MuddyWater Hackers Abusing Legitimate RMM Tool to Deliver Malware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The Iranian state-sponsored threat actor MuddyWater has been observed exploiting a legitimate remote monitoring and management (RMM) tool, Atera Agent, to conduct a sophisticated malware delivery campaign. This alarming trend …

PoC Exploit Released For Critical Flowmon Vulnerability

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Progress addressed a critical vulnerability last week, which was associated with an unauthenticated Command injection on the Progress Flowmon product. This vulnerability was assigned CVE-2024-2189, and the severity was given …

Chrome Critical Flaw Let Attackers Execute Arbitary Code : Patch Now

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Google announced the release of Chrome 124, which fixes four vulnerabilities, including a critical security issue that allows attackers to execute arbitrary code. Over the next few days or weeks, the …

Hackers Exploit Google Ads to Spread IP Scanner with Concealed Backdoor

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Malicious actors are distributing a new backdoor, MadMxShell, through a Google Ads campaign that impersonates an IP scanner. This Windows backdoor leverages DNS MX queries for communication with its command-and-control …

Hackers Employ Black Hat SEO Techniques To Deliver Malware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Hackers use black hat SEO methods to manipulate search engine rankings and make malicious or fraudulent websites more visible. Recently, Zscaler cybersecurity researchers have seen a wave of fraudulent sites …

GitLab High-severity Flaw Let Attackers Takeover Account – Update Now

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

GitLab released security patches 16.11.1, 16.10.4, and 16.9.6 for both Community and Enterprise Editions, and upgrading to these versions is strongly recommended to address vulnerabilities.  Scheduled patch releases occur twice …