Over 10 Million Personal And Corporate Devices Infected By Information Stealers

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Kaspersky has reported that nearly 10 million personal and corporate devices were compromised by data-stealing malware in 2023, marking a staggering 643% increase over the past three years. This alarming …

Hackers Exploiting Roundcube XSS Vulnerability To Steal Login Credentials

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Security researchers have uncovered a new phishing campaign targeting users of the popular open-source Roundcube webmail software. Unknown threat actors are exploiting a now-patched cross-site scripting (XSS) vulnerability to steal …

Hackers Mimic As  ESET To Attack Organizations With Wiper Malware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Hackers impersonated ESET, a prominent cybersecurity firm, to attack organizations with destructive wiper malware. The attack, which began on October 8, 2024, involved a phishing campaign that exploited ESET’s brand …

New AI Tool to Discover 0-Days at Large Scale with a Click of a Button

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A new AI tool named Vulnhuntr has been introduced, revolutionizing the way vulnerabilities are discovered in open-source projects. This innovative tool leverages the power of large language models (LLMs) to …

Internet Archive Breached Again, Hackers Exploited Unrotated API Tokens

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The Internet Archive has fallen victim to another cyberattack, marking the third major security incident in October 2024. On October 20, hackers successfully exploited unrotated API tokens to gain unauthorized …

Cisco Investigating Cyber Security Incident, Takes DevHub Portal Offline

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cisco, has launched an investigation into a potential cyber security incident and has taken its public DevHub portal offline as a precautionary measure. On October 18, 2024, the company confirmed …

Brazil Arrests ‘USDoD,’ Hacker in FBI Infragard Breach

Blog WriterCybersecurity News - Original News Source is krebsonsecurity.com

Brazilian authorities reportedly have arrested a 33-year-old man on suspicion of being “USDoD,” a prolific cybercriminal who rose to infamy in 2022 after infiltrating the FBI’s InfraGard program and leaking …

Bitdefender Total Security Vulnerability Exposes Users to Man-in-the-Middle Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Bitdefender Total Security has been found vulnerable to Man-in-the-Middle (MITM) attacks due to improper certificate validation in its HTTPS scanning functionality. This vulnerability, identified under multiple CVEs, poses a serious …

Vulnerabilities In WebRTC Implementations Let Attackers Trigger DoS Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

WebRTC (Web Real-Time Communication) is an open-source project that facilitates real-time audio, video, and data sharing directly between web browsers and mobile applications without the need for plugins. Its integration …