Juniper Junos Flaw Let Attackers Gain Full ‘Root’ Access

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Hackers focus on Juniper Junos because it is extensively used in business networking and, consequently, a huge target for hacking valuable systems. Since it is prominent in big organizations, any successful breach can result in significant data loss or operational …

Pinterest Data Leak: Hackers Claiming Access to 60 Million Rows of Data

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Pinterest, the popular image-sharing platform with over 518 million monthly active users, faces a potential data leak that could affect millions of users. A hacker known as “Tchao1337” has allegedly leaked a database containing 60 million rows of Pinterest user …

Threat Actors Claims Breach of 1.1TB of Disney’s Internal Slack Chats

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Threat actors have claimed responsibility for a massive data breach involving 1.1TB of Disney’s internal Slack chats. The breach, first reported on July 12 by a hacktivist named NullBulge on a dark web forum, has sent ripples through the cybersecurity …

Google to Acquire Cybersecurity Firm Wiz for $23 Billion

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Google is reportedly in advanced discussions to acquire the cloud security firm Wiz for a staggering $23 billion. The Wall Street Journal broke the news on Sunday, citing sources familiar with the matter. If finalized, this acquisition would mark Google’s …

BianLian Ransomware Leveraging RDP Credentials To Gain Initial Access

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

BianLian emerged in 2022, and after its emergence rapidly, it became one of the three most active ransomware groups.  They started their operations by exploiting RDP, ProxyShell, and SonicWall VPN vulnerabilities.  The cybersecurity researchers at Juniper affirmed that the operators …

CRYSTALRAY Hackers Exploiting Popular pentesting Tools To Evade Detections

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The threat actor Crystalray, previously observed using SSH-Snake, has significantly expanded operations, targeting over 1,500 victims.  Employing mass scanning, exploiting multiple vulnerabilities, and utilizing tools like zmap, asn, httpx, nuclei, platypus, and SSH-Snake, CRYSTALRAY aims to steal and sell credentials, …

Hackers Starting To Exploit The Vulnerabilities Within 22 Minutes Of PoC Release

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The growing tension and global elections in the past year have presented major challenges to internet security, raising the volume of malicious traffic. Cloudflare cybersecurity researchers presented their Q1 2024 Application Security Report, which illustrated how Cloudflare’s mitigated traffic has …

OilAlpha Hacker Group Attacking Humanitarian & Human Rights Organizations

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A pro-Houthi group, OilAlpha, is targeting humanitarian organizations in Yemen with malicious Android applications by stealing credentials and gathering intelligence, potentially disrupting aid distribution.  The applications target sensitive data and require invasive permissions, such as camera and SMS access. The …

Hackers Compromised Multiple Squarespace Customers’ Domain Names

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Unknown threat actors have compromised multiple domain names registered with Squarespace. The incident, which began around July 10, 2024, has affected numerous domains that were transferred to Squarespace following its acquisition of Google Domains in September 2023. On September 7, …

AT&T Paid $370,000 to Hacker For Deleting Stolen Records

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

AT&T reportedly paid a hacker approximately $370,000 to delete stolen customer data. The payment was made to ensure the erasure of call and text records that had been illicitly obtained during a series of cyber intrusions earlier this year. The …