Hackers Exploiting Veeam RCE Flaw to Deploy New Frag Ransomware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Threat actors are actively exploiting a critical vulnerability in Veeam Backup & Replication software to deploy a new ransomware strain called “Frag.” The vulnerability, tracked as CVE-2024-40711, allows unauthenticated remote code execution and has a severity score of 9.8 out …

Hackers Attacking macOS Users with New Multi-Stage Malware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

North Korean threat actors, likely associated with BlueNoroff, have launched multi-stage malware attacks targeting cryptocurrency businesses, expanding their toolkit to include RustDoor/ThiefBucket and RustBucket campaigns.  Hidden Risk, a DPRK-linked threat actor, employed a novel persistence technique involving Zsh configuration file …

Beware of Fake Copyright Claims that Deliver Rhadamanthys Stealer Malware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cybercriminals have launched a large-scale phishing attack using a new variant of Rhadamanthys Stealer, dubbed CopyRh(ight)adamantys, which targets individuals and organizations worldwide, falsely accusing them of copyright infringement.  Attackers impersonate legitimate companies via Gmail accounts, sending emails that trick victims …

North Korean Hackers Abuse Cloud-Based Services to Deploy Malware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

ESET’s recent report details the activities of various advanced persistent threat (APT) groups from April to September 2024, highlighting key trends and developments observed during this period, including the use of sophisticated techniques such as targeted phishing attacks, malware distribution, …

Beware of Fake Copyright Claims That Deliver Rhadamanthys Stealer

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Stealer malware is a type of malicious software designed to infiltrate computers and extract sensitive information. Once installed, it communicates with a command-and-control server operated by threat actors and enables data theft like saved passwords and browser cookies. Security experts …

Threat Actors Attacking macOS Users With New Multi-stage Malware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Multi-stage malware means sophisticated cyberattack strategies that evolve in several steps. Recent developments in multi-stage malware highlight the increasing sophistication of cyber threats. SentinelOne researchers recently discovered that threat actors have been attacking macOS users with new multi-stage malware. macOS …

Hackers Can Hijack Your MFA Enabled Email Accounts By Stealing Cookies

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

MFA enhances the security of email accounts by requiring users to provide additional verification beyond just their password. Implementing MFA reduces the risk of unauthorized access which makes it a critical security measure for protecting sensitive information in email accounts. …

CISA Warns of Palo Alto & Android Vulnerabilities Exploited in Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The Cybersecurity and Infrastructure Security Agency (CISA) has issued urgent warnings regarding two critical vulnerabilities currently being exploited in the wild. These security flaws affect Palo Alto Networks’ Expedition tool and Google’s Android operating system, potentially exposing countless devices and …

Hackers Use ZIP File Concatenation Tactic to Launch Undetected Attacks on Windows Users

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cybercriminals are utilizing a sophisticated evasion strategy called ZIP file concatenation to specifically target Windows users. This method combines several ZIP files into a single archive, making it harder for security software to detect malicious content. As a result, unsuspecting …

Cisco Industrial Wireless Software Flaw Let Attackers Run Command As Root User

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Hackers target Cisco primarily due to its critical role in global network infrastructure and security. Cisco’s devices are essential for protecting sensitive data and communications which makes them attractive targets for espionage. Cybersecurity researchers at Cisco recently discovered a Cisco …