Hackers are Actively Exploiting Apache Struts 2 Vulnerability

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Hackers are taking advantage of a Critical Apache Struts Bug’s initial activity with limited IP addresses engaged in exploitation attempts. Apache is an open-source framework for creating Java EE web …

Rhadamanthys – A Fast-evolving Multi-layer Malware Sold on The Dark Web

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Threat actors make use of fast-evolving multi-layer malware for their complexity and sophistication, as they offer the ability to rapidly adapt and change their code. To make analysis and countermeasures …

Research Discovered 116 Malicious PyPI Packages Downloaded Over 10,000 Times

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A cluster of malicious Python projects has been identified in PyPI, the official Python PyPI package repository, which targets both Windows and Linux systems and often deploys a custom backdoor. In certain …

Multiple Flaws in Dell PowerProtect Products Let Attackers Execute OS Commands

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Multiple vulnerabilities have been discovered in Dell’s PowerProtect, which were associated with SQL injection, cross-site scripting (XSS), privilege escalation, command injection, and path tracing. The severity for these vulnerabilities ranges …

Engineering-assisted Dynamic Malware Analysis using GPT-4 With 100% Recall Rate

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A new prompt engineering-assisted Dynamic Malware Analysis model has been introduced, which can overcome the drawbacks faced in the quality API call sequences deployed for dynamic malware analysis.  This new …

Zoom Mobile and Desktop App Flaws Let Attackers Escalate Privileges

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The popular video conferencing software Zoom has security issues with its desktop and mobile apps that could allow for privilege escalation. An attacker may be able to obtain elevated privileges …

New Dark Web Market OLVX Advertising Variety of Hacking Tools 

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Threat actors exploit underground markets by purchasing or selling stolen data, malware, and hacking tools to facilitate cybercrime.  These underground markets provide the following key facilities among threat actors that …

Microsoft Seized Storm-1152 Websites Used to Sell Microsoft Products & Accounts

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Hackers sell fake Microsoft products and accounts because it allows them to profit from illicit activities, taking advantage of unsuspecting users. Microsoft’s security team, partnered with Arkose Labs, is cracking …