Hackers Attacking Check Point Remote Access VPN Devices to Breach Enterprise Networks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Check Point Software Technologies recently issued an advisory regarding an ongoing campaign by threat actors to breach enterprise networks by targeting Remote Access VPN devices. This development underscores the growing …

Hackers use the Greatness PaaS tool to Steal Microsoft 365 login credentials

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A new Phishing-as-a-Service (PaaS) tool called Greatness is being used by cybercriminals to steal Microsoft 365 login credentials. First detected in 2022, Greatness allows attackers to bypass security measures and …

Threats Actors Delivering Remcos RAT Distributed as UUE (Uuencoding) File

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

AhnLab Security Intelligence Center (ASEC) has confirmed the accuracy of the Remcos RAT malware being distributed through UUE (UUEncoding) files compressed with Power Archiver. This sophisticated method of malware distribution …

Hackers Advertising of Pulse Connect Secure VPN RCE 0-Day

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cybersecurity experts have identified a critical zero-day vulnerability in Pulse Connect Secure VPN, a widely used virtual private network solution. The vulnerability, which allows for remote code execution (RCE), has …

LangChain JS Framework Vulnerability Let Hackers Read Arbitrary File on Servers

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A security researcher uncovered a high-risk vulnerability in the popular LangChain JS framework that could allow attackers to read arbitrary files on servers running applications built with the framework. LangChain, …

Google Shares Details on Accidental File Deletion that Impacts Pension Fund’s Accounts

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

In a recent blog post, Google Cloud has shared details about an incident that impacted one of its Australian customers, UniSuper, a pension fund. The incident involved accidentally deleting the …

Indian National Pleads Guilty for $37 Million By Running Fake Coinbase’s Website

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Chirag Tomar, a 30-year-old citizen of the Republic of India, appeared before U.S. Magistrate Judge Susan C. Rodriguez today and pleaded guilty to federal charges for orchestrating a sophisticated spoofing …

Windows 10 PLUGScheduler Vulnerability Allows Privilege Escalation

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical vulnerability in the Windows 10 operating system, tracked as CVE-2024-26238, could allow attackers to gain elevated privileges on affected systems. The flaw resides in the PLUGScheduler component of …