Achieving 24/7 Threat Monitoring & Response for Small IT Security Teams – Free Guide

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Maintaining continuous vigilance is essential for organizations of all sizes in the face of increasing cyber threats. However, lean IT security teams often face the challenge of providing 24/7 threat monitoring and response with limited resources. For lean IT security …

North Korean Government Hacker Charged for Attacking U.S. Hospitals

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A grand jury in Kansas City has charged North Korean national Rim Jong Hyok for orchestrating a series of cyberattacks targeting U.S. hospitals and healthcare providers. The indictment outlines a conspiracy involving ransomware attacks, extortion, and money laundering. The ill-gotten …

HealthEquity Data Breach, 4.3 Million User Data Exposed

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

HealthEquity, Inc., a prominent health savings account administrator, has reported a data breach affecting approximately 4.3 million individuals. The breach, which occurred on March 9, 2024, and was discovered on June 26, 2024, has raised serious concerns about data security …

DigiCert to Revoke Thousands of Certificates Following DNS Validation Error

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

DigiCert, a major certificate authority, to revoke thousands of SSL/TLS certificates because of a Domain Control Verification error. This could affect a lot of websites. The company discovered that an oversight in the DNS-based verification process affected approximately 0.4% of …

Proofpoint’s Email Protection Service Exploited to Send Millions of Phishing Emails

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A massive phishing campaign dubbed “EchoSpoofing” has exploited a critical vulnerability in Proofpoint’s email protection service, allowing cybercriminals to send millions of perfectly spoofed phishing emails impersonating major brands. The exploit, uncovered by cybersecurity firm Guardio Labs, affected Proofpoint’s system …

Ransomware Gangs Exploiting VMware ESXi Auth Bypass Flaw for Mass Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Microsoft researchers have found a critical vulnerability in VMware’s ESXi hypervisors. Ransomware operators are using this problem to attack systems. This vulnerability, CVE-2024-37085, allows threat actors to gain full administrative permissions on domain-joined ESXi hypervisors, posing a severe risk to …

Phishing Threats and Cybersecurity 2024 : Protecting Personal and Organizational Data

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

As Americans engage in major activities such as the 2024 presidential race, large-scale cultural festivals, and high-profile sporting events, cybersecurity will be on high alert. Phishing attacks involve users through emails and messages in a somewhat deceiving way throughout the …

Threat Actors Exploiting SMBs Using List of Popular Productivity Tools

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Due to their widespread use, popular productivity tools are often targeted and attacked by hackers. These tools create a large attack surface area and offer the potential to access huge amounts of sensitive data. Successful exploitation of these tools enables …

Beware of Trik Loader Botnet that protects FUD from Antivirus

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A threat actor has claimed to have put the source code for sale for the notorious Trik botnet, also known as Phorpiex, in antivirus (AV) circles. This C++ botnet has a suite of modules that make it a formidable threat …

Beware of Malicious Mandrake Apps From Google Play With Over 32,000 Installs

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated Android spyware campaign known as Mandrake has resurfaced on the Google Play Store, infecting over 32,000 devices between 2022 and 2024. Mandrake has returned after a two-year break with its latest campaign. The malware stays inactive on victims’ …