ConfusedFunction Vulnerability in Google Cloud Platform Let Attackers Escalate Privileges

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A newly discovered vulnerability in Google Cloud Platform (GCP) has raised significant security concerns among users and experts alike. The vulnerability, dubbed “ConfusedFunction,” involves GCP’s Cloud Functions and Cloud Build services, potentially allowing attackers to escalate privileges and gain unauthorized …

PKfail Vulnerability Allows Hackers to Install UEFI Malware on Over 200 Device Models

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The PKfail vulnerability is a significant security issue affecting over 200 device models of Secure Boot. PKfail is a critical firmware supply-chain issue that undermines the Secure Boot process in the UEFI ecosystem. Secure Boot ensures that only trusted software …

OpenStack Nova Vulnerability Allows Hackers Gain Unauthorized Access to Cloud Servers

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A vulnerability in OpenStack’s Nova component has been identified, potentially allowing hackers to gain unauthorized access to cloud servers. This vulnerability, tracked as CVE-2024-40767, affects multiple versions of Nova and poses a serious risk to cloud infrastructure worldwide. CVE-2024-40767– OpenStack …

North Korean Charged in Cyberattacks on US Hospitals, NASA & Military Bases

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A North Korean military intelligence operative has been indicted for orchestrating a series of cyberattacks targeting U.S. hospitals, NASA, and military bases, federal prosecutors announced on Thursday. Rim Jong Hyok, a member of the Andariel Unit within North Korea’s Reconnaissance …

RA Ransomware Group Aggressively Attacking Manufacturing Sector

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

RA World, an emerging ransomware group, has been increasingly active since March 2024, using a multi-extortion tactic to steal data and threaten to leak it if the ransom is not paid.  Their leak site shows a recent shift in targets …

Vigorish Viper, nn Advanced Suite for Cybercrime Supply Chain

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Hackers make use of the cybercrime supply chain for a multitude of illicit purposes like acquiring and distributing malicious tools, services, and stolen data. This collaboration leads them to execute more sophisticated and widespread attacks by enabling them to specialize …

Red Art Games Hacked, Customers Personal Information Exposed

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Red Art Games, a prominent publisher and distributor of limited-edition video games, has fallen victim to a cyberattack. The breach has resulted in the exposure of sensitive customer information, causing widespread concern among its user base. On July 25, 2024, …

Threat Actors Using Telegram APIs To Steal Login Credentials

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Threat actors are exploiting Telegram APIs to avoid detection and illicitly obtain users’ login credentials. Be cautious of a phishing email containing a disguised URL (hxxps[://]www[.]astunet[.]com/wp-plug/imu0nni5/3rhenqt2/) that directs you to a deceptive landing page hosted on r2.dev cloud storage (hxxps[://]pub-31a116fb226d4dfaa2004eef764a6bff[.]r2[.]dev/ayo[.]html). …

North Korean APT45 Hackers, Long Running Digital Military Since 2009

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The FBI and Google-owned Mandiant have recently revealed a sophisticated North Korean hacking group known as APT45. This group, previously dubbed Andariel, has been conducting cyber espionage campaigns globally since at least 2009. It has now been elevated to an …

Hackers Claiming Breach of CrowdStrike’s Threat Actor Database

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A hacktivist entity known as USDoD has claimed to have leaked CrowdStrike’s “entire threat actor list” and alleged possession of the company’s “entire IOC [indicators of compromise] list”, which contains over 250 million data points. On July 24, 2024, the …