CoreWarrior Malware Attacking Windows Machines With Self-replication Capabilities

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Malware targeting Windows machines continues to be a significant threat. While these threats could be in various forms like viruses, worms, and ransomware. These malicious programs can infiltrate systems via …

OilRig Hackers Exploiting Microsoft Exchange Servers To Steal Login Details

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

OilRig hackers (aka Earth Simnavaz, APT34, OilRig) is a cyber espionage group that was linked to “Iranian” interests. This APT group primarily targets energy, governmental, and critical infrastructure sectors. Cybersecurity …

Popular Java Framework pac4j Vulnerable To RCE Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical security vulnerability has been identified in the popular Java security framework, pac4j, specifically affecting versions prior to 4.0. This vulnerability tracked as CVE-2023-25581, allows for remote code execution …

TrickMo Malware Attacking Android Devices To Steal Unlock Patterns & PINs

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

TrickMo is a sophisticated malware that emerged as a “banking Trojan”, and this malware is designed to steal “financial credentials” and “personal information.” Besides this, it has a history of …

Gmail Users Beware Of AI Scam that Takeovers Your Gmail Account

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated new scam targeting Gmail users has emerged, using artificial intelligence to trick victims into surrendering control of their accounts. This “super realistic AI scam call” combines fake account …

Hackers Selling ProKYC Tools To Bypass Two-Factor Authentication

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

2FA enhances security by requiring two distinct forms of identification before granting access to an account or service. Though 2FA reduces the risk of unauthorized access, it’s not completely error-free. …

Apache Roller CSRF Vulnerability Let Attackers Escalate privileges

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The Apache Roller team revealed a critical security update addressing a Cross-Site Request Forgery (CSRF) vulnerability that could allow attackers to escalate privileges. This vulnerability, present in previous versions of …

North Korean Posing as Recruiters to Attack Job Seekers Device

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Hackers target job seekers primarily for financial gain and to obtain sensitive personal information.  Many job seekers are vulnerable due to their enthusiasm for finding employment, which exposes them to …

Zendesk Email Spoofing Flaw Let Attackers Gain Access To Support Tickets

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A severe vulnerability in Zendesk, a widely used customer service tool, has been exposed, allowing attackers to gain unauthorized access to sensitive support tickets of numerous Fortune 500 companies. The …

GitHub Enterprise Server Vulnerability Allows Authentication Bypass

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical vulnerability has been identified in GitHub Enterprise Server, posing significant security risks by allowing attackers to bypass authentication mechanisms. This flaw, tracked as CVE-2024-9487, was discovered in the …