Rewards Up To $2.5 Million for Angler Exploit Kit Developer

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The U.S. Department of State has announced a reward of up to $2.5 million for information leading to Volodymyr Kadariya’s arrest and/or conviction. Kadariya is allegedly a key figure in a major malware organization responsible for developing and distributing the …

Researchers Exploited Remote Code Execution Moodle Platform

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The popular learning platform Moodle was found to have a critical vulnerability that allowed for remote code execution, which was caused by an improper sanitization of user input that could be exploited to inject malicious code into the system.  The …

HZ Rat Attacking macOS Users Via Messaging Platform WeChat

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Hackers target macOS as its growing user base makes it an increasingly attractive target.  Despite its reputation for strong security, macOS vulnerabilities exist, and exploiting them can give hackers access to valuable data or control over devices, particularly in environments …

CISA & FBI Details Phishing Techniques Used by Malicious Hackers

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The Cybersecurity and Infrastructure Security Agency (CISA) and the Federal Bureau of Investigation (FBI) have detailed the latest phishing techniques of malicious hackers. This joint guidance aims to equip organizations with the knowledge to defend against these pervasive threats. Understanding …

Hacking a Bicycle: Vulnerabilities Exploited in Wireless Gear-Shifting Systems

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Researchers have uncovered significant cybersecurity vulnerabilities in the wireless gear-shifting systems of high-end bicycles, particularly those using Shimano’s Di2 technology. This revelation has sent shockwaves through the professional cycling community, highlighting potential risks to rider safety and the integrity of …

Critical SQL Injection Vulnerability Discovered in Fortra FileCatalyst Workflow

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Fortra has urgently released patches to address two critical SQL injection vulnerabilities in its FileCatalyst Workflow software, identified as CVE-2024-6632 and CVE-2024-6633. If exploited, these vulnerabilities could severely compromise the confidentiality, integrity, and availability of affected systems. FileCatalyst Workflow, a …

Chinese Hackers Exploited Versa Director Zero-Day to Target IT Sectors, CISA Warns

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Chinese state-sponsored threat actors have been exploiting a zero-day vulnerability in Versa Director servers, identified as CVE-2024-39717. This vulnerability, discovered by Black Lotus Labs at Lumen Technologies, has been actively targeted since June 2024, affecting several U.S. and international victims …

Research Unveils Eight Android & iOS That Leaks User’s Sensitive Data

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The eight Android and iOS apps fail to adequately protect user data, which transmits sensitive information, such as device details, geolocation, and credentials, over the HTTP protocol instead of HTTPS.  It leaves the data exposed to potential attacks like data …

Cisco to Acquire AI Application Security Platform Robust Intelligence

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cisco has announced its intent to acquire Robust Intelligence, a leader in AI application security. This acquisition aligns with Cisco’s commitment to enhancing IT infrastructure and security in the face of AI’s transformative potential, as highlighted by the 2024 Cisco …

Greasy Opal, Hackers Created 750 Million Fake Microsoft Accounts

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Greasy Opal, based in the Czech Republic since 2009, is reportedly a Cyber Attack Enablement company that manufactures and markets advanced cyber attack bypassing tools and devices. The company’s main product features robust and rapid machine learning models that can …