Beware of Malicious Slack Ads that Deliver Malicious Payloads

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cybercriminals have been exploiting Google search ads to deliver malicious payloads through seemingly legitimate ads for the popular communication tool Slack. This stealthy and sophisticated attack highlights the evolving tactics of threat actors who are increasingly adept at bypassing security …

Russian Karakurt Ransomware Group Member Charged For Laundered Ransom Payment

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A member of a notorious Russian cybercrime group has been charged federally and appeared in U.S. District Court in Cincinnati today. A federal grand jury has indicted Deniss Zolotarjovs, 33, of Moscow, Russia, on charges of conspiring to commit money …

Cthulhu Stealer macOS Malware can be Renting for $500/Month to Steal Data

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

In recent years, the belief that macOS systems are immune to malware has been increasingly challenged. With the emergence of threats like Silver Sparrow, KeRanger, and Atomic Stealer, macOS users are becoming more aware of the vulnerabilities in their systems. …

Hackers Exploiting Amazon Services To Deliver Weaponized MSC Files

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Hackers often target and exploit Amazon services due to their vast offerings, including massive computer power, storage, and global reach. These elements of Amazon’s services are lucrative to hackers, making them ideal for launching attacks, hosting malicious content, and hiding …

Dell Power Manager Vulnerability Allow Attackers Gain Unauthorized Access – Patch Now!

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Dell Technologies has identified a security vulnerability in Dell Power Manager (DPM), affecting versions 3.15.0 and prior. This vulnerability, identified as CVE-2024-39576, involves an Incorrect Privilege Assignment that could allow a low-privileged attacker with local access to execute code and …

Microsoft Edge RCE Vulnerability Let Attackers Take Control of the System Remotely

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical remote code execution (RCE) vulnerability in Microsoft Edge has been discovered. It could allow attackers to take control of affected systems by executing arbitrary code remotely. Microsoft has assigned the flaw, CVE-2024-38210, an “Important” severity rating. The vulnerability …

Chinese Hackers Exploiting Zero-Day Flaw in Cisco Switches to Deploy Malware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated China-linked cyber espionage group, known as Velvet Ant, has been discovered exploiting a zero-day vulnerability in Cisco NX-OS Software to deploy custom malware on network switches. The vulnerability, tracked as CVE-2024-20399, was identified by cybersecurity firm Sygnia during …

McDonald’s Official Instagram Account Hacked to Promote Cryptocurrency Scam

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

On August 21, 2024, McDonald’s official Instagram account was hacked, resulting in a cryptocurrency scam that made the hackers around $700,000. The hackers exploited the fast-food giant’s massive social media following to promote a fraudulent cryptocurrency called “GRIMACE,” named after …

New Ngate Android Malware Lets Hackers Withdraw Money From Payment Cards

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Hackers execute several illicit activities with the help of Android malware, and they target Android due to its widespread use and its open ecosystem.  This makes it much easier for the hackers to perform their illicit activities like distributing malicious …

New Malware Hidden Within PostgreSQL Process Deploys Cryptocurrency Miners

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A successful brute-force attack on a PostgreSQL database exploited a feature that allowed command execution, where the attacker created a superuser role, dropped files to eliminate competition and gain persistence, and ultimately deployed cryptocurrency miners.  The attack demonstrates the severe …