Windows Wi-Fi Code Execution Flaw Let Attacker Hijack Your Devices

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Microsoft patched several vulnerabilities as part of June 2024’s Patch Tuesday, one of which was associated with remote code execution in Wi-Fi Driver. This vulnerability was assigned with CVE-2024-30078, and the severity was 8.8 (High).  However, based on Microsoft’s description …

BadSpace Malware Attacking Users By Leveraging High-Ranking Infected Websites

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Hackers abuse high-ranking infected websites to leverage their established credibility and large user base to spread malware, launch phishing attacks, or redirect traffic to malicious sites. While exploiting such trusted infected platforms they can now reach out to larger audiences, …

Critical ASUS Router Flaw Attacker Executes Arbitrary Commands

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical vulnerability has been discovered in several models of ASUS routers. It allows unauthenticated remote attackers to execute arbitrary system commands on the affected devices. The flaw, identified as CVE-2024-3912, has been assigned a CVSS score of 9.8, indicating …

Bondnet Using High-Performance Bots For C2 Server

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Threat actors abuse high-performance bots to carry out large-scale automated attacks efficiently. These bots can work quickly, flood systems, steal information, and conduct and orchestrate sophisticated cyber operations largely autonomously. Cybersecurity researchers at ASEC recently discovered that Bondnet has used …

Discord-Based Malware Attacking Orgs Linux Systems In India

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Linux systems are deployed mostly in servers, in the cloud, and in environments that are considered vital; consequently, they are often compromised by attacks from threat actors. This wide use and deployment of Linux makes it a lucrative target for …

New Moonstone Sleet North Korean Actor Deploying Malicious Open Source Packages

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

In December 2023, we reported on how North Korean threat actors, particularly Jade Sleet, have been compromising supply chains through the open-source ecosystem. One of their key tactics is the exploitation of the public npm registry to distribute malicious packages. …

Life360 Breach: Hackers Accessed the Tile Customer Support Platform

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Life360, a company known for its family safety services, recently fell victim to a criminal extortion attempt. The company received emails from an unknown actor claiming to possess Tile customer information. Upon receiving these emails, Life360 promptly investigated and detected …

Microsoft Delays Release of Controversial Windows AI Recall Tool Amid Privacy Concerns

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Microsoft has announced that it will delay the broad release of its AI-powered Recall feature for Windows Copilot+ PCs, following heavy criticism from users and privacy advocates. The feature, which was originally slated for wide availability on June 18, will …

SmokeLoader – A Modular Malware With Range Of Capabilities

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Hackers misuse malware for diverse illicit intentions, including data theft, disrupting systems, espionage, or distortion for unethical monetary benefits. Besides this malware is also helpful in conducting cyber warfare or receptive intelligence by the nation-state actors of a certain country …

Hackers Abuse Windows Search Functionality To Deploy Malware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Hackers use Windows Search’s vulnerability to penetrate different layers and rooms in the client’s systems and execute unauthorized code by using bugs in the search functionality itself.  This enables them to increase their privileges, disseminate viruses and malware, and steal …