APT Hackers Exploiting Zero-Day Vulnerabilities in WPS Office

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

ESET researchers have uncovered two critical zero-day vulnerabilities in WPS Office for Windows, exploited by the advanced persistent threat (APT) group APT-C-60. This South Korea-aligned cyberespionage group has been targeting …

HZ Rat Attacking macOS Users Via Messaging Platform WeChat

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Hackers target macOS as its growing user base makes it an increasingly attractive target.  Despite its reputation for strong security, macOS vulnerabilities exist, and exploiting them can give hackers access …

CISA & FBI Details Phishing Techniques Used by Malicious Hackers

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The Cybersecurity and Infrastructure Security Agency (CISA) and the Federal Bureau of Investigation (FBI) have detailed the latest phishing techniques of malicious hackers. This joint guidance aims to equip organizations …

Hacking a Bicycle: Vulnerabilities Exploited in Wireless Gear-Shifting Systems

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Researchers have uncovered significant cybersecurity vulnerabilities in the wireless gear-shifting systems of high-end bicycles, particularly those using Shimano’s Di2 technology. This revelation has sent shockwaves through the professional cycling community, …

Critical SQL Injection Vulnerability Discovered in Fortra FileCatalyst Workflow

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Fortra has urgently released patches to address two critical SQL injection vulnerabilities in its FileCatalyst Workflow software, identified as CVE-2024-6632 and CVE-2024-6633. If exploited, these vulnerabilities could severely compromise the …

Chinese Hackers Exploited Versa Director Zero-Day to Target IT Sectors, CISA Warns

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Chinese state-sponsored threat actors have been exploiting a zero-day vulnerability in Versa Director servers, identified as CVE-2024-39717. This vulnerability, discovered by Black Lotus Labs at Lumen Technologies, has been actively …

Research Unveils Eight Android & iOS That Leaks User’s Sensitive Data

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The eight Android and iOS apps fail to adequately protect user data, which transmits sensitive information, such as device details, geolocation, and credentials, over the HTTP protocol instead of HTTPS.  …