Chinese Hackers Exploiting Zero-Day Flaw in Cisco Switches to Deploy Malware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated China-linked cyber espionage group, known as Velvet Ant, has been discovered exploiting a zero-day vulnerability in Cisco NX-OS Software to deploy custom malware on network switches. The vulnerability, tracked as CVE-2024-20399, was identified by cybersecurity firm Sygnia during …

McDonald’s Official Instagram Account Hacked to Promote Cryptocurrency Scam

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

On August 21, 2024, McDonald’s official Instagram account was hacked, resulting in a cryptocurrency scam that made the hackers around $700,000. The hackers exploited the fast-food giant’s massive social media following to promote a fraudulent cryptocurrency called “GRIMACE,” named after …

New Ngate Android Malware Lets Hackers Withdraw Money From Payment Cards

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Hackers execute several illicit activities with the help of Android malware, and they target Android due to its widespread use and its open ecosystem.  This makes it much easier for the hackers to perform their illicit activities like distributing malicious …

New Malware Hidden Within PostgreSQL Process Deploys Cryptocurrency Miners

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A successful brute-force attack on a PostgreSQL database exploited a feature that allowed command execution, where the attacker created a superuser role, dropped files to eliminate competition and gain persistence, and ultimately deployed cryptocurrency miners.  The attack demonstrates the severe …

North Korean Hackers Unveils New MoonPeak Malware With Updated Attack Methods

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cisco Talos has uncovered a new remote access trojan (RAT) family, which is XenoRAT-based malware that is under active development by a North Korean nexus cluster named “UAT-5394.”  While the new malware is dubbed “MoonPeak,” and the analysis reveals links …

Netflix Security Breach, Hackers Leaked Upcoming Episodes Online

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Hackers have leaked footage and clips from several unreleased Netflix anime shows, including full episodes, online. The content was stolen from one of Netflix’s post-production partners, causing a stir in the entertainment industry. Details of the Breach The leaked content …

FAA Proposed New Cybersecurity Rules for Airplanes

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The Federal Aviation Administration (FAA) has proposed new cybersecurity regulations for transport category airplanes, engines, and propellers. This initiative aims to address the growing threats posed by unauthorized electronic interactions, ensuring the safety and integrity of modern aircraft systems. The …

GitHub Enterprise Server Vulnerability Allow Attackers to Gain Admin Access

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The latest update to GitHub Enterprise Server, version 3.13.3, addressed a critical vulnerability (CVE-2024-6800), allowing attackers to forge SAML responses and gain unauthorized access. Enterprise Server 3.13.3 introduces several enhancements aimed at improving user experience and system management Users can …

Russia Reports DDoS Attack Disrupting Telegram and WhatsApp

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Russian users of popular messaging apps Telegram and WhatsApp experienced significant disruptions, which were attributed to a distributed denial-of-service (DDoS) attack. The state communications monitoring service confirmed the incident, stating that the attack had been successfully repelled and services were …

Zero-Day Vulnerability In Arcadyan WiFi Devices Allows RCE for Root Access – Exploit Released

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical zero-day vulnerability has been identified in the Arcadyan FMIMG51AX000J model and potentially other devices affiliated with the WiFi Alliance. This flaw allows remote attackers to execute arbitrary code. An independent security researcher working with SSD Secure Disclosure identified …