RomCom Group Exploiting Microsoft Office 0-day To Deploy Ransomware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The Russian group RomCom, dubbed Storm-0978, distributes underground ransomware by leveraging the Microsoft Office and Windows HTML RCE zero-day vulnerability identified as CVE-2023-36884. This ransomware encrypts files on victims’ Windows …

Researchers Unpacked ViperSoftX Malware’s Evasion Tactics And Techniques

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Sophisticated threat actors, like those behind the ViperSoftX malware from 2020, often make use of existing tools to save time and resources.  ViperSoftX uses AutoIt, the CLR, and pre-made hacking …

Threat Actor Allegedly Claims Leak of BMW Customer Database

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A well-known threat actor identified as “888” has claimed responsibility for leaking sensitive customer data belonging to BMW Hong Kong. According to the Breachforums post, “888” has allegedly leaked sensitive …

Zyxel Critical Vulnerability Let Attackers Perform OS Command Injection

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Zyxel has issued patches to address a critical operating system (OS) command injection vulnerability identified as CVE-2024-7261. This vulnerability affects several versions of their access points (AP) and security routers. …

Hackers Abuse Red Team Tool MacroPack To Deliver Multiple Malicious Payloads

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

MacroPack is a convenient tool for creating obfuscated VBA malware, but it is still a risk even with the macro execution restricted in downloaded Office documents from Microsoft. This tool …

Travelers Beware of Sophisticated Booking.com Phishing Attack

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cybercriminals have launched a sophisticated phishing attack targeting Booking.com, one of the world’s leading online travel platforms. This attack, characterized by its complexity and high success rate, has been evolving …

Actively Exploited Android Zero-Day Elevation of Privilege vulnerability Patched

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Google has released a patch for a critical zero-day vulnerability, CVE-2024-32896, which was actively exploited in the wild. This vulnerability, classified as a high-severity elevation of privilege (EoP) flaw, was …

PoC Exploit Released for 0-Day Windows Kernel Privilege Escalation Vulnerability

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A proof-of-concept (PoC) exploit has been publicly released for a critical zero-day elevation of privilege vulnerability in the Windows kernel. The flaw, tracked as CVE-2024-38106, was one of several zero-days …

Blackwired Launches ThirdWatch℠, A Paradigm Shift in Cybersecurity

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Blackwired, the leading cyber observatory for disruptive cybersecurity technologies, has announced the launch of ThirdWatch℠, a groundbreaking solution to identify direct threats facing an organization and its Third Parties. ThirdWatch℠ …

YubiKeys cryptographic Flaw Let Attackers Clone Devices by Extracting Private Key

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Security researchers have uncovered a significant vulnerability in YubiKeys, specifically targeting the YubiKey 5 Series. This vulnerability, identified as a side-channel attack, allows attackers to clone these devices by extracting …