NailaoLocker Ransomware Attacking Windows Systems Using Chinese SM2 Cryptographic Standard

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

FortiGuard Labs has discovered a sophisticated new ransomware strain called NailaoLocker that represents a significant departure from conventional encryption malware. This Windows-targeting threat introduces the first documented use of China’s …

Threat Actors Leverage Zoho WorkDrive Folder to Deliver Obfuscated PureRAT Malware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cybercriminals have escalated their attack sophistication by utilizing legitimate cloud storage services to distribute advanced malware, as demonstrated in a recent campaign targeting a certified public accounting firm in the …

Microsoft’s AppLocker Flaw Allows Malicious Apps to Run and Bypass Restrictions

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical configuration flaw in Microsoft’s AppLocker block list policy has been discovered, revealing how attackers could potentially bypass security restrictions through a subtle versioning error.  The issue centers on …

Surveillance Company Using SS7 Bypass Attack to Track the User’s Location Information

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A surveillance company has been detected exploiting a sophisticated SS7 bypass technique to track mobile phone users’ locations. The attack leverages previously unknown vulnerabilities in the TCAP (Transaction Capabilities Application …

APT41 Hackers Leveraging Atexec and WmiExec Windows Modules to Deploy Malware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The notorious Chinese-speaking cyberespionage group APT41 has expanded its operations into new territories, launching sophisticated attacks against government IT services across Africa using advanced Windows administration modules. This represents a …

Dell Data Breach – Test Lab Platform Hacked by World Leaks Group

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Dell Technologies has confirmed a security breach of its Customer Solution Centers platform by the World Leaks extortion group, marking another high-profile attack by the newly rebranded threat actor.  The …

CISA Warns of Microsoft SharePoint Server 0-Day RCE Vulnerability Exploited in Wild

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

CISA has issued an urgent warning about a critical zero-day remote code execution vulnerability affecting Microsoft SharePoint Server on-premises installations that threat actors are actively exploiting in the wild. The …

Lighthouse Studio RCE Vulnerability Let Attackers Gain Access to Hosting Servers

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical remote code execution vulnerability has been discovered in Lighthouse Studio, one of the most widely deployed yet relatively unknown survey software platforms developed by Sawtooth Software. The flaw, …