New Emansrepo Malware Weaponizing HTML Files To Attack Windows Users

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Emansrepo is a Python infostealer that was discovered by the FortiGuard Labs in August 2024 and has been disseminated through phishing emails containing fake purchase orders and invoices. It started its operation in November 2023, where Emansrepo retrieves exfiltrated data …

RomCom Group Exploiting Microsoft Office 0-day To Deploy Ransomware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The Russian group RomCom, dubbed Storm-0978, distributes underground ransomware by leveraging the Microsoft Office and Windows HTML RCE zero-day vulnerability identified as CVE-2023-36884. This ransomware encrypts files on victims’ Windows computers, similar to typical ransomware, and then drops ransom notes …

Researchers Unpacked ViperSoftX Malware’s Evasion Tactics And Techniques

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Sophisticated threat actors, like those behind the ViperSoftX malware from 2020, often make use of existing tools to save time and resources.  ViperSoftX uses AutoIt, the CLR, and pre-made hacking scripts. This helps them to develop malware faster and avoid …

Threat Actor Allegedly Claims Leak of BMW Customer Database

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A well-known threat actor identified as “888” has claimed responsibility for leaking sensitive customer data belonging to BMW Hong Kong. According to the Breachforums post, “888” has allegedly leaked sensitive data from BMW Hong Kong, affecting approximately 14,057 customer records. …

Zyxel Critical Vulnerability Let Attackers Perform OS Command Injection

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Zyxel has issued patches to address a critical operating system (OS) command injection vulnerability identified as CVE-2024-7261. This vulnerability affects several versions of their access points (AP) and security routers. Users are strongly urged to apply these patches to safeguard …

Hackers Abuse Red Team Tool MacroPack To Deliver Multiple Malicious Payloads

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

MacroPack is a convenient tool for creating obfuscated VBA malware, but it is still a risk even with the macro execution restricted in downloaded Office documents from Microsoft. This tool can create several output types like office files, scripts, and …

Travelers Beware of Sophisticated Booking.com Phishing Attack

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cybercriminals have launched a sophisticated phishing attack targeting Booking.com, one of the world’s leading online travel platforms. This attack, characterized by its complexity and high success rate, has been evolving over the past year, posing significant risks to hotel managers …

Actively Exploited Android Zero-Day Elevation of Privilege vulnerability Patched

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Google has released a patch for a critical zero-day vulnerability, CVE-2024-32896, which was actively exploited in the wild. This vulnerability, classified as a high-severity elevation of privilege (EoP) flaw, was discovered in the Android operating system, specifically impacting Pixel devices. …

PoC Exploit Released for 0-Day Windows Kernel Privilege Escalation Vulnerability

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A proof-of-concept (PoC) exploit has been publicly released for a critical zero-day elevation of privilege vulnerability in the Windows kernel. The flaw, tracked as CVE-2024-38106, was one of several zero-days patched by Microsoft in their August 2024 Patch Tuesday update. …

Blackwired Launches ThirdWatch℠, A Paradigm Shift in Cybersecurity

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Blackwired, the leading cyber observatory for disruptive cybersecurity technologies, has announced the launch of ThirdWatch℠, a groundbreaking solution to identify direct threats facing an organization and its Third Parties. ThirdWatch℠ is a subject-directed monitoring platform that provides a comprehensive 360-degree …