Dior, a Louis Vuitton Brand, Alerts Customers Following Cyber Attack

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Christian Dior Couture, the luxury fashion house owned by Louis Vuitton, has begun notifying customers of a major cybersecurity incident that exposed sensitive personal information of clients.  The breach, discovered …

Microsoft Releases Mitigations and Threat Hunting Queries for SharePoint Zero-Day

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Thousands of organizations worldwide face active cyberattacks targeting Microsoft SharePoint servers through two critical vulnerabilities, prompting urgent government warnings and emergency patches. Microsoft confirmed over the weekend that threat actors …

Greedy Sponge Hackers Attacking Financial Institutions With Modified Version of AllaKore RAT

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A financially motivated threat group dubbed Greedy Sponge has been systematically targeting Mexican financial institutions and organizations since 2021 with a heavily modified version of the AllaKore remote access trojan …

DeerStealer Malware Delivered Via Weaponized .LNK Using LOLBin Tools

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated new phishing campaign has emerged, delivering the DeerStealer malware through weaponized .LNK shortcut files that exploit legitimate Windows binaries in a technique known as “Living off the Land” …

Threat Actors Hijack Popular npm Packages to Steal The Project Maintainers’ npm Tokens

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated supply chain attack has compromised several widely-used npm packages, including eslint-config-prettier and eslint-plugin-prettier, after threat actors successfully stole maintainer authentication tokens through a targeted phishing campaign. The attack …

Developers Beware of npm Phishing Email That Steal Your Login Credentials

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated phishing campaign has emerged targeting Node.js developers through a meticulously crafted attack that impersonates the official npm package registry. The malicious operation utilizes the typosquatted domain npnjs.com, substituting …

NailaoLocker Ransomware Attacking Windows Systems Using Chinese SM2 Cryptographic Standard

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

FortiGuard Labs has discovered a sophisticated new ransomware strain called NailaoLocker that represents a significant departure from conventional encryption malware. This Windows-targeting threat introduces the first documented use of China’s …

Threat Actors Leverage Zoho WorkDrive Folder to Deliver Obfuscated PureRAT Malware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cybercriminals have escalated their attack sophistication by utilizing legitimate cloud storage services to distribute advanced malware, as demonstrated in a recent campaign targeting a certified public accounting firm in the …

Microsoft’s AppLocker Flaw Allows Malicious Apps to Run and Bypass Restrictions

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical configuration flaw in Microsoft’s AppLocker block list policy has been discovered, revealing how attackers could potentially bypass security restrictions through a subtle versioning error.  The issue centers on …