Multiple Vulnerabilities In Veritas Enterprise Vault Let Attackers Execute Remote Code

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Multiple critical vulnerabilities were identified by the Veritas Technologies in its Enterprise Vault software that allows attackers to execute remote code on affected servers. These vulnerabilities, disclosed on November 15, …

North Korean IT Workers Mimic as US Organizations for Job Offers

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

North Korea has established a global network of highly skilled IT workers who pose as professionals from other countries to secure remote jobs and freelance contracts with businesses worldwide. These …

Hackers Abuse URL Rewriting In Sophisticated Phishing Attack

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cybercriminals have found a new way to exploit email security measures, turning them into tools for their malicious activities. Since mid-June 2024, threat actors have been increasingly abusing URL rewriting …

Critical 7-Zip Vulnerability Let Attackers Execute Arbitrary Code

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A severe security vulnerability has been discovered in 7-Zip, the popular file compression utility, allowing remote attackers to execute malicious code through specially crafted archives. The vulnerability tracked as CVE-2024-11477 …

Nearest Neighbor Attack: Hackers Breach Organizations via Wi-Fi from Russia

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Russian state-sponsored hacking group GruesomeLarch (also known as APT28 or Fancy Bear) has demonstrated a sophisticated new attack technique dubbed the “Nearest Neighbor Attack,” which allows remote hackers to breach …

Russian TAG-110 Attacking Users With HATVIBE And CHERRYSPY Hacking Tools

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

TAG-110, a threat group affiliated with Russia, is conducting an ongoing cyber-espionage effort targeting Central Asia, East Asia, and European organizations. The group mainly targets government agencies, human rights organizations, …

Microsoft Seizes 240 Domains Used By phishing-As-A-Service (PhaaS) Platform

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The Digital Crimes Unit (DCU) of Microsoft has taken down 240 fraudulent websites that were utilized by the Egyptian phishing-as-a-service operation “ONNX.” Abanoub Nady, also known online as “MRxC0DER,” created …

Microsoft Shares Intelligence On North Korean & Chinese Hackers At CYBERWARCON

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Microsoft Threat Intelligence analysts are presenting groundbreaking research on North Korean and Chinese hacking activities, shedding light on years of threat actor tracking, infrastructure monitoring, and attacker tooling analysis at …

CISA Warns of Apple & Oracle Agile Vulnerabilities Exploited in Wild

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent advisory regarding three critical vulnerabilities affecting Apple and Oracle products. These flaws, identified as CVE-2024-44308, CVE-2024-44309, and CVE-2024-21287, have …

Multiple D-Link End-of-Life Routers Vulnerabilities Let Attackers Execute Remote Code

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

D-Link, a prominent networking hardware manufacturer, has issued a critical security advisory urging users to retire and replace several end-of-life VPN router models due to a severe remote code execution …