte ransomware group is actively exploiting a recently patched authentication bypass vulnerability in VMware ESXi hypervisors to deploy ransomware and gain full administrative access to victim networks. The vulnerability, tracked as CVE-2024-37085, allows attackers …

Multiple Vulnerabilities in AI Platforms Exposes Sensitive Data to Anyone

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Artificial intelligence (AI) platforms have become integral tools for businesses and organizations worldwide. These technologies promise efficiency and innovation, from chatbots powered by large language models (LLMs) to intricate machine learning operations (MLOps). However, recent investigations have uncovered alarming vulnerabilities …

APT Hackers Exploiting Zero-Day Vulnerabilities in WPS Office

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

ESET researchers have uncovered two critical zero-day vulnerabilities in WPS Office for Windows, exploited by the advanced persistent threat (APT) group APT-C-60. This South Korea-aligned cyberespionage group has been targeting users in East Asian countries, leveraging these vulnerabilities to execute …

Rewards Up To $2.5 Million for Angler Exploit Kit Developer

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The U.S. Department of State has announced a reward of up to $2.5 million for information leading to Volodymyr Kadariya’s arrest and/or conviction. Kadariya is allegedly a key figure in a major malware organization responsible for developing and distributing the …

Researchers Exploited Remote Code Execution Moodle Platform

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The popular learning platform Moodle was found to have a critical vulnerability that allowed for remote code execution, which was caused by an improper sanitization of user input that could be exploited to inject malicious code into the system.  The …