Google Patched Critical Chrome Vulnerability Leads to Browser Crash

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Google has rolled out a critical security update for its Chrome browser, addressing a severe flaw that could lead to browser crashes. The update, now available on the Stable channel, brings Chrome to version 127.0.6533.88/89 for Windows and Mac and …

Beware! Tycoon 2FA Phish-kit Exploits Amazon SES to Steal User Credentials

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated phishing campaign with Tycoon 2FA Phish-kit has been identified, leveraging Amazon Simple Email Service (SES) and a series of high-profile redirects to steal user credentials. The attack chain, meticulously designed to evade detection, involves multiple stages and utilizes …

Critical OAuth Vulnerability Exposes 1 Million Sites to XSS Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Security researchers have uncovered a critical vulnerability affecting over one million websites. The vulnerability combines OAuth implementation flaws with cross-site scripting (XSS) attacks. The vulnerability stems from the interaction between OAuth, a widely used authentication protocol, and XSS, a long-standing …

Record-breaking Ransom Payment: Dark Angels Ransomware Received $75 Million

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cybersecurity firm Zscaler has revealed that the Dark Angels ransomware group received an unprecedented $75 million ransom payment from a single victim in a shocking development that underscores the escalating ransomware threat. This staggering sum nearly doubles the $40 million …

How to Collect and Use IOCs From Malware Configs IN TI Lookup – SOC/DFIR Teams

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Indicators of Compromise (IOCs) are key forensic data points used to detect security breaches. They include file hashes, suspicious IP addresses, domain names, URLs, specific email addresses, unusual file names, registry changes, unexpected processes, and abnormal network traffic patterns. These …

Microsoft Azure Globally Down – What’s Happening!

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

On July 30, 2024, at approximately 13:13 UTC, Microsoft Azure reported a global outage affecting a subset of its services. The issue resulted in timeouts and difficulties connecting to various Azure services worldwide. Multiple engineering teams at Microsoft were promptly …

Cuckoo Spear Attacking Windows Users With Highly Sophisticated Malware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Researchers uncovered Cuckoo Spear, a new threat actor associated with the APT10 group, demonstrating persistent stealthy operations within victim networks for two to three years.  The advanced persistent threat (APT) utilizes novel techniques and tools to conduct cyber espionage, emphasizing …

Researchers Hacked into Medusa Ransomware Group’s Cloud Storage

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The Medusa Ransomware Group experienced significant operational security (OPSEC) failure, which was primarily due to the group’s use of Rclone, a widely utilized tool for data exfiltration, to store stolen data in the cloud storage service put.io.  The key issue …

iPhone Users Beware! Fake Postal Messages Stealing Your Login Credentials

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cybercriminals have launched a smishing campaign targeting iPhone users in India, impersonating India Post. Malicious iMessages falsely claim a package awaits at an India Post warehouse, enticing victims to click on fraudulent links.  It leverages the widespread trust in India …

New MOVEit File Transfer Vulnerability Let Attackers Escalate Privileges

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Progress Software has disclosed a new high-severity vulnerability in its MOVEit Transfer file transfer solution that could allow attackers to escalate privileges through improper authentication. The vulnerability, tracked as CVE-2024-6576 with a CVSS score of 7.3, affects the SFTP module …