Hackers Infiltrated 9-days Within UnitedHealth Network Before Ransomware Attack

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Andrew Witty, CEO of UnitedHealth Group, detailed a sophisticated ransomware attack on Change Healthcare, a key component of the UnitedHealth network. The cybercriminals, identifying themselves as ALPHV or BlackCat, infiltrated Change Healthcare’s information technology environments, marking a significant cybersecurity breach …

Malware Cuckoo – Previously Unknown Infosteler Spyware Steals Data From MacOS

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Security researchers have uncovered a previously undetected malware threat for macOS that exhibits characteristics of both an infostealer and spyware. Dubbed “Cuckoo” after the brood parasitic bird, this malicious code infiltrates systems and steals resources for its own gain. The …

Postman API Testing Platform Flaw Exposes Sensitive Credentials

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Truffle Security Co. has recently discovered a major vulnerability in Postman, the widely used API testing platform. This flaw exposed over 4,000 active credentials, creating serious security concerns for the impacted individuals or organizations. This vulnerability has positioned Postman as …

Millions of Docker Hub Repositories Found Pushing Malware for Over 5 Years

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

It has been found that almost one-fifth of the repositories on Docker Hub, a popular platform for developers to store and share containerized applications, have been exploited to spread malicious software and phishing scams. This is a concerning discovery for …

Investigating Two TeamCity Authentication Bypass Vulnerabilities

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Vulnerability exploits are the third most common way that cybercriminals gain access to target organizations, surpassed only by credential stealing and phishing in 2023. Once illicit access is achieved, intruders can launch ransomware attacks, exfiltrate sensitive data for sale in …

Threat Actors Claiming of 0-Day Vulnerability in Zyxel VPN Device

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Threat actors have claimed to have discovered a 0-day vulnerability in Zyxel VPN devices. This revelation was made public through a tweet by the cybersecurity monitoring group MonThreat, which has been closely tracking and reporting on various cyber threats. As …

Muddling Meerkat Using DNS As A Powerful Weapon For Sophistication

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Hackers exploit DNS vulnerabilities to redirect users to malicious websites, launch distributed denial-of-service (DDoS) attacks by overwhelming DNS servers, and manipulate domain resolutions to intercept traffic for surveillance or data theft purposes. Infoblox researchers recently revealed “Muddling Meerkat,” a highly …

Pathfinder – New Attack Steals Sensitive Data From Modern Processors

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Microarchitectural side-channel attacks misuse shared processor state to transmit information between security domains.  Although they can be used in isolation, they are frequently employed as building blocks for more sophisticated attacks such as Spectre, which uses side channels to achieve …

Beware of New Android Trojan That Executes Malicious Commands on Your Phone

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cybersecurity researchers at XLab have uncovered a new Android malware strain called “Wpeeper.” This sophisticated backdoor Trojan has been designed to infiltrate Android systems and execute a wide range of malicious commands, posing a significant threat to unsuspecting users. Wpeeper’s …

Authorities Seized Platform Used For Paid DDoS

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

On April 17, 2024, a joint effort between the Dresden Public Prosecutor’s Office and the Cybercrime Competence Center of the Saxony State Criminal Police Office, in collaboration with a U.S. investigative agency, won significantly in the ongoing battle against cybercrime.  …