MOVEit 0-day Breach – Millions of Employee Data Stolen from 25 Major Organizations

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical vulnerability in the widely used MOVEit file transfer software has led to one of the most extensive corporate data leaks in recent history, affecting millions of employees across 25 major organizations. The breach, attributed to a zero-day vulnerability …

6 Effective Steps to Accelerate Cybersecurity Incident Response

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Modern security tools continue to evolve, improving their ability to protect organizations from cyber threats. Despite these advances, bad actors still occasionally find ways to infiltrate networks and endpoints. Therefore, it is critical for security teams to not only have …

Hackers Attacking Windows Users With Weaponized Excel Documents To Deliver Remcos RAT

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Hackers weaponize Excel documents primarily due to their widespread use and the inherent vulnerabilities within the software. With Microsoft blocking VBA macros by default, hackers have shifted to exploiting “.XLL” files as a means to deliver malware. Fortinet researchers recently …

Roblox Developers Under Attack Via Weaponized npm Packages

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Researchers discovered five malicious npm packages that target Roblox developers, spreading malware to steal credentials and personal information. These packages, which include autoadv, ro.dll, node-dlls, and two rolimons-api versions, were designed to imitate legitimate modules that are often utilized by …

Gootloader Malware Targets Bengal Cat Lovers By Poisoning Google Search Results

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

SEO poisoning is a malicious tactic where threat actors manipulate search engine results to promote harmful websites by exploiting trending keywords. This approach not only risks personal information but can also damage the reputations of legitimate businesses. Cybersecurity researchers at …

DeltaPrime Exploited, Hackers Stolen $4.8M Worth of ARB and AVAX Tokens

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Decentralized finance (DeFi) protocol DeltaPrime has fallen victim to yet another major exploit. Hackers siphoned off approximately $4.8 million worth of ARB and AVAX tokens. The attack targeted DeltaPrime’s Avalanche and Arbitrum networks. This marks the protocol’s second significant breach this year. DeltaPrime Exploited Blockchain security …

Epson Devices Vulnerability Let Attackers Create Rogue Admin Accounts

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A newly disclosed security vulnerability, CVE-2024-47295, has been found in several Epson devices, including printers, scanners, and network interface products. The flaw allows attackers to exploit a critical configuration oversight that could result in unauthorized control of affected devices. Vulnerability …

Hackers Abusing Google Ads To Deliver Fakebat Malware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cybersecurity researchers have uncovered a resurgence of the Fakebat malware loader being distributed through malicious Google Ads. After a months-long break, Fakebat has resurfaced, focusing on users who are looking for popular productivity software. Malwarebytes detected a malicious Google ad …

Palo Alto Networks Warns Of Critical PAN-OS Remote Code Execution Vulnerability

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Palo Alto Networks has issued an urgent warning about a potential critical remote code execution (RCE) vulnerability affecting the management interface of their PAN-OS next-generation firewalls. The cybersecurity company has advised customers to take immediate protective measures while investigating the …

Microsoft Bookings Flaw Let Hackers Create Impersonate User Acccounts

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical security flaw in Microsoft Bookings has been uncovered. This flaw, inherent in the default configuration of Microsoft Bookings, potentially allows attackers to create unauthorized Entra (formerly Azure AD) accounts and obtain fraudulent certificates. This vulnerability poses significant risks …