LockBit Gang Money Flow Uncovered : New Strain Under Development

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Over the past few years, LockBit, a ransomware-as-a-service (RaaS) operation, has been linked to multiple security incidents affecting organizations worldwide. Yet, they appear to have experienced a lot of logistical, …

ScreenConnect Security Flaw Exploited In The Wild By Attackers

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The ScreenConnect software is a popular choice for remote access among organizations worldwide. However, recent vulnerabilities have raised concerns about potential exploitation by attackers. Specifically, these vulnerabilities could allow attackers to …

New SSH-Snake Malware Abuses SSH Credentials To Spread Itself In The Network

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Threat actors abuse SSH credentials to gain unauthorized access to systems and networks. By exploiting weak or compromised credentials, they can execute malicious activities. SSH credential abuse provides a stealthy …

Russian Government Software Hijacked to Install Konni RAT

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical cybersecurity incident recently occurred where the Konni Remote Access Trojan (RAT), a highly covert and sophisticated malware that specializes in data exfiltration, infiltrated the software systems of the …

Apple Adds PQ3 post-quantum Encryption for iMessage

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Apple has released its new PQ3 (post-quantum) cryptographic protocol, claimed to be the first-ever messaging protocol to reach Level 3 security. Apple announced its cryptographic protocol change in 2019 when …

Hackers launched 250,000+ Attacks to Exploit Ivanti VPN 0-Day

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Ivanti Connect Secure vulnerabilities were disclosed in January 2024 as a potential gateway for threat actors to penetrate corporate networks. The two vulnerabilities, CVE-2023-46805 and CVE-2024-21887 were associated with authentication …

Hackers Heavily Abusing Google Cloud Run to Deliver Banking Malware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Large-scale malware distribution campaigns are abusing Google Cloud Run to transmit banking trojans, including Astaroth (also known as Guildma), Mekotio, and Ousaban, to European and Latin American targets. With Cloud …

VoltSchemer – Wireless Charger Attack Boils Phone and Injects Voice Commands

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Threat actors target wireless chargers for multiple malicious activities, such as implanting malware or conducting power-related attacks. The rising popularity of wireless charging brings convenience. Still, recent research by Zihao …