Hackers Uses Social Engineering Attack to Gain Remote Access in 300 Seconds

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Threat actors successfully compromised corporate systems within just five minutes using a combination of social engineering tactics and rapid PowerShell execution.  The incident, investigated by NCC Group’s Digital Forensics and …

New Microsoft Exchange Server Vulnerability Enables Attackers to Gain Admin Privileges

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical security vulnerability in Microsoft Exchange Server hybrid deployments has been disclosed, allowing attackers with on-premises administrative access to escalate privileges to cloud environments without easily detectable traces. The …

Akira and Lynx Ransomware Attacking Managed Service Providers With Stolen Login Credential and Vulnerabilities

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Two sophisticated ransomware operations have emerged as significant threats to managed service providers (MSPs) and small businesses, with the Akira and Lynx groups deploying advanced attack techniques that combine stolen …

Lazarus Hackers Trick Users To Believe Their Camera or Microphone is Blocked to Deliver PyLangGhost RAT

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cybersecurity researchers have observed a new social engineering campaign attributed to North Korea’s Lazarus Group in recent weeks that leverages fake camera and microphone errors to force targets into running …

Threat Actors Weaponize Smart Contracts to Drain User Crypto Wallets of More Than $900k

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

In a sophisticated campaign uncovered in early 2024, cybercriminals have begun distributing malicious Ethereum smart contracts masquerading as lucrative trading bots. These weaponized contracts leverage Web3 development platforms such as …

Mustang Panda Attacking Windows Users With ToneShell Malware Mimic as Google Chrome

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated new cyber campaign has emerged targeting Windows users through a deceptive malware variant known as ToneShell, which masquerades as the legitimate Google Chrome browser. The advanced persistent threat …

UAC-0099 Hackers Weaponizing HTA Files to Deliver MATCHBOIL Loader Malware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The Ukrainian threat intelligence group UAC-0099 has significantly evolved its cyber warfare capabilities, deploying a sophisticated new malware toolkit targeting Ukrainian state authorities, Defense Forces, and defense industrial enterprises. The …

Google’s Salesforce Instances Hacked in Ongoing Attack: Hackers Exfiltrate User Data

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Google has confirmed that one of its corporate Salesforce instances was compromised in June by the threat group tracked as UNC6040. This incident is part of a Salesforce attack campaign …

WhatsApp’s New Security Feature Allows Users to Pause, Question, and Verify Malicious Messages

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

WhatsApp has unveiled a comprehensive security enhancement that implements a “pause, question, and verify” protocol to protect users from sophisticated messaging scams.  The platform has simultaneously disrupted over 6.8 million …

CAPTCHAgeddon – New ClickFix Attack Leverages Fake Captcha to Deliver Malware Payload

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated new malware campaign has emerged that weaponizes fake CAPTCHA verification pages to trick users into executing malicious PowerShell commands, marking a significant evolution in browser-based attack methodologies. The …