Critical Vulnerability in Digital Video Recorders Exposes 400,000 Devices to Hackers

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Multiple digital Video Recorder (DVR) devices have been identified with a critical security vulnerability, leaving over 408,000 units exposed to potential cyber-attacks. The flaw, primarily affecting models such as TVT DVR TD-2104TS-CL, TD-2108TS-HP, Provision-ISR DVR SH-4050A5-5L(MM), and AVISION DVR AV108T, allows unauthorized …

Leaked Wallpaper Exploit Let Attackers Escalate Privilege on Windows Systems

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical security flaw in Windows’ wallpaper handling mechanism has been uncovered. It allows attackers to gain system-level privileges on affected machines. Security researcher Andrea Pierini disclosed the vulnerability, which is tracked as CVE-2024-38100 and dubbed “FakePotato.” The FakePotato exploit …

Hackers Can Use HDMI Cables to Capture Your Passwords

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Security researchers have discovered a new way that hackers can steal sensitive information, like passwords. This involves eavesdropping on HDMI cables, a concerning development for computer users. The technique, detailed in a recent study by researchers at Universidad de la …

Telegram-Controlled TgRat Attacking Linux Servers to Exfiltrate Data

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

TgRat, a Telegram-controlled trojan, was discovered attacking Linux servers in an attempt to steal data from a compromised system. In 2022, the TgRat trojan was first identified. Although the original version of the trojan was small and designed for Windows, …

Sitting Ducks DNS Attack Hijack 35,000 Domains

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Threat actors have been exploiting the attack vector known as Sitting Ducks since at least 2019 to conduct malware delivery, phishing, brand impersonation, and data exfiltration by exploiting flaws in DNS. This widespread flaw, affecting multiple DNS providers, enables domain …

Beware! Fake Google Authenticator Sites Spreading DeerStealer Malware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Researchers from ANY RUN identified a malware distribution campaign dubbed DeerStealer that leverages deceptive websites masquerading as legitimate Google Authenticator download pages.  The initial discovered website, “authentificcatorgoolglte[.]com,” closely resembles the authentic Google page “safety.google/intl/en_my/cybersecurity-advancements,” presumably to trick users into believing …

Threat Actors Exploiting ChatGPT’s Sora AI Excitement To Deliver Malware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Threat actors exploit AI to make their attacks more effective through automation, scanning large data sets for security gaps and creating intricate phishing scams that are harder to spot. In addition, threat actors can employ AI to produce legit-looking fake …

DEV#POPPER Attacking developers via New Social Engineering Tactics

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Threat actors masquerade as interviewers and send a ZIP file (onlinestoreforhirog.zip) to candidates as part of a fake interview, which contains legitimate files and a malicious JavaScript file (printfulRoute.js) that is obfuscated to evade detection.  The obfuscated code uses techniques …

Leading Silver Producer Fresnillo PLC Suffer Cyberattack

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Fresnillo PLC, the world’s largest primary silver producer, and Mexico’s largest gold producer has announced that it has been the target of a significant cybersecurity incident. The breach resulted in unauthorized access to specific IT systems and data. Upon discovering …

Tricky OneDrive Phishing Campaign Tricks Users To Execute PowerShell Script

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated phishing campaign targets Microsoft OneDrive users, employing social engineering to trick victims into executing malicious PowerShell scripts.  The attack leverages a false sense of urgency by claiming a DNS issue prevents file access, enticing users to click a …