Check Point VPN Zero-Day Vulnerability Exploited in Wild to Gain Remote Access

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Check Point, a leading cybersecurity vendor, has released emergency patches to address a critical zero-day vulnerability in its VPN products that threat actors have actively exploited. The vulnerability, tracked as CVE-2024-24919, allows attackers to gain unauthorized access to sensitive information …

Virustotal Shares New Ideas to Track Threat Actors

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

In a recent presentation at the FIRST CTI in Berlin and Botconf in Nice, VirusTotal unveiled innovative methods to track adversary activity by focusing on images and artifacts used during the initial stages of the kill chain. This approach aims …

Foxit PDF Reader and Editor Flaw Let Attackers Escalate Privilege

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Foxit PDF reader has been discovered with a new privilege escalation vulnerability that allows a low-privileged user to escalate their privileges. This vulnerability has been assigned with CVE-2024-29072 and the severity has been given as 8.2 (High). This vulnerability affects …

Moonstone Sleet New North Korean Hacker Group With Unique Tricks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Microsoft has identified a new North Korean threat actor, now tracked as Moonstone Sleet (formerly Storm-1789). This actor uses a combination of many tried-and-true techniques used by other North Korean threat actors and unique attack methodologies to target companies for …

Hackers Weaponizing Microsoft Office Documents to Deploy Malware in Business Environments

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Microsoft Office allows one to generate a professional business report on office365 or write college essays, prepare CVs, take notes, and perform analysis.  These offer text and data editing, like macros and Python scripting in Excel, that enable automatic data …

U.S. Sanctions Cybercrime Network Behind Massive Residential Proxy Bothnet Service

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The United States has imposed sanctions on a cybercrime network responsible for operating a massive residential proxy botnet service to combat cybercrime. This network, 911.re, has been implicated in various illicit activities. It leverages residential IP addresses to anonymize malicious …

Citrix Workspace app Let Attackers Elevate Privileges From Local User to Root User

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical security vulnerability has been identified in the Citrix Workspace app for Mac, potentially allowing attackers to elevate their privileges from a local authenticated user to a root user. This vulnerability tracked as CVE-2024-5027, poses a significant risk to …

Hackers Claim Ticketmaster Data Breach: 560M User Details and Payment Card Exposed

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

In a dramatic turn of events, hackers have claimed a massive data breach involving Ticketmaster, allegedly exposing the details of 560 million users and their payment card information. This claim has catapulted BreachForums into the spotlight, providing the platform with …

Russian Hackers Charged For Selling Unauthorized Access To Computer Networks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A Russian citizen has been indicted for working as an “access broker” and selling unauthorized access to computer networks, including a victim company in New Jersey, U.S. Attorney Philip R. Sellinger, District of New Jersey, announced. Details of the Indictment …

PoC Exploit Released for Critical Fortinet FortiSIEM Command Injection Vulnerability

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A proof-of-concept (PoC) exploit has been released for a critical vulnerability in Fortinet’s FortiSIEM. The vulnerability, CVE-2024-23108, allows for remote, unauthenticated command execution as root. This article delves into the details of the vulnerability, its discovery, and its implications for …