Hackers Using k4spreader Tool To Install DDoS Botnet And Miners

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A new ELF malware tool named k4spreader, written in Cgo by the Chinese “8220” (Water Sigbin) mining gang, was discovered in June 2024. Packed with a modified UPX packer, k4spreader installs other malware, including the Tsunami DDoS botnet and PwnRig …

Polyfill JS Library Injected Malware Into 100K+ Websites

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Polyfill.js is a JavaScript library that gives modern functionality on older browsers without native support for some web features. Polyfills ensure compatibility across a wide range of browsers, enabling developers to use modern JavaScript and web APIs by implementing what …

Researchers Released PoC For Windows Bluetooth Service RCE Vulnerability

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Microsoft addressed a Remote code execution vulnerability on their Bluetooth service on March 2023 Patch Tuesday. This vulnerability could allow an unauthorized threat actor to run a certain function on the Windows Bluetooth driver, which could lead to executing arbitrary …

FireTail Unveils Free Access for All to Cutting-Edge API Security Platform

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

FireTail announces a free version of its enterprise-level API security tools, making them accessible to developers and organizations of all sizes. FireTail’s unique combination of open-source code libraries, inline API call evaluation, security posture management, and centralized audit trails helps …

HC3 Unveils Qilin Ransomware Attacking Global Healthcare Organizations

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The Health Sector Cybersecurity Coordination Center (HC3) has issued a critical alert regarding a new ransomware strain, Qilin, which is targeting healthcare organizations worldwide. This revelation underscores the escalating cyber threats facing the healthcare sector, which is already grappling with …

VMware ESXi Vulnerability Allows Attackers to Bypass Authentication

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

VMware has disclosed three critical vulnerabilities in its ESXi hypervisor that allow attackers to bypass authentication mechanisms. These vulnerabilities, identified as CVE-2024-37085, CVE-2024-37086, and CVE-2024-37087, pose significant risks to organizations using VMware ESXi for their virtualized environments. Free Webinar on …

Neiman Marcus Hacked: 64,000 customers Data Exposed

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A Luxury retailer, Neiman Marcus, has disclosed a data breach affecting approximately 64,000 customers. The incident, which came to light after an investigation, exposed sensitive customer information, including names, contact details, dates of birth, and gift card numbers from Neiman …

P2Pinfect Malware Deploy Ransomware and Cryptominer in Windows Via SSH

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cybersecurity researchers have discovered a significant evolution in the previously dormant P2Pinfect malware strain. The updated version can now deploy ransomware and a cryptominer, posing a serious threat to organizations and individuals alike. P2Pinfect, a malware strain that has been …

New MOVEit Auth Bypass Vulnerability Under Attack Now, Patch Immediately

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Progress Software’s popular MOVEit Transfer and MOVEit Cloud-managed, file transfer solutions, have been found to contain a critical authentication bypass vulnerability (CVE-2024-5806). The vulnerability, which exists in the products’ SFTP module, can allow attackers to bypass authentication and gain unauthorized …

ANY.RUN Cyber Attack: Employee Email Address Hacked

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A leading cybersecurity company has become the latest victim of a sophisticated phishing attack. The incident, which began in late May and culminated in a large-scale email compromise on June 18, 2024, has sent shockwaves through the cybersecurity community. First …