300,000 Chinese Devices in US : 40% Increase Despite Official Bans

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Chinese devices are suspected of administering cyber espionage due to concerns over potential backdoors, supply chain vulnerabilities, and the risk of tampering.  State-sponsored cyber threats, such as viral memes, are …

Hackers Hijacking YouTube Channels to Steal Your Data

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cybercriminals are increasingly exploiting YouTube, a platform beloved by millions, to produce sophisticated malware attacks. These threat actors, leveraging the impression of free software and video game enhancements, target unsuspecting …

WordPress Plugin SQl Injection Exposes 1,000,000 Sites to Cyber Attack

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Over a million WordPress websites have been at risk due to a critical SQL Injection vulnerability discovered in the popular LayerSlider plugin. The flaw, CVE-2024-2879, could allow unauthenticated attackers to …

Feds Stepping to Patch Years-old SS7 Vulnerability in Phone Networks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The FCC (Federal Communications Commission) seeks public input regarding measures by communications providers to address vulnerabilities in SS7 and Diameter protocols that enable tracking consumers’ mobile device locations without consent. …

Aembit Selected as Finalist for RSA Conference 2024 Innovation Sandbox Contest

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The Leading Company for Securing Access Between Workloads Recognized for the Aembit Workload IAM Platform Aembit, the Workload Identity and Access Management (IAM) Company, has been named one of the …

‘The Manipulaters’ Improve Phishing, Still Fail at Opsec

Blog WriterCybersecurity News - Original News Source is krebsonsecurity.com

Roughly nine years ago, KrebsOnSecurity profiled a Pakistan-based cybercrime group called “The Manipulaters,” a sprawling web hosting network of phishing and spam delivery platforms. In January 2024, The Manipulaters pleaded …

WP-Members Plugin Expose WordPress Sites To Injection Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A security researcher reported a critical vulnerability in the WP-Members Membership Plugin that allows attackers to inject malicious scripts and potentially take over websites.  Administrators could take advantage of the …

StrelaStealer Attacking Users to Steal Logins from Outlook & Thunderbird

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated variant of StrelaStealer malware has been identified, targeting Spanish-speaking users with the primary aim of pilfering email account credentials from popular email clients Outlook and Thunderbird. This updated …