Secret Blizzard Hackers Attack Windows Infrastructure Using Multiple Hacking Tools

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

In a recent joint report by Microsoft Threat Intelligence and Black Lotus Labs, new insights have emerged about “Secret Blizzard,” a sophisticated Russian nation-state cyber actor attacking windows infrastructure using a variety of hacking tools. Known for its stealthy espionage …

Chinese Salt Typhoon Hacked 8+ Telecoms To Stole U.S. Citizens Data

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A Chinese hacking campaign, codenamed “Salt Typhoon” by Microsoft, has infiltrated more than 8 American telecommunications companies, stealing vast amounts of U.S. citizens’ phone data. Officials describe it as one of the largest intelligence compromises in U.S. history. The operation, …

Isreali NSO Group’s Pegasus Spyware Detected in New Mobile Devices

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cybersecurity researchers from iVerify have revealed widespread new infections of the Pegasus spyware, developed by NSO Group (dubbed “Rainbow Ronin”), showing that spyware targets not only activists and journalists but also professionals and civilians. The company’s newly launched Mobile Threat …

Deloitte Hacked – Brain Cipher Ransomware Group Allegedly Stolen 1 TB of Data

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Notorious ransomware group Brain Cipher has claimed to have breacked Deloitte UK, allegedly exfiltrating over 1 terabyte of sensitive data from the professional services giant. Brain Cipher is a ransomware group that emerged in June 2024, quickly gaining notoriety for …

Operation Destabilise, Authorities Dismateled Cybercriminals Money Laundering Network

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

In a major international operation codenamed “Operation Destabilise,” law enforcement agencies have successfully dismantled sophisticated Russian money laundering networks that served cybercriminals, drug traffickers, and sanctioned Russian elites worldwide. The operation, led by the National Crime Agency (NCA), exposed two …

Hackers Exploit Docker Remote API Servers To Inject Gafgyt Malware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The Gafgyt malware (often referred to as Bashlite or Lizkebab) has expanded its attack scope by targeting publicly exposed Docker Remote API servers. Gafgyt malware, also known as Bashlite, and Mirai have targeted millions of vulnerable IoT devices in recent …

SolarWinds Platform XSS Vulnerability Let Attackers Inject Malicious Code

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical security vulnerability has been recently disclosed by SolarWinds in its Platform product, a major player in IT management software. The flaw, identified as CVE-2024-45717, allows authenticated attackers to inject malicious code through a cross-site scripting (XSS) vulnerability. This …

HR & IT-Related Phishing Emails Are Top-Clicked Among Phishing Email Types

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Phishing emails masquerading as HR and IT-related communications are the most likely to be clicked on by employees as unveiled in a recent study, posing a significant cybersecurity risk to organizations across various industries. The 2024 Phishing by Industry Benchmarking …

HackSynth An Autonomous Penetration Testing Framework For Simulating Cyber-Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The introduction of HackSynth marks a significant advancement in the field of autonomous penetration testing. Developed by researchers at Eotvos Lorand University, HackSynth leverages Large Language Models (LLMs) to autonomously conduct penetration tests, simulating cyber-attacks to identify vulnerabilities in systems …

Cloudflare Developer Domains Abused For Cyber Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cloudflare developer domains are actively abused by the threat actors for several illicit malicious purposes, as reported by the security analysts at FORTRA. Recent investigations have uncovered a significant surge in attacks targeting Cloudflare Pages and Cloudflare Workers, two popular …