American Water Works IT Systems Hit by Cyber Attack

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

American Water Works Company, Inc., the largest regulated water and wastewater utility in the United States, reported a cybersecurity incident on October 3, 2024, affecting its computer networks and systems. The company, which provides services to over 14 million people …

MoneyGram Cyber Attack: Hackers Stole Customers’ Personal and Transaction Data

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

MoneyGram Payment Systems, Inc. confirmed that hackers accessed and stole sensitive customer data, including personal information and transaction details. The breach occurred between September 20 and 22, 2024, and was discovered on September 27, 2024. The stolen data includes a …

Comcast Data Breach: 237,000+ Customers’ Personal Data Exposed

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A data breach has impacted more than 237,000 Comcast customers, exposing their personal information such as names, addresses, Social Security numbers, dates of birth, and Comcast account numbers. The breach occurred at Financial Business and Consumer Solutions (FBCS), a third-party …

Critical Oath-Toolkit Vulnerability Let Attackers Escalate Privilege

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

OATH Toolkit is a software suite that is primarily designed to implement OTP authentication systems. It includes libraries and command-line tools for generating both event-based (HOTP) and time-based (TOTP) OTPs. Not only that even it also offers a “PAM module” …

North Korean Hackers Employ PowerShell-Based Malware With Serious Evasion Techniques

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

PowerShell-based malware is a form of fileless malware that exploits PowerShell to execute malicious scripts directly in memory which helps in evading AV solution detection methods. Attackers favor this approach due to PowerShell’s deep integration with Windows, which allows them …

Hackers Exploit Visual Studio RCE Vulnerability Via Dump Files

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Visual Studio is a powerful IDE from Microsoft that is primarily used for developing applications in various programming languages like “C#,” “C++,” and “Visual Basic.”  It offers a rich set of features like “debugging tools,” “a code editor with IntelliSense,” …

Google to Block Malicious Sideloaded Apps Exclusively for Indian Users

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Google has announced the launch of an enhanced fraud protection pilot for Android users in the country. This initiative aims to block malicious sideloaded apps that exploit sensitive permissions to commit financial fraud. According to the Indian Cyber Crime Coordination …

What is Banner Grabbing? Types, Features & How it Works!

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Both hackers and security professionals employ various techniques to gather information about computer systems and networks. One such technique is “banner grabbing,” which is used to discover details about a system’s software and services running on open ports. This article …

50+ Vulnerabilities Uncovered in RPKI security Framework for Internet Routing

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

RPKI is a security framework designed to enhance the integrity of Internet routing by associating specific IP address blocks and ASNs with their legitimate holders.  It employs cryptographic certificates that are known as ROAs to validate BGP route announcements which …

Crypto Hacker Pleads Guilty for Stealing Over $37 Million in Cryptocurrency

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Evan Frederick Light, a 21-year-old from Lebanon, Indiana, has pleaded guilty to conspiracy charges to Commit Wire Fraud and to Launder Monetary Instruments. The announcement was made by United States Attorney Alison J. Ramsdell following Light’s appearance before U.S. Magistrate …