Supershell – Open-Source Botnet That Obtain SSH Shell Access

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The digital age offers opportunities but also increases the importance of cybersecurity as threats grow in complexity and sophistication, making preparedness a top priority. Open-source botnets are now a hot …

Threat Actors Deployed Hundreds of Python Packages to Steal System Data

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

In the open-source ecosystem, shadows shift as collaboration succeeds, attracting both novices and skilled threat actors. A rising threat has been evolving and sharpening its tools in recent months. Checkmarx …

Wireshark 4.0.10 Released: What’s New!

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Wireshark has been the most widely used open-source Network protocol analyzing tool for several purposes, including troubleshooting, analysis, development, and education. On their previous release of 4.0.9, CVE-2023-5371, associated with …

Top 10 SaaS Security Risks and How to Mitigate Them

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

SaaS, an acronym for Software as a Service, is a software distribution model that enables organizations to access and utilize ready-made software solutions. Rather than developing and customizing software in-house, …

Sony Breached Via MOVEit Zero-Day Vulnerability

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Sony Interactive Entertainment (SIE) discloses a cybersecurity breach caused by the exploitation of a zero-day vulnerability in Progress Software’s MOVEit Transfer platform. Nearly 6791 current and former workers or members of …

Malicious npm Package from a Twin Developers Deliver r77 Rootkit

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A malicious supply chain attack affecting the popular npm platform, often used for Node.js projects, has been identified.  This attack employs a tactic known as typosquatting, where malicious actors create …

EvilProxy Attacking Microsoft 365 Users Abusing Open Redirection With Indeed.com

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

EvilProxy Attacking Microsoft 365 Users Abusing Open Redirection With Indeed.com By Guru – October 5, 2023 A recent phishing campaign, identified by Menlo Labs, has been actively targeting executives in …

Qualcomm Sys Hackers Actively Exploit 3 new Zero-Days – Patch Now

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Three new zero days have been reported to Qualcomm, which were CVE-2023-33106, CVE-2023-33107, and CVE-2023-33063. These vulnerabilities were discovered as part of Google Project Zero and were disclosed to Qualcomm …

Microsoft Teams & Edge Zero-Day Vulnerabilities Leads to Code Execution

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Microsoft has addressed two zero-day vulnerabilities in two Open-Source Software security vulnerabilities, which include Microsoft Edge, Microsoft Teams for Desktop, Skype for Desktop, and Webp images extension. These vulnerabilities were …