Threat Actors Abuse Genuine Code-Signing Certificates To Evade Detections

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A code signing certificate is a digital certificate that allows software developers to sign their applications. This ensures both the “authenticity of the publisher” and the “integrity of the code.”HarfangLab researchers recently discovered that threat actors have been actively abusing …

Hackers Abuse EDRSilencer Red Team Tool To Evade Detection

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

EDRSilencer is a tool designed to enhance data privacy and security by “silencing” or “blocking” unwanted data transmissions from endpoints. The tool is likely used in conjunction with EDR systems to improve overall cybersecurity measures and also provide an additional …

Threat Actors Hacking 3 To 5 Websites Per Hour Exploiting CosmicSting Vulnerability

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

In a disturbing development for e-commerce security, cybersecurity experts have revealed that threat actors are actively exploiting the CosmicSting vulnerability (CVE-2024-34102) to compromise 3 to 5 websites per hour. This critical security flaw, which affects Adobe Commerce and Magento platforms, …

Leeds Equity Partners Acquires Cybersecurity Training Firm OffSec

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Leeds Equity Partners (“Leeds Equity”) announced today that it has acquired OffSec (the “Company”), the leading provider of continuous cybersecurity workforce development training and professional education for cybersecurity practitioners from Spectrum Equity. Terms of the transaction were not disclosed. OffSec …

Hackers Using Bitbucket Code Hosting Platform To Host Malicious Payloads

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cybersecurity researchers have uncovered a sophisticated malware campaign exploiting Bitbucket, a popular code hosting platform, to deliver dangerous payloads to unsuspecting victims. The attackers are leveraging Bitbucket’s legitimate reputation to host and distribute various types of malware, including remote access …

SideWinder APT Hackers Added New Post-Exploitation Toolkit to Their Arsenal

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Security researchers at Kaspersky have uncovered a significant expansion in the capabilities of the SideWinder advanced persistent threat (APT) group. In a report published on October 15, 2024, the Kaspersky that SideWinder has developed a new post-exploitation toolkit called “StealerBot” …

ExoneraTor Tool Detects IP Address Linked With Tor Network, Uncovers Volt Typhoon

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Volt Typhoon is a Chinese state-sponsored hacking group that has been active since at least mid-2021, targeting critical infrastructure sectors in the United States and its territories. The group employs sophisticated techniques to infiltrate networks by using “compromised routers” and …

What is Business Continuity Plan? How it Works!

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Businesses face an array of potential disruptions that can threaten their operations. From natural disasters to cyberattacks, maintaining business functions during unforeseen events is crucial. This is where a Business Continuity Plan (BCP) comes into play. A BCP is a …

ErrorFather Hackers Attacking Android Users To Take Control Of The Device

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cerberus is an advanced Android banking trojan that emerged in 2019, primarily designed to steal sensitive “financial information.” While this sophisticated trojan is commonly distributed via “malicious apps” and “phishing campaigns.” Cybersecurity analysts at Cyble recently discovered the “ErrorFather” campaign …

Threat Actors Claim to Sell Data Allegedly Stolen from Cisco

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A group of threat actors, led by the notorious hacker known as IntelBroker, has claimed responsibility for a significant data breach at Cisco Systems, Inc. The hackers allege they have stolen a vast amount of sensitive information and are now …