Frontier Communications Ransomware Attack: 750,000 Users’ Data Exposed

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Frontier Communications Parent, Inc. (the “Company”) detected unauthorized access to portions of its information technology environment. The breach, attributed to a likely cybercrime group, exposed the personal data of approximately 750,000 users. The Company promptly initiated its cyber incident response …

Bitdefender GravityZone Flaw Let Hackers Launch SSRF Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Bitdefender has recently fixed a critical Server-Side Request Forgery (SSRF) vulnerability in its GravityZone Console On-Premise, known as CVE-2024-4177. This flaw, discovered in the host whitelist parser, could have allowed malicious actors to exploit the system by sending crafted requests, …

Microsoft Made Changes to Recall Feature Following Controversial Security Concerns

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Microsoft has announced significant updates to its new Recall feature for Copilot+ PCs, following a wave of security and privacy concerns raised by experts and users. The Recall feature, set to debut on June 18th, is designed to enhance productivity …

North Korean Kimsuky APT Exploiting Facebook And MS Console For Targeted Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Facebook and MS Console are often targeted by hackers, as they contain a lot of personal and sensitive data that can be used for identity theft, phishing, and other harmful activities. When these systems are breached, threat actors use them …

Beware of Fake Google Chrome Update Pop-Ups that Installs Malware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

In the ever-changing cybersecurity landscape, a persistent threat appears in the form of a fake Chrome update.  Usually, these efforts involve injecting harmful code into a website, which prompts individuals to update their web browsers with a popup message.  A …

270GB of New York Times Internal Data and Source Code Leaked

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

An anonymous hacker has claimed to have leaked 270 GB of internal data and source code from The New York Times (NYT) on the controversial image board 4chan. The leak, reportedly containing over 5,000 repositories and 3.6 million files, was …

Hackers Attack ThinkPHP By Injecting Payload From Remote Servers

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Threat actors are constantly evolving their TTPs and developing new malicious tools to execute their activities. Recently, Akamai researchers have noted a concerning trend of attackers exploiting known vulnerabilities, such as the years-old ThinkPHP RCE CVE-2018-20062 and CVE-2019-9082.  Initially detected …

TotalRecall: A New Tool that Extracts Dara From Windows 11 Recall Feature

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Microsoft’s Windows Recall is a new feature for Copilot+ PCs, announced in May 2024. It takes periodic screenshots (every 5 seconds when screen content changes) and stores them locally on the device.  Users can then search this history using natural …

Wineloader Mimic As Ambassador Of India To Start The Infection Chain

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

ARC Labs delved into the intricacies of the Wineloader backdoor, a sophisticated tool used in spearphishing campaigns linked to the notorious APT29 group, also known as NOBELIUM or COZY BEAR. This analysis aims to provide defenders with detection guidance and …

Huge Surge in Attacks Exploiting Check Point VPN Zero-Day Vulnerability

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Check Point published an advisory regarding a critical vulnerability, CVE-2024-24919, which has since seen a surge in exploitation attempts. The vulnerability, rated with a CVSS score of 8.6, allows attackers to access sensitive information on the Security Gateway, potentially leading …