Microsoft Sway Abused By Threat Actors To Steal Login Credentials

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Researchers observed a significant surge in phishing attacks targeting MS Office credentials via Microsoft Sway in July 2024, where attackers used QR codes to lure victims to malicious websites, employing transparent phishing and Cloudflare Turnstile to evade detection and bypass …

Cisco NX-OS Software Vulnerability Let Attackers Trigger DoS Condition

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cisco has disclosed a critical vulnerability in its NX-OS software that could allow unauthenticated, remote attackers to cause a denial of service (DoS) condition on affected devices. The flaw, tracked as CVE-2024-20270, impacts the DHCPv6 relay agent feature in certain …

AutoIT Malware Attacking Gmail Users To Steal Login Credentials

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A malicious AutoIT-compiled executable has been discovered that attempts to open Gmail login pages using popular browsers and possesses capabilities to steal clipboard data, capture keystrokes, and manipulate system behavior.  It can also evade detection by blocking user input and …

Corona Mirai Botnet Exploiting RCE Zero-Day To Hire New Bots

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A botnet is exploiting a new zero-day vulnerability, CVE-2024-7029, in AVTECH CCTV cameras to spread a Mirai variant, which is a command injection vulnerability in the brightness function that allows for remote code execution.  It leverages this vulnerability to gain …

Hackers Could Exploit Dell BIOS Flaw Let Hackers Execute Arbitrary Code

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical vulnerability in the Dell Client Platform BIOS has been identified, potentially allowing hackers to hijack compromised systems. This flaw, identified as CVE-2024-39584, is classified as a “Use of Default Cryptographic Key” vulnerability. It poses a significant risk, with …

Check Point to Acquire Cyberint Technologies to Enhance Threat Intelligence

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Check Point® Software Technologies Ltd. (NASDAQ: CHKP), a prominent player in the cybersecurity industry, has announced a definitive agreement to acquire Cyberint Technologies Ltd. This strategic acquisition aims to enhance Check Point’s Security Operations Center (SOC) capabilities and expand its …

Wireshark 4.4.0 Released – What’s New!

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The Wireshark Foundation has announced the release of Wireshark 4.4.0, bringing a host of new features, improvements, and bug fixes to the popular open-source network protocol analyzer. This latest version introduces significant enhancements to graphing capabilities, display filter functionality, and …

BlackByte Hackers Exploiting VMware ESXi Auth Bypass Flaw to Deploy Ransomware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Security researchers have discovered that the BlackByte ransomware group is actively exploiting a recently patched authentication bypass vulnerability in VMware ESXi hypervisors to deploy ransomware and gain full administrative access to victim networks. The vulnerability, tracked as CVE-2024-37085, allows attackers …

Multiple Vulnerabilities in AI Platforms Exposes Sensitive Data to Anyone

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Artificial intelligence (AI) platforms have become integral tools for businesses and organizations worldwide. These technologies promise efficiency and innovation, from chatbots powered by large language models (LLMs) to intricate machine learning operations (MLOps). However, recent investigations have uncovered alarming vulnerabilities …

APT Hackers Exploiting Zero-Day Vulnerabilities in WPS Office

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

ESET researchers have uncovered two critical zero-day vulnerabilities in WPS Office for Windows, exploited by the advanced persistent threat (APT) group APT-C-60. This South Korea-aligned cyberespionage group has been targeting users in East Asian countries, leveraging these vulnerabilities to execute …