Why Cybersecurity Leaders Trust the MITRE ATT&CK Evaluations

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

In today’s rapidly evolving threat landscape, security leaders must make informed decisions to protect their organizations effectively. The “MITRE Engenuity ATT&CK Evaluations: Enterprise” serve as an essential resource for cybersecurity decision-makers. These evaluations simulate real-world threats to assess how different …

XT Exchange Hacked, $1.7 Million Stolen in Cryptocurrency, Withdrawal Halted

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A major cryptocurrency exchange, XT.com, suspended all withdrawals on November 28, 2024, following a suspected hack that resulted in the theft of approximately $1.7 million worth of digital assets. The Dubai-based exchange, which boasts a daily trading volume of $3.4 …

North Korean Hackers Attacking Developers With A Weaponized JavaScript Projects

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

North Korean threat actors target software developers with weaponized Javascript projects that include BeaverTail malware deployed via NPM packages. It is intended to steal information and load additional stages of malware, notably a multi-stage Python-based backdoor called InvisibleFerret. The InvisibleFerret …

New Skimmer Malware Steals Credit Card Data From Checkout Pages

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A new skimmer malware is targeting Magento-powered eCommerce websites, stealing sensitive credit card information from checkout pages.  This malware dynamically creates a false credit card form or directly extracts payment fields, activating only on checkout pages.  Subsequently, the stolen information …

What is End-to-End Encryption (E2EE)?

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

With the rise of cyber threats, surveillance, and unauthorized access, protecting sensitive information has become a critical challenge for individuals, businesses, and governments alike. One technology at the forefront of safeguarding data is End-to-End Encryption (E2EE). This article takes an in-depth …

HPE Insight Remote Support Vulnerabilities Let Attackers Execute Remote Code

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Hewlett Packard Enterprise (HPE) has disclosed multiple high-severity vulnerabilities in its Insight Remote Support (IRS) software, potentially allowing attackers to execute remote code, perform directory traversal, and access sensitive information. The security bulletin, released on November 22, 2024, urges users …

Zabbix SQL Injection Vulnerability Let Attackers Gain Complete Control Of Instances

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical security flaw has been discovered in Zabbix, the popular open-source monitoring solution, potentially allowing attackers to gain full control over affected instances. The vulnerability, identified as CVE-2024-42327, affects multiple versions of Zabbix and has been assigned a CVSS …

Beware Of PixPirate Malware Attacking Users Via WhatsApp

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A new and dangerous malware campaign known as PixPirate has been targeting users in recent months, primarily in Brazil and India, with infections also spreading to Italy and Mexico. This sophisticated malware poses as a legitimate authentication application, tricking users …

China Conceling State, Corporate & Academic Assets For Offensive Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

China’s cyber threat landscape has evolved into a complex ecosystem involving state actors, private companies, and academic institutions. This intricate network supports and enhances China’s offensive cyber capabilities, blurring the lines between government, industry, and academia. China’s cybersecurity industry, valued …

Microsoft Re-Releases Exchange Server Security Update Fixing Transport Rules

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Microsoft has re-released the November 2024 Security Updates (SUs) for Exchange Server, addressing a critical issue that caused transport rules to stop functioning after a certain period in some environments. This update comes as a response to widespread reports from …