Kemp Load Balancer Command Injection Vulnerability Allow Full Compromise

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical vulnerability has been discovered in Kemp’s LoadMaster Load Balancer, allowing for full system compromise through a command injection attack. This security flaw, identified as CVE-2024-7591, affects all LoadMaster versions up to and including 7.2.60.0, as well as multi-tenant …

New Windows 11 Integer Overflow Vulnerability Lets Attackers Elevate Privileges

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical security flaw in Windows 11 has been discovered, allowing attackers to gain elevated system privileges through an integer overflow vulnerability. The exploit, which affects the ksthunk.sys driver was successfully demonstrated at the recent TyphoonPWN 2024 event, where it …

T-Mobile Spotted Chinese Salt Typhoon Hackers Attacking Its Routers

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

T-Mobile revealed how it successfully blocked attempts by the Chinese hacking group Salt Typhoon to infiltrate its network. This announcement follows reports from earlier this month about Salt Typhoon’s successful breaches of wiretap systems managed by major U.S. telecom companies, …

New Stealthy GodLoader Malware Attacking Windows, macOS, Linux, Android, & iOS Devices

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A newly discovered malware, dubbed GodLoader, is raising alarms in the cybersecurity community for its ability to stealthily infect devices across multiple operating systems, including Windows, macOS, Linux, Android, and iOS. Unveiled by Check Point Research, this advanced malware exploits …

Black Basta Ransomware Attacking Microsoft Teams With Advanced Social Engineering Tactics

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The notorious Black Basta ransomware group has escalated its attack strategy, now leveraging Microsoft Teams as a potent tool for social engineering. This alarming development, observed throughout October 2024, has targeted hundreds of organizations across various sectors, including finance, technology, …

Automate Analysis of Common Attack Vectors with a Malware Sandbox

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Analysts often face an overwhelming number of threats daily, each demanding a detailed examination to understand its behavior and potential impact. When alerts start piling up, manually analyzing each one becomes time-consuming and puts your team under pressure. Fortunately, these …

New Elpaco Ransomware Actors Connect Via RDP To Deploy Ransomware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Elpaco ransomware, a Mimic variation, has been identified where attackers were able to connect via RDP to the victim’s server following a successful brute force attack and subsequently execute the ransomware. The variant abuses the Everything DLL, which is used …

NachoVPN Attack Exploits RCE Flaws in SonicWall & Palo Alto VPNs

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

In a study examining popular corporate VPN clients, including traditional SSL-VPN clients and modern Zero Trust solutions, researchers uncovered vulnerabilities in the trust relationships between these VPN clients and their servers. These flaws demonstrated how attackers could exploit the tools …

Teaching AI to Hack: Researchers Demonstrate ChatGPT’s to Ethically Hack Linux & Windows

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

In a new study released today, researchers have demonstrated the significant potential of artificial intelligence (AI) in enhancing ethical hacking practices, particularly in Linux environments. The study, conducted by Haitham S. Al-Sinani from the Diwan of Royal Court in Oman …

Chinese APT Hackers Using Multiple Tools And Vulnerabilities To Attack Telecom Orgs

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Since 2023, the Chinese APT group Earth Estries (aka Salt Typhoon, FamousSparrow, GhostEmperor, and UNC2286) has mostly targeted government agencies and vital industries, including telecoms in the US, Asia-Pacific, Middle East, and South Africa. The group uses sophisticated attack methods …