Sharp Dragon Hackers Attacking Government Entities Using Cobalt Strike & Custom Backdoors

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The activities of the Chinese threat actor group known as Sharp Dragon (formerly Sharp Panda) have been meticulously documented. Since 2021, this group has been involved in highly targeted phishing campaigns, primarily focusing on Southeast Asia. However, recent developments indicate …

GenAI Bots Can Be Tricked by Anyone To Leak Company Secrets

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The introduction and widespread use of generative AI technologies such as ChatGPT has shown a new era for the world but comes with some unexplored cybersecurity risks. Prompt injection attacks are one form of manipulation that can happen with LLMs, …

New DoS Attack ‘DNSBomb’ Exploiting DNS Queries & Responses

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cybersecurity researchers have unveiled a new and potent Denial of Service (DoS) attack, dubbed “DNSBomb.” This attack leverages the inherent mechanisms of the Domain Name System (DNS) to create a powerful pulsing DoS attack that poses a significant threat to …

Ransomware Attacks Targeting VMware ESXi Infrastructure Adopt New Pattern

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cybersecurity professionals at Sygnia have noted a notable change in the strategies used by ransomware groups that are aiming at virtualized environments, specifically VMware ESXi infrastructure, in relation to development. The incident response team has noted a steady increase in …

Hackers Can Abuse Apple’s Wi-Fi Positioning System to Track Users Globally

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A recent study by security researchers has revealed a major privacy vulnerability in Apple’s Wi-Fi Positioning System (WPS) that allows hackers to track the locations of Wi-Fi access points and their owners globally. Researchers from the University of Maryland published …

Threat Actor Claiming Access to AWS, Azure, MongoDB & Github API Keys

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A threat actor has claimed to have gained unauthorized access to API keys for major cloud service providers, including Amazon Web Services (AWS), Microsoft Azure, MongoDB, and GitHub. The announcement was made via a post on the social media platform …

LastPass is Encrypting URLs Used with Password Vaults

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

LastPass, a widely used password manager trusted by millions of consumers and businesses globally, has announced an upgrade to its security measures, the encryption of URLs within its password vaults. This development is part of LastPass’s ongoing mission to protect …

End of VBScript! Microsoft Replacing it With Advanced Alternatives

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Microsoft has officially announced the gradual deprecation of VBScript, with plans to replace it with more advanced alternatives such as JavaScript and PowerShell. The move comes as part of Microsoft’s commitment to providing users with the best and most efficient …

WinRAR Flaw Let Attackers Deceive Users with ANSI Escape Sequences

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical vulnerability has been discovered in WinRAR, a popular file compression and archiving utility for Windows. The flaw, tracked as CVE-2024-36052, affects WinRAR versions prior to 7.00 and allows attackers to spoof the screen output using ANSI escape sequences. …

GHOSTENGINE Malware Exploits Vulnerable drivers To Terminate EDR Agents

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Researchers discovered REF4578, an intrusion set that uses vulnerable drivers to disable established security solutions (EDRs) for crypto mining and deploys a malicious payload known as GHOSTENGINE. GHOSTENGINE is in charge of locating and running the machine’s modules. To download …