Beware of Work Email Security Alert that Steals Your Login Credentials

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A new phishing scam is targeting employees by exploiting their sense of responsibility and concern for email security. The attack begins with an email purportedly from “The Office 365 Team,” alerting the recipient of a suspicious forwarding rule or unauthorized …

Aembit Raises $25 Million in Series A Funding for Non-Human Identity and Access Management

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The investment will drive the company’s advancement of scalable workload access management for enterprises Aembit, the leading non-human identity and access management (IAM) company, has secured $25 million in Series A funding, bringing its total capital raised to nearly $45 …

Google Unveils Air-gapped Backup Vaults to Protect Data from Ransomware Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Google Cloud has introduced air-gapped backup vaults as part of its enhanced Backup and Disaster Recovery (DR) service. This new feature, currently available in preview, aims to provide robust protection against the rising threat of ransomware attacks and unauthorized data …

Threat Actors Exploiting Legitimate Software For Stealthy Cyber Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Threat actors often exploit legitimate software for malicious purposes as it enables them to evade security measures and gain unauthorized access to systems.  By using legitimate software, threat actors can avoid detection and blend in with normal network traffic which …

Six North Korean Threat Groups Under The Umbrella Of Lazarus

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Lazarus Group is a notorious APT hacker group believed to be state-sponsored by North Korea, primarily linked to the country’s intelligence agency.  This group has been involved in a wide range of cybercriminal activities since at least 2009, and it’s …

New Android Banking Malware TrickMo Attacking Users To Steal Login Credentials

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Banking malware is a type of malicious software that targets financial institutions and their customers. There is a rise in Android banking malware, which exploits vulnerabilities in the Android operating system to steal sensitive user information. Cleafy’s Threat Intelligence team …

Cisco IOS XR Software Flaw Let Attackers Exhaust Memory, DoS & Elevate Privileges

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical vulnerability has been identified in the multicast traceroute version 2 (Mtrace2) feature of Cisco IOS XR Software, posing significant risks to network stability and security. This flaw allows unauthenticated, remote attackers to exhaust the UDP packet memory of …

Cisco Web-Based Management Interface Vulnerability Allows Privilege Escalation

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cisco has disclosed a critical vulnerability in the JSON-RPC API feature used by the web-based management interfaces of several products, including Cisco Crosswork Network Services Orchestrator (NSO), Cisco Optical Site Manager, and Cisco RV340 Dual WAN Gigabit VPN Routers. The …

GitLab Releases Critical Security Update, Urges Users to Patch Immediately

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

GitLab has released a critical security update addressing several vulnerabilities; among them critical ones are CVE-2024-6678, CVE-2024-8640, CVE-2024-8635, and CVE-2024-8124. GitLab recommends that all installations running affected versions be upgraded to the latest patched releases (17.3.2, 17.2.5, and 17.1.7) as …

Hunters Ransomware Group Allegdly Claims Breach of ICBC London

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The Hunters International ransomware group allegedly claiming the breach of the London branch of the Industrial and Commercial Bank of China (ICBC), a major Chinese state-owned bank. The group claims to have exfiltrated a staggering 6.6 terabytes of data, equating to over …