Beware of Fake AppleCare+ Service that Steals Money from Users

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A malicious campaign targeting Mac users seeking support or extended warranty services through AppleCare+ has been uncovered. This scam involves perpetrators purchasing Google ads to lure victims into visiting fraudulent websites hosted on GitHub, a platform owned by Microsoft. The …

Medusa Ransomware Exploiting Fortinet Flaw For Sophisticated Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The notorious Medusa ransomware group has been exploiting a critical vulnerability in Fortinet’s FortiClient EMS software to launch sophisticated ransomware attacks. The SQL injection flaw, tracked as CVE-2023-48788, allows attackers to execute malicious code on vulnerable systems and gain a …

Azure API Management Vulnerability Let Users Escalate Privileges

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical vulnerability was recently discovered in Azure API Management (APIM) that allowed users with Reader-level access to escalate their privileges to the equivalent of Contributor-level access. This security flaw enabled users to read, modify, and even delete configurations of …

New Linux Malware Exploiting Oracle Weblogic Servers

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Oracle WebLogic Server is an application server that is primarily designed to develop, deploy, and manage enterprise applications based on Java EE and Jakarta EE standards. It serves as a critical component of Oracle’s Fusion Middleware, which provides a reliable …

Kawasaki Europe Confirms Cyber Attack, RansomHub Claims Responsibility

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Kawasaki Motors Europe (KME) has officially confirmed it was the target of a cyberattack in early September, causing temporary disruptions to its operations. The company stated that while the attack was “not successful,” it resulted in the isolation of its …

Port of Seattle Confirms August Cyberattack by Rhysida Ransomware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The Port of Seattle has confirmed that the Rhysida ransomware gang orchestrated the cyberattack that disrupted its systems and operations in late August. The attack on August 24, 2024, forced the Port to isolate critical systems, resulting in widespread outages …

New GAZEploit Attack Let Hackers Capture Keystrokes from Apple Vision Pro

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A novel security vulnerability dubbed “GAZEploit” has been discovered that could allow hackers to capture keystrokes from Apple Vision Pro’s virtual keyboards. The attack exploits the eye-tracking technology used for gaze-based typing on Apple’s mixed-reality headset. Researchers from the University …

1.3 Million Android TV Box Hijacked By Android.Vo1d Malware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

An Android TV Box is a small device that connects to your TV and allows you to access a wide range of online content, apps, and services. It runs on the Android operating system, similar to smartphones and tablets, and …

What is Brute Force Attacks?

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

In cybersecurity, brute force attacks are a well-known and persistent threat. Despite being one of the oldest methods hackers use, brute force attacks remain a popular and effective tactic for gaining unauthorized access to systems and data. This article delves …

Citrix Workspace App Vulnerabilities Allow Privilege Escalation Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Citrix has released security updates to address two critical vulnerabilities, tracked as CVE-2024-7889 and CVE-2024-7890, affecting the Citrix Workspace app for Windows. These flaws could allow local attackers to gain SYSTEM privileges on compromised machines. The vulnerabilities impact the following …