DigiCert to Revoke Thousands of Certificates Following DNS Validation Error

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

DigiCert, a major certificate authority, to revoke thousands of SSL/TLS certificates because of a Domain Control Verification error. This could affect a lot of websites. The company discovered that an …

Proofpoint’s Email Protection Service Exploited to Send Millions of Phishing Emails

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A massive phishing campaign dubbed “EchoSpoofing” has exploited a critical vulnerability in Proofpoint’s email protection service, allowing cybercriminals to send millions of perfectly spoofed phishing emails impersonating major brands. The …

Ransomware Gangs Exploiting VMware ESXi Auth Bypass Flaw for Mass Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Microsoft researchers have found a critical vulnerability in VMware’s ESXi hypervisors. Ransomware operators are using this problem to attack systems. This vulnerability, CVE-2024-37085, allows threat actors to gain full administrative …

Phishing Threats and Cybersecurity 2024 : Protecting Personal and Organizational Data

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

As Americans engage in major activities such as the 2024 presidential race, large-scale cultural festivals, and high-profile sporting events, cybersecurity will be on high alert. Phishing attacks involve users through …

Beware of Malicious Mandrake Apps From Google Play With Over 32,000 Installs

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated Android spyware campaign known as Mandrake has resurfaced on the Google Play Store, infecting over 32,000 devices between 2022 and 2024. Mandrake has returned after a two-year break …

Operation ShadowCat Using Weaponized Office document To Attack Users In India

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Researchers identified a new attack campaign (“Operation ShadowCat”) using malicious LNK files distributed via spam emails, which triggers a PowerShell script that drops a .NET loader and a decoy Word …

Threat Actors Using OS Command Injection Vulnerabilities To Compromise Systems, CISA Warns

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

By exploiting OS command injection vulnerabilities, threat actors can run arbitrary commands on a host operating system to obtain unauthorized access, control, and the power to either corrupt or steal …

Hackers Exploiting MSHTML vulnerability to Deliver Atlantida Malware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Void Banshee, a threat actor, has been exploiting a critical MSHTML vulnerability, CVE-2024-38112, to distribute the Atlantida InfoStealer malware. This sophisticated campaign has targeted unsuspecting users by attracting PDF books …