“Audi Q7 Car For Sale! ” – But Malware Will be Delivered Instead of Car

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A Russian threat actor known as Fighting Ursa (also referred to as APT28, Fancy Bear, and Sofacy) has been identified in a new campaign that began in March 2024. This campaign uses a fake car sale advertisement to distribute the …

SLUBStick Linux Vulnerability Let Attackers Gain Full System Control

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Security researchers have discovered a severe vulnerability in the Linux kernel that could allow attackers to gain full control over affected systems. Dubbed “SLUBStick,” the exploit technique uses memory allocation flaws to achieve arbitrary read and write access to kernel …

Hackers Abuse TryCloudflare Service To Bypass Detection And Deliver Malware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cybercriminals increasingly leverage the TryCloudflare Tunnel to deliver Remote Access Trojans (RATs) in financially motivated attacks. TryCloudflare is a tool for developers to experiment with Cloudflare Tunnel without adding a site to Cloudflare’s DNS. Threat actors continually refine tactics to …

New Widespread Phishing Campaign Attacking Users With Multiple Malware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Phishing campaigns intensified in May 2024, with Poland bearing the brunt of attacks, accounting for 80% of over 26,000 protected users, as Italy and Romania also experienced significant targeting.  Threat actors launched nine distinct phishing campaigns during the month, primarily …

Microsoft Edge Vulnerability Let Attackers Execute Arbitrary Code

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Microsoft has released a critical security update for its Edge browser to address multiple vulnerabilities, including a severe validation flaw that could allow attackers to execute arbitrary code on affected systems. The update, released on August 1, 2024, patches three …

RBI Mandated Additional Factor Authentication for All Card payments

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The Reserve Bank of India (RBI) has proposed a new framework mandating additional factor authentication (AFA) for all digital payment transactions, with some exceptions. This move aims to enhance the security of digital payments while allowing for alternative authentication methods …

Authorities Sentenced Leader of Tech Support Fraud Scheme to Seven Years in Prison

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Damian Williams, the United States Attorney for the Southern District of New York, announced that Vinoth Ponmaran has been sentenced to seven years in prison for his role in a widespread tech support fraud scheme. The conspiracy, which targeted elderly …

Bitdefender Vulnerability Let Attackers Trigger SSRF Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical security vulnerability has been discovered in Bitdefender’s GravityZone Update Server, potentially exposing organizations to server-side request forgery (SSRF) attacks. The flaw, identified as CVE-2024-6980, carries a high severity rating with a CVSS score of 9.2 out of 10, …

New Flame Stealer Malware Attacking Users to Steal Credit Card Data

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A new malware named “Flame Stealer” has been making waves in the cybersecurity community, posing a significant threat to users’ financial and personal data. Developed in C and C++, this sophisticated software was first announced on Telegram on April 14, …

10 Best SMTP Testing Tools for Email Security in 2024

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

MTP (Simple Mail Transfer Protocol) test tools are essential for verifying the configuration and security of email servers. These tools help ensure that email communications are secure, reliable, and properly configured, which is crucial for protecting sensitive information and preventing …