Kematian Stealer Abuses Powershell Tool for Covert Data Exfiltration

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The Kematian Stealer has emerged as a sophisticated PowerShell-based malware that covertly exfiltrates sensitive data from compromised systems. This article delves into the intricate workings of this malicious tool, highlighting its methods and the potential risks it poses. Binary Analysis …

New Volcano Demon Ransomware Group Threatening Victims Over Phone Call

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A novel malware known as Volcano Demon has been observed targeting Windows workstations and servers, obtaining administrative credentials from the network. The threat actor doesn’t have a leak site and instead uses phone calls to executives in IT and leadership …

Beware Of Malicious PDF Files That Mimic As Microsoft 2FA Security Update

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Malware authors are exploiting the growing popularity of QR codes to target users through PDF files, where these malicious PDFs, often delivered via email disguised as faxes, contain QR codes that trick users into scanning them with their smartphones.  QR …

Critical OpenStack Arbitrary File Access Flaw Exposes Cloud Data to Hackers

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical security vulnerability has been identified in OpenStack, a widely used open-source cloud computing platform. The flaw tracked as CVE-2024-32498, allows authenticated attackers to gain unauthorized access to arbitrary files on the host system, potentially exposing sensitive data. The …

Mallox Ransomware Attacking Linux Servers In Wild – Decryptor Uncovered

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Linux servers often provide hosting for critical applications, websites, and databases, which makes them a lucrative target for intruders to get unauthorized access to steal data and manipulate services. Exploiting security holes in Linux servers can enable attackers to take …

Malicious QR Reader App in Google Play Delivers Anatsa Banking Malware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cybersecurity experts have identified a malicious QR code reader app on Google Play that is delivering the notorious Anatsa banking malware. This discovery underscores the persistent threat posed by malicious apps in official app stores, emphasizing the need for heightened …

ChatGPT for MacOS Store All The Conversation in Plain Text

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Significant security concerns have been raised regarding the OpenAI ChatGPT app on macOS. The app reportedly stores user conversations in plain text in a non-protected location, sparking a debate about its adherence to macOS’s stringent security protocols. This practice means …

MSI Installer Vulnerability Let Attackers Escalate Privileges with Windows Systems

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical local privilege escalation vulnerability has been discovered in MSI Center versions 2.0.36.0 and earlier, allowing low-privileged users to escalate their privileges on Windows systems. This security flaw, tracked as CVE-2024-37726, stems from insecure file operations performed by the …

International Operation Takes Down 593 Malicious Cobalt Strike Servers

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Law enforcement agencies from around the world have successfully shut down 593 rogue servers running unauthorized versions of Cobalt Strike, a tool often misused by cybercriminals. The operation, codenamed “Operation Morpheus,” was spearheaded by the UK’s National Crime Agency (NCA) …

Free Malware Research with ANY.RUN Sandbox: Now Windows 10 Access for All Users

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

In a significant move to enhance cybersecurity analysis for all its users, ANY.RUN has announced that Windows 10 is now available to everyone, including Community plan users. This update marks a substantial improvement in the platform’s ability to detect and …