Ivanti Virtual Traffic Manager RCE Vulnerability (CVE-2024-7593) Exploit Released

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Verkada, a prominent security camera company, has agreed to pay $2.95 million following a massive data breach. This breach exposed the company’s failure to secure sensitive data, leading to widespread privacy and protection concerns. The Breach and Its Implications The …

Verkada pay $2.95 Million Failed to Secure Data Lead to Massive Breach

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The Federal Trade Commission (FTC) has announced that security camera firm Verkada will pay a $2.95 million penalty following allegations of inadequate data security practices. This settlement follows a massive data breach that exposed sensitive information from thousands of internet-connected …

Transport for London Faces Cyber Attack – Operation Distributed

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Transport for London (TfL), the organization responsible for the capital’s public transport network, is grappling with the aftermath of a significant cyber attack that has disrupted services. In the early hours of Monday, September 2, TfL’s IT systems were targeted …

Hacktivist Group Exploit WinRAR Vulnerability to Encrypt Windows & Linux

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The hacktivist group Head Mare has leveraged a vulnerability in WinRAR to infiltrate and encrypt systems running on Windows and Linux. This group, active since the onset of the Russo-Ukrainian conflict, has primarily targeted organizations in Russia and Belarus. Their …

New Voldemort Malware Using Google Sheets To Store Stolen Data

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Hackers abuse Google Sheets to covertly store and transmit stolen data or execute malicious scripts, taking advantage of its trusted platform status and collaboration features. Cybersecurity researchers at Proofpoint identified an unusual campaign in August 2024 involving the use of …

New ManticoraLoader Malware Attacking Citrix Users To Steal Data

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

DeadXInject, the group behind AresLoader and AiDLocker ransomware, is offering a new Malware-as-a-Service (MaaS) called ManticoraLoader.  Advertised on underground forums and Telegram since August 8th, 2024, ManticoraLoader is a C-based tool designed to target Windows systems (including servers) and steal …

Godzilla Fileless Backdoor Exploits Atlassian Confluence Vulnerability CVE-2023-22527

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A new attack vector has emerged, exploiting the critical vulnerability CVE-2023-22527 in Atlassian Confluence. This vulnerability, which affects the Confluence Data Center and Server products, has been weaponized using the Godzilla backdoor, a sophisticated file-less malware. The implications of this …

Microsoft Observed A New Tickler Malware Attack Satellite Devices

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cybersecurity researchers at Microsoft recently discovered that Peach Sandstorm, a state-sponsored threat actor affiliated with the IRGC, added Tickler, a new multistage backdoor, to their arsenal between April and July 2024. The threat actors attack satellite devices because they are …

How Phishing Messages Break Through Email Filters – Report

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Phishing remains a persistent danger. It’s an email-based cyber threat through which threat actors target sensitive user credentials and distribute malware. More than 963,000 attacks were discovered recently in the APWG’s Phishing Activity Trends Report for Q1 2024. In Business …

New Latrodectus Attacking Users with Enhanced Capabilities & Evasion Techniques

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The Latrodectus malware has been observed to have enhanced capabilities and sophisticated evasion techniques. Initially discovered by Walmart in October 2023, Latrodectus has gained notoriety for its similarities with the infamous IcedID malware. This article delves into the new features …