North Korean Hackers Attacking Windows Users With Weaponized npm Files

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Scalable package scanning within PyPi and npm using GuardDog software identified two malicious packages linked to a DPRK-aligned threat actor cluster dubbed “Stressed Pungsan.”  The cluster strongly aligns with Microsoft’s MOONSTONE SLEET, indicating a sophisticated supply chain attack vector. The …

Windows Smart App Control & SmartScreen Flaw Let Hackers Hijack Systems

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Hackers often target Window Smart App Control and SmartScreen security flaws to launch malicious code and applications for their illicit purposes. Threat actors aiming to undermine Windows security features can use these vulnerabilities to seize illicit access, steal sensitive data, …

Google Patches Actively Exploited Android Kernel Zero-Day Patched

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The Android Security Bulletin for August 2024 details vulnerabilities addressed by the 2024-08-05 security patch level.  The most critical issue is a high-severity vulnerability in the Framework component, which could potentially allow local privilege escalation without additional execution privileges.  Android …

New Threat Detection Model Detects Threats in Serverless Cloud With 0.003 False Alarm

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Researchers have introduced a novel threat detection model designed specifically for serverless cloud environments. This innovative approach leverages cloud providers’ native monitoring tools to detect anomalous behavior in serverless applications, providing a robust and efficient solution for identifying compromised serverless …

Threat Actors Announced Doubleface Ransomware, Claims Fully Undetectable

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A new ransomware variant named Doubleface has been announced by its creators. The ransomware, which boasts a range of sophisticated features, claims to be fully undetectable by major antivirus software. According to a Dark Web Informer tweet, Threat actors announced …

Jfrog Artifactory Flaw Let Attackers Poison Artifact Caches

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical vulnerability identified as CVE-2024-6915 has been discovered in JFrog Artifactory, a widely used repository manager. This flaw, categorized under CWE-20 (Improper Input Validation), allows attackers to poison artifact caches, potentially leading to severe security breaches. CVE-2024-6915: Cache Poisoning …

Researchers Jailbreaked Text-To-Image LLM Models Using Atlas Agent

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

LLM agents, combining large language models with memory and tool usage, have shown promise in diverse domains. While successful in fields like software engineering and industrial automation, their potential in generative AI safety remains largely unexplored.  Given the rapid advancement …

Apache OFBiz Zero-Day Vulnerability Let Attackers Execute Remote Code

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical zero-day vulnerability in Apache OFBiz, an open-source enterprise resource planning (ERP) system, has been discovered that could allow unauthenticated attackers to execute arbitrary code remotely. The flaw, tracked as CVE-2024-38856 with a CVSS score of 9.8, affects all …

Bloody Wolf Attacking Organizations With $80 Malware From Underground Market

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cybersecurity experts have uncovered a series of attacks targeting organizations in Kazakhstan by a threat actor dubbed “Bloody Wolf.” The group utilizes STRRAT, an inexpensive but potent malware available on underground forums for as little as $80. Since late 2023, …

APT41 Hackers Attacking Research Institute with ShadowPad and Cobalt Strike

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cisco Talos has unearthed a sophisticated cyber-espionage campaign targeting a Taiwanese government-affiliated research institute. The attack, attributed to the notorious Chinese hacking group APT41, involved the deployment of the ShadowPad malware and Cobalt Strike, among other customized tools. This article …