Sophisticated Celestial Stealer Attacking Browsers to Steal Login Credentials

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Celestial Stealer, a JavaScript-based infostealer packaged either as an Electron application, has been spotted targeting both Chromium and Gecko-based browsers to steal browser data. The stealer is specifically targeting the system’s browsers attempting to steal the browser’s history, saved passwords, …

New DroidBot Malware Attacking 77 Banks And Cryptocurrency Exchange Services

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

DroidBot is an advanced Android Remote Access Trojan (RAT) that targets 77 different organizations, including national organizations, cryptocurrency exchanges, and banks.  Active campaigns have been detected in countries including the United Kingdom, Italy, France, Spain, and Portugal, indicating a potential …

HCL DevOps Deploy & Launch Vulnerable To HTML Injection Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A recently disclosed vulnerability in HCL Software’s DevOps Deploy and Launch platforms has raised security concerns. Identified as CVE-2024-42195, this vulnerability allows attackers to embed arbitrary HTML tags within the web user interface (UI), potentially leading to sensitive information disclosure. …

Fuji Electric Indonesia Hit By Ransomware Attack, Business Information Compromised

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

In a concerning development, Fuji Electric Indonesia (FEID) has fallen victim to a ransomware attack, potentially exposing sensitive business partner information. The incident, which occurred on Wednesday, November 27th, has left several of FEID’s PCs and servers inoperable, raising alarms …

Mitel MiCollab Zero-Day Vulnerability Let Attackers Bypass Authentication

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Security researchers have uncovered a critical zero-day vulnerability in Mitel MiCollab, a popular unified communications solution. The flaw, which remains unpatched, allows attackers to perform arbitrary file reads on the server’s filesystem, potentially compromising sensitive information and system security. The …

MOONSHINE Kit Exploiting Android Messaging Apps Flaw To Inject Backdoor

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated exploit kit named MOONSHINE has been actively targeting Android messaging apps to implant backdoors on users’ devices. This toolkit, under continuous monitoring since 2019, has recently been found to have an upgraded version with enhanced capabilities and protections …

What is Host-based Intrusion Detection System?

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Organizations face a myriad of challenges in protecting their digital assets. One critical component of a robust security strategy is the implementation of Intrusion Detection Systems (IDS). Among these, Host-Based Intrusion Detection Systems (HIDS) play a crucial role in monitoring, …

CISA Warns Of CyberPanel, North Grid, ProjectSend & Zyxel Firewalls Flaws Exploited In Wild

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued an alert regarding four critical vulnerabilities actively exploited in the wild, urging organizations to take immediate action to mitigate risks. These flaws, affecting CyberPanel, North Grid Proself, ProjectSend, and Zyxel …

Thinkware Cloud APK Vulnerability Let Attackers Execute Arbitrary Code

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical security flaw has been uncovered recently in the Thinkware Cloud APK version 4.3.46, Thinkware’s cloud-based dashcam services. The vulnerability, identified as CVE-2024-53614, allows malicious actors to access sensitive data and execute arbitrary commands with elevated privileges, potentially compromising …

Beware Of New HR Payroll Phishing Attack Targeting Numerous Employees

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated phishing campaign dubbed “Payroll Pirates” is currently targeting employees of various high-profile organizations. While the targets include California Employment Development Department (EDD), Kaiser Permanente, Macy’s, New York Life, and Roche. This ongoing malicious operation aims to carry out …