Beware Of Fake MetaMask Android Apps That Steal Login Details

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Threat actors exploit fake Android apps primarily for illicit reasons, such as stealing sensitive and personal information from unsuspecting users. Besides this, these fake apps often mimic legitimate ones to trick users into downloading and installing them from unofficial sources. …

CrushFTP Zero-Day Could Allow Attackers To Gain Complete Server Access

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

CrushFTP disclosed a zero-day vulnerability (CVE-2024-4040) affecting versions below 10.7.1 and 11.1.0. The vulnerability allows remote attackers with low privileges to bypass the VFS sandbox and read arbitrary files on the underlying filesystem.  It could be exploited for server-side template …

IBM QRadar XSS Flaw Let Attackers Arbitrary JavaScript Code

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A significant vulnerability was detected in IBM QRadar Suite Software and Cloud Pak for Security, allowing attackers to execute arbitrary JavaScript code. An attacker can insert harmful executable scripts into the code of a reliable program or website via stored …

Seedworm Hackers Exploit RMM Tools to Deliver Malware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The notorious hacking group Seedworm, also known as MuddyWater, has been found exploiting legitimate remote monitoring and management (RMM) tools to orchestrate sophisticated malware attacks. This revelation underscores a significant shift in cybercriminals’ tactics, with them leveraging trusted software to …

WordPress Plugin Flaw Exposes 10k+ Websites to Cyber Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical vulnerability in the WP Datepicker WordPress plugin was identified, affecting over 10,000 active installations.  This Arbitrary Options Update vulnerability (CVE-2024-3895) has been assigned a CVSS score of 8.8, indicating a high severity level. CVE-2024-3895: Arbitrary Options Update Vulnerability …

Beware! Notorious Samurai Stealer Used in Targeted Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A new type of malware, the “Samurai Stealer,” has been identified in a series of targeted attacks. This malicious software is reportedly designed to infiltrate systems, steal sensitive information, and evade detection with alarming sophistication. How the “Samurai Stealer” Operates …

Russian Hackers Claim Responsibility for Cyber Attack on Indiana Water Plant

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

In a recent cybersecurity incident, a group of Russian-speaking hackers claimed responsibility for a cyber attack on a wastewater treatment plant in Tipton, Indiana. The attack, which occurred on Friday evening, was part of a broader pattern of similar incidents …

AI-Based Brute-Forcing Attack Outperforming Probabilistic Model

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Web Vulnerability Assessment and Penetration Testing (Web VAPT) aims to identify vulnerabilities in web apps. However, current wordlist-based methods are ineffective since directory brute-forcing attacks can establish reachable directories. Offensive AI is the integration of AI technology to enhance cyber …

Russian Hackers Launched Sabotage Attacks On 20 Critical Infrastructure

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Researchers identified a cyberattack by the Sandworm group targeting critical infrastructure in Ukraine in March 2024. The attack aimed to disrupt the information and communication systems (ICS) of energy, water, and heat suppliers across ten regions.  In addition to the …

Hackers Weaponized Electron Framework to Steal Data Stealthy

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Hackers abuse Electron Framework’s cross-platform desktop app capabilities, which are based on web technologies like HTML, JS, and CSS.  The flexibility and widespread adoption of the Electron Framework enables the creation of several malicious programs cross-OS.  Cybersecurity researchers at ASEC …