New Windows-Based DarkCloud Stealer Attacking Computers to Steal Login Credentials and Financial Data

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated new variant of the DarkCloud information stealer has emerged in the cyberthreat landscape, targeting Windows users through carefully crafted phishing campaigns designed to harvest sensitive credentials and financial information. This fileless malware variant represents a significant evolution in …

Axis Camera Server Vulnerabilities Exposes Thousands of Organizations to Attack

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Critical security flaws in Axis Communications’ surveillance infrastructure have left over 6,500 organizations worldwide vulnerable to sophisticated cyberattacks, with potential impacts spanning government agencies, educational institutions, and Fortune 500 companies. The Swedish security camera manufacturer’s popular video surveillance products contain …

VexTrio TDS System Developing Several Malicious Apps Mimic as VPNs to Publish in Google Play and App Store

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The notorious VexTrio traffic distribution system (TDS) has expanded its cybercriminal operations beyond traditional web-based scams to include the development and distribution of malicious mobile applications designed to masquerade as legitimate VPN services. . This sophisticated threat actor, which has …

US Confirms Shutdown of BlackSuit Ransomware That Hacked Over 450 Organizations

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

U.S. authorities have announced the successful dismantling of the BlackSuit ransomware operation, a notorious group linked to attacks on more than 450 organizations worldwide. The operation, led by Immigration and Customs Enforcement’s (ICE) Homeland Security Investigations (HSI), involved seizing servers, …

PyPI Released Advisory to Prevent ZIP Parser Confusion Attacks on Python Package Installers

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

In recent months, security researchers have uncovered a novel attack vector targeting Python package installers through ambiguities in the ZIP archive format. By exploiting discrepancies between local file headers and the central directory, malicious actors can craft seemingly benign wheel …

Columbia University Data Breach – Hackers Stolen 870,000 Individuals Personal and Financial Data

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Columbia University has disclosed a major cybersecurity incident where an unauthorized third party accessed and extracted a significant volume of personal and financial data. The breach, which affects a vast number of individuals connected to the university, was discovered following …

RubyGems Malware Attack Weaponizes 60+ Packages to Steal Credentials from Social Media and Marketing Tools

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Threat actors began slipping malicious code into legitimate RubyGems packages, disguising infostealers as social media automation tools in early 2023. Over the past two years, attackers operating under aliases such as zon, nowon, kwonsoonje, and soonje have published more than …

Windows User Account Control Bypassed Using Character Editor to Escalate Privileges

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated new technique that exploits the Windows Private Character Editor to bypass User Account Control (UAC) and achieve privilege escalation without user intervention, raising significant concerns for system administrators worldwide. The attack disclosed by Matan Bahar leverages eudcedit.exeMicrosoft’s built-in …

Threat Actors Weaponize Malicious Gopackages to Deliver Obfuscated Remote Payloads

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cybersecurity researchers have uncovered a sophisticated malware campaign targeting the Go ecosystem through eleven malicious packages that employ advanced obfuscation techniques to deliver second-stage payloads. The campaign demonstrates a concerning evolution in supply chain attacks, leveraging the decentralized nature of …

ECScape: Exploiting ECS Protocol on EC2 to Exfiltrate Cross-Task IAM and Execution Role Credentials

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated technique dubbed “ECScape” that allows malicious containers running on Amazon Elastic Container Service (ECS) to steal AWS credentials from other containers sharing the same EC2 instance. The discovery highlights critical isolation weaknesses in multi-tenant ECS deployments and underscores …