Halliburton Hit by Cyberattack, Operations Disrupted

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Halliburton, a leading oilfield services company, is currently grappling with a significant cyberattack that has disrupted operations at its Houston campus and affected some of its global networks. A person familiar with the situation first reported the incident to Reuters, …

Chrome Zero-day Vulnerability (CVE-2024-7971) Actively Exploited in The Wild

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Google has recently addressed a high-severity zero-day vulnerability in its Chrome browser, identified as CVE-2024-7971. This vulnerability involves a type of confusion issue within the V8 JavaScript engine, which can be exploited to execute arbitrary code. The flaw was reported …

Tycoon 2FA Phishing Kit: What You Need to Know about the Highly Active Threat

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

If your company is using Microsoft products, you are at risk of falling victim to a Tycoon 2FA phishing attack. The adoption of this phishing kit in attacks is steadily increasing with new campaigns emerging almost every week. Let’s learn …

Xeon Sender Abusing Nine SaaS providers For Massive SMS Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Xeon Sender, a Python script, is a tool that enables threat actors to send spam messages through nine different SaaS providers. Initially observed in 2022, various threat actors have reused and rebranded this tool in the cloud hacktool scene.  By …

Chipmaker Microchip Hit by Cyber Attack, Operations Impacted

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Microchip Technology Incorporated, a leading semiconductor manufacturer, has been hit by a significant cyber attack that has disrupted its operations. The company, which supplies chips to the U.S. defense industry, detected suspicious activity on its information technology systems on August …

AWS Configuration Vulnerability Exposes Thousands of Web Apps to Attack

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A recent discovery by Miggo Research has unveiled a critical configuration vulnerability in Amazon Web Services (AWS) that exposes thousands of web applications to potential attacks. This vulnerability, dubbed “ALBeast,” affects applications using AWS’s Application Load Balancer (ALB) authentication feature, …

TA453 Hackers Using Fake podcast To Deliver New BlackSmith Malware Toolkit

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Iranian threat actor TA453 launched a phishing campaign targeting a prominent religious figure with a fake podcast invitation aiming to deliver a new malware toolkit, BlackSmith, containing a PowerShell trojan named AnvilEcho.  AnvilEcho, consolidating TA453’s previous malware functionalities into a …

Critical Slack Vulnerability Let Attackers Steal Data From Private Slack Channels

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A newly discovered vulnerability in Slack AI could allow attackers to exfiltrate sensitive data from private Slack channels. Cybersecurity researchers responsibly disclosed a vulnerability to Slack that involves manipulating the language model used for content generation. This vulnerability allows attackers …

Dell SupportAssist Vulnerability Exposes PCs to Privilege Escalation Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical security vulnerability has been identified in Dell’s SupportAssist for Home PCs, specifically affecting the installer executable version 4.0.3. This flaw, tracked as CVE-2024-38305, allows local low-privileged authenticated attackers to escalate their privileges, potentially leading to the execution of …

Critical Vulnerability In OpenBMCs For Servers, Leads To Full Compromise

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

BMCs are specialized microcontrollers embedded in servers and other devices, responsible for monitoring and managing hardware health, including temperature, voltage, and system logs. Cybersecurity researchers at Tetrel Sec recently discovered a critical vulnerability in the slpd-lite sub-component of the OpenBMC …