Ghost Tap Attack, Hackers Stolen Credit Card Linked To Google Pay Or Apple Pay

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Threat actors are actively using a new cash-out technique called “Ghost Tap” to cash out money using credit card information that has been stolen and connected to mobile payment services …

Critical AnyDesk Vulnerability Let Attackers Uncover User IP Address

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical vulnerability in AnyDesk, a popular remote desktop application, has been discovered that could allow attackers to expose users’ IP addresses. The flaw, identified as CVE-2024-52940, affects AnyDesk versions …

Gelsemium APT Hackers Attacking Linux Servers With New WolfsBane Malware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A new Linux backdoor named WolfsBane has been recently uncovered by the ESET researchers, attributed to the Gelsemium advanced persistent threat (APT) group. This discovery marks the first public report …

10-Year Old Flaws In Ubuntu Server needrestart Package Let Attackers Gain Root Access

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The cybersecurity community is on high alert following the discovery of five critical Local Privilege Escalation (LPE) vulnerabilities in the needrestart component, a default package in Ubuntu Server. These flaws, …

CISA Warns of VMware VCenter Vulnerabilities Actively Exploited in Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The Cybersecurity and Infrastructure Security Agency (CISA) has issued a critical warning regarding two newly discovered vulnerabilities in VMware’s vCenter Server. These vulnerabilities, identified as CVE-2024-38812 and CVE-2024-38813, have the …

Authorities Charged 5 Hackers For Attacking Companies via Phishing Text Messages

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Federal authorities have unveiled criminal charges against 5 individuals accused of directing a sophisticated phishing scheme targeting employees of companies across the United States. The defendants allegedly used stolen credentials …

Malicious PyPi Package Mimic ChatGPT & Claude Steals Developers Data

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Kaspersky’s Global Research and Analysis Team (GReAT) has recently uncovered a sophisticated supply chain attack targeting the Python Package Index (PyPI). The attack, which remained undetected for nearly a year, …

Critical Kubernetes Vulnerability Let Attackers Execute Arbitrary Commands

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A high-severity security vulnerability in Kubernetes has been discovered, potentially allowing attackers to execute arbitrary commands beyond container boundaries. The vulnerability has been tracked as CVE-2024-10220, affects Kubernetes clusters using …

macOS WorkflowKit Race Vulnerability Let Malicious Apps Intercept Shortcuts

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical vulnerability in macOS WorkflowKit, the framework underpinning Apple’s Shortcuts app, has been disclosed. This vulnerability allows malicious applications to intercept and modify user-imported shortcuts. Identified as CVE-2024-27821, this race …