New TLDs Like .shop, .top And .xyz Attracting Phishers

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A significant surge in phishing attacks has been unveiled by a recent study conducted by Interisle Consulting, with a nearly 40% increase in the year ending August 2024. The research highlights that much of this growth is concentrated in a …

Google Chrome Type Confusion Vulnerability Let Attackers Execute Remote Code

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A high-severity type confusion vulnerability in the V8 JavaScript engine of Google Chrome was recently discovered by independent researchers. As a result of this discovery, Google Chrome users are urged to update their browsers immediately. The flaw, identified as CVE-2024-12053, …

PoC Exploit Released For Progress WhatsUp Gold Vulnerability

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical security flaw in Progress WhatsUp Gold, a popular network monitoring tool, has been exposed with the release of a proof-of-concept (PoC) exploit. The vulnerability, identified as CVE-2024-8785, affects versions of WhatsUp Gold prior to 24.0.1 and poses a …

MobSF Vulnerability Let Attackers Inject Malicious Scripts

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical security flaw has been discovered in Mobile Security Framework (MobSF), a popular pen-testing and malware analysis tool, potentially exposing users to significant risks. The vulnerability, identified as CVE-2024-53999, allows attackers to execute malicious scripts through a Stored Cross-Site …

CISA Releases Guidance For Network Monitoring to Detect Malicious Cyber Actors

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The Cybersecurity and Infrastructure Security Agency (CISA), in collaboration with the National Security Agency (NSA), Federal Bureau of Investigation (FBI), and international partners, has released crucial guidance for monitoring networks and hardening devices. This initiative comes in response to a …

Authorities Dismantle MATRIX Secret Chat Service Used by Cybercriminals

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A joint investigation team (JIT) involving French and Dutch authorities, with support from Eurojust and Europol, has successfully dismantled an encrypted messaging service known as MATRIX. This operation, which took place on December 3, 2024, marks a pivotal moment in …

Veeam Service Provider RCE Vulnerability Let Attackers Execute Remote Code

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Veeam, a leading provider of backup and disaster recovery solutions, has disclosed two significant vulnerabilities affecting its Service Provider Console (VSPC), including a critical remote code execution (RCE) flaw. The vulnerabilities discovered during internal testing impact VSPC version 8.1.0.21377 and …

Storm-1811 Hackers Exploits RMM Tools to Deliver Black Basta Ransomware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Storm-1811, a financially driven threat actor that employs social engineering techniques, has recently been observed exploiting RMM tools to distribute the Black Basta ransomware. The threat actor exploits the client management tool, Microsoft Quick Assist, with the intention of delivering …

SmokeLoader Malware Attacking Windows Users Exploiting XLS And DOC Vulnerabilities

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The notorious SmokeLoader malware has been identified targeting firms in Taiwan, including those in manufacturing, healthcare, information technology, and other industries.  SmokeLoader is renowned for its adaptability and sophisticated evasion strategies, and it can carry out a variety of attacks …

Cisco Confirms Active Exploitation Of Cisco XSS VPN Vulnerability

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cisco has confirmed that a decade-old cross-site scripting (XSS) vulnerability in its Adaptive Security Appliance (ASA) Software is currently being actively exploited in the wild. The vulnerability, identified as CVE-2014-2120, affects the WebVPN login page and could allow unauthenticated, remote …