Threat Actors Use Abnormal Certificates to Deliver Info-stealing Malware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Malicious certificates can be highly dangerous as they can be used to deceive users into trusting malicious websites or software. This can lead to various security threats, including:- Data breaches …

‘Ransomed.Vc’ Group Attacking Japanese Giants in New operations

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

In the ever-evolving cyber threat landscape, Ransomed.vc, a ransomware syndicate with a rapidly growing reputation on the Dark Web, has once again made headlines. This time, their target is Japan’s telecommunications …

OPNsense Firewall Flaws Let Attackers Employ XSS to Escalate Privileges

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

OPNsense is a firewall and routing platform that is based on FreeBSD. It is open-source, making it freely available for use. Additionally, OPNsense is designed to be user-friendly, with a …

ZenRAT Malware Delivered Through Fake Bitwarden Installation Packages

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

According to the recent findings by Proofpoint, a new malware called ZenRAT has been discovered. This malware is being spread via fraudulent download packages disguised as Bitwarden installations. This malware …

BlackTech APT Hackers Attacking Network Routers to Breach Corporate Networks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Hackers called BlackTech APT have been doing bad things since 2010. They attack places like the government, factories, technology, media, electronics, phones, and the military. The group behind the attack …

Google Given Max Severity Score for lipwebp Zero-day Exploited in Wild

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Google released a security fix for a critical vulnerability that affected Google Chrome for Windows, macOS, and Linux. The vulnerability was given the CVE ID as CVE-2023-4863 and has been …

Exela Stealer Attacking Discord Users to Steal Login Credentials

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Open-source data stealers are rapidly gaining popularity due to their versatility, giving threat actors useful reconnaissance tools for malicious objectives. Open-source data stealers can be stealthy if designed and configured …

ShadowSyndicate: A New Raas Provider Launching Multiple Ransomware Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A new Ransomware-as-a-service (RaaS) provider has been discovered by researchers, which notably uses multiple ransomware families and is found to have links with several ransomware attacks since July 2022. This …