Microsoft Observed Huge-Surge In Attacks Targeting Internet-Exposed OT Devices In WWS

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Microsoft has reported a significant increase in cyberattacks targeting internet-exposed, poorly secured operational technology (OT) devices. These attacks have particularly focused on the United States’ water and wastewater systems (WWS). Various nation-backed actors, including the IRGC-affiliated “CyberAv3ngers” and pro-Russian hacktivists, …

RedTail Cryptominer Exploiting Palo Alto Networks Firewall Zero-day Flaw

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The RedTail cryptocurrency mining malware has been observed exploiting a critical zero-day vulnerability in Palo Alto Networks’ firewall software, PAN-OS. This vulnerability, tracked as CVE-2024-3400, has a CVSS score of 10.0, indicating its severity. The flaw allows unauthenticated attackers to …

BBC Data Breach: Hackers Access Cloud-Based Storage Service

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The BBC has confirmed a data security incident involving the personal information of some members of the BBC Pension Scheme. The breach, which was detected by the BBC’s information security team, involved unauthorized access to a cloud-based storage service where …

New Meterpreter Backdoor Hides Malicious Codes Within the Image

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

ANY.RUN sandbox has analyzed a new strain of Meterpreter backdoor malware that leverages sophisticated steganography techniques to conceal its malicious payload within an image file. The malware, dubbed “Meterpreter Backdoor,” is designed to evade detection by hiding its code in …

Beware of Free Piano Messages that Steal Personal & Financial Data

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Hackers target and steal personal and financial data for fraud and other illicit purposes. They also sell the data on the black market for profit.  They exploit this information to gain unauthorized access to bank accounts, credit cards, and other …

Mastermind Behind Biden Ai Deepfake Robocall Charged

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Attorney General John M. Formella announced today that Steven Kramer, age 54, of New Orleans, LA, has been indicted on charges of felony voter suppression and misdemeanor impersonation of a candidate. This indictment follows an extensive investigation into a series …

Operation Endgame: Authorities Seized IcedID, Pikabot, & Other Droppers

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Between May 27 and 29, 2024, a coordinated effort known as Operation Endgame, led by Europol, targeted a range of malicious software droppers, including IcedID, SystemBC, Pikabot, Smokeloader, Bumblebee, and Trickbot. This operation aimed to disrupt criminal services by arresting …

PoC Exploit Released for Microsoft Edge Information Disclosure Vulnerability

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cybersecurity researchers have released a Proof-of-Concept (PoC) exploit for a recently disclosed information disclosure vulnerability in Microsoft Edge, the Chromium-based web browser. The vulnerability, tracked as CVE-2024-30056, could allow unauthorized actors to access private user information, raising concerns about data …

Indian Stock Exchange BSE Starts Encrypting Messages to Traders

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The Bombay Stock Exchange (BSE) has begun encrypting messages sent to traders, becoming the first exchange in the world to implement such a system. The move aims to enhance security and protect sensitive information in the face of growing cyber …

911 S5 Botnet with 19 Million IP Addresses Dismantled & Admin Arrested

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The U.S. Department of Justice (DOJ) announced the dismantling of the 911 S5 botnet, a massive network of compromised computers used for various illegal activities. The operation carried out in cooperation with international law enforcement agencies, resulted in the apprehension …