Operation ShadowCat Using Weaponized Office document To Attack Users In India

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Researchers identified a new attack campaign (“Operation ShadowCat”) using malicious LNK files distributed via spam emails, which triggers a PowerShell script that drops a .NET loader and a decoy Word document.  The loader fetches a steganographic PNG containing a Gzip-compressed …

Threat Actors Using OS Command Injection Vulnerabilities To Compromise Systems, CISA Warns

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

By exploiting OS command injection vulnerabilities, threat actors can run arbitrary commands on a host operating system to obtain unauthorized access, control, and the power to either corrupt or steal sensitive data. Such hacking can result in serious security breaches, …

Hackers Exploiting MSHTML vulnerability to Deliver Atlantida Malware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Void Banshee, a threat actor, has been exploiting a critical MSHTML vulnerability, CVE-2024-38112, to distribute the Atlantida InfoStealer malware. This sophisticated campaign has targeted unsuspecting users by attracting PDF books distributed via various public platforms, including online libraries and Discord …

Spyware Provider for Windows, Mac & Android Hacked, Sensitive Data Exposed

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

TechCrunch has learned that Spytech, a little-known spyware maker based in Minnesota, has been hacked, exposing sensitive data from thousands of devices worldwide. The breach has unveiled the covert surveillance activities of the company, which has compromised over 10,000 devices …

RADIUS Protocol Vulnerability Impacted Multiple Cisco Products

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical vulnerability in the Remote Authentication Dial-In User Service (RADIUS) protocol has been disclosed, affecting multiple Cisco products. The vulnerability, CVE-2024-3596, allows an on-path attacker to forge RADIUS responses, potentially leading to unauthorized access to network resources. It could …

CrowdStrike Outage Leads to Estimated Financial Loss of $5.4 Billion

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A recent global IT outage linked to CrowdStrike, a leading cybersecurity company, has resulted in an estimated $5.4 billion in direct financial losses for Fortune 500 companies, according to a report released by cloud insurance firm Parametrix. The incident on …

Hackers Abuse Microsoft Office Forms to Launch Two-Step Phishing Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cybercriminals are increasingly using Microsoft Office Forms to launch sophisticated two-step phishing attacks. At present, certain individuals are being tricked into divulging their Microsoft 365 (M365) login information through Office Forms. Threat actors use the technique known as “external account takeover” …

Beware Of Malicious Chrome Installer From Chinese Hackers

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A malicious Chrome installer, ChromeSetup.msi, distributed via drive-by download, delivers a novel Gh0st RAT variant, dubbed Gh0stGambit, that evasively retrieves and executes encrypted payloads.  The RAT is a modified open-source version targeting Chinese-speaking users with data theft and evasion capabilities, …

Threat Actors Exploiting Selenium Grid Services For Cryptomining

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Threat actors often exploit the cloud services for cryptomining, as doing so allows them to abuse the huge computational resources available.  This enables them to significantly maximize their mining efficiency without bearing any cost. Cybersecurity analysts at Wiz recently identified …

ServiceNow Flaw Let Remote Attackers Execute Arbitrary Code

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

ServiceNow recently disclosed three critical vulnerabilities (CVE-2024-4879, CVE-2024-5217, and CVE-2024-5178) affecting multiple Now Platform versions, allowing unauthenticated remote code execution and unauthorized file access.  The vulnerabilities, with CVSS scores ranging from 6.9 to 9.3, pose significant risks of data theft, …