Earth Koshchei Hackers Using Red Team Tools To Attack RDP Servers

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated cyber espionage campaign leveraging red team tools to exploit Remote Desktop Protocol (RDP) servers has been uncovered, with the threat actor Earth Koshchei (also known as APT29 and …

BADBOX Botnet Hacked 74,000 Android Devices With Customizable Remote Codes

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The BADBOX botnet, a sophisticated cybercriminal operation, has compromised approximately 74,000 devices, including Android TV boxes, smartphones, and other electronics. This malware is pre-installed on devices before they even reach …

Microsoft Sentinel Launched Agentless Integration for SAP Security

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

With critical SAP vulnerabilities being weaponized within 72 hours of a patch release, and unprotected SAP applications provisioned in cloud environments being discovered and compromised in under three hours, securing …

Beware Of Malicious SharePoint Notifications Delivering Xloader Malware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated phishing campaign exploiting fake Microsoft SharePoint notifications to distribute the Xloader malware. This malicious operation, recently intercepted by Sublime Security, highlights the growing threat of cybercriminals leveraging legitimate …

Hackers Exploit Google Calendar & Drawings to Bypass Email Security

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Google Calendar, with over 500 million active users worldwide and availability in 41 languages, has long been celebrated for its efficiency in organizing schedules and managing time. However, its popularity …

Google’s New XRefer Tool to Analyze More Complex Malware Samples

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Google’s Mandiant FLARE team has unveiled XRefer, a cutting-edge tool designed to streamline the complex process of malware analysis. This innovative plugin for IDA Pro aims to revolutionize how analysts …

CISA Issues Best Practices to Secure Microsoft 365 Cloud Environments

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The Cybersecurity and Infrastructure Security Agency (CISA) has released Binding Operational Directive (BOD) 25-01, mandating federal civilian agencies to enhance the security of their Microsoft 365 cloud environments. This directive …

New DDoS Malware “cShell” Exploit Linux Tools to Attack SSH Servers

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The AhnLab Security Intelligence Center (ASEC) has uncovered a new strain of DDoS malware, named cShell, targeting poorly managed Linux SSH servers (screen and hping3). The malware exploits weak SSH …

Apache Struts RCE Vulnerability Actively Exploited in Wild Using Public PoC

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical security vulnerability has been identified in Apache Struts, a popular open-source framework for building Java-based web applications actively used in attacks leveraging publish PoC that allows attackers to …

Azure Data Factory And Apache Airflow Integration Flaws Let Attackers Gain Write Access

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Researchers uncovered new security vulnerabilities in the Azure Data Factory Apache Airflow integration dubbed “Dirty DAG”, which allow attackers to get unauthorized write permissions to a directed acyclic graph (DAG) …