Hillstone WAF Vulnerability Let Attackers Execute Command Injection Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The Hillstone WAF is designed to provide enterprise-class security for web servers, applications, and APIs from various cyber threats. It uses both traditional rules-based detection and innovative semantic analysis in …

Stealthy Linux Malware ‘Sedexp’ Having Zero-detections Since 2022

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Hackers often abuse Linux malware since Linux systems are widely used in critical servers and infrastructure for their operation. By exploiting vulnerabilities in Linux threat actors can gain complete control …

ValleyRAT Malware Attack Windows Systems Using Weaponised Microsoft Office Doc

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Researchers at ANY.RUN uncovered a sophisticated attack targeting Chinese-speaking users. The attack is spreading multi-stage malware known as ValleyRAT, which is designed to infiltrate systems and establish persistent backdoors, allowing attackers to …

Beware of WhatsApp Verification Code Attacks that Steal Payments

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The National Cyber Security Centre (NCSC) of Ireland has warned about a growing trend of WhatsApp verification code scams targeting users. These scams are not only compromising personal accounts but …

Iranian Hacking Group APT42 Attack WhatsApp Users

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Facebook’s security teams recently blocked a small cluster of WhatsApp accounts posing as tech companies’ support agents after investigating user reports. The malicious activity, which originated in Iran, attempted to …

What is Cyber Threat Intelligence (CTI) – How it Works?

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cyber Threat Intelligence (CTI), also known as Threat Intelligence or Threat Intelligence, is a critical practice in cybersecurity. It involves gathering and analyzing data to identify, understand, and counteract existing …

Russian Cybercrime Group Member Charged for Hacking Computers Around Globe

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Deniss Zolotarjovs, 33, from Moscow, Russia, was charged with federal crimes in the U.S. District Court in Cincinnati today. A member of a notorious Russian cybercrime group, Zolotarjovs, was indicted …

Traccar GPS System Vulnerability Let Attackers Execute Remote Code

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Two critical vulnerabilities have been discovered in the Traccar GPS. These vulnerabilities, CVE-2024-31214 and CVE-2024-24809, allow unauthenticated attackers to execute remote code on systems running Traccar 5. This article delves …

D(HE)at Attack – 20-Yr-old Flaw Let Attackers Exploit Diffie-Hellman Protocol To Over-Heat Your CPU

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Researchers uncovered a new type of denial-of-service (DoS) attack, known as the D(HE)at attack, exploits the computational demands of the Diffie-Hellman key agreement protocol, particularly its ephemeral variant (DHE), to …