Operation ShadowCat Using Weaponized Office document To Attack Users In India

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Researchers identified a new attack campaign (“Operation ShadowCat”) using malicious LNK files distributed via spam emails, which triggers a PowerShell script that drops a .NET loader and a decoy Word …

Threat Actors Using OS Command Injection Vulnerabilities To Compromise Systems, CISA Warns

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

By exploiting OS command injection vulnerabilities, threat actors can run arbitrary commands on a host operating system to obtain unauthorized access, control, and the power to either corrupt or steal …

Hackers Exploiting MSHTML vulnerability to Deliver Atlantida Malware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Void Banshee, a threat actor, has been exploiting a critical MSHTML vulnerability, CVE-2024-38112, to distribute the Atlantida InfoStealer malware. This sophisticated campaign has targeted unsuspecting users by attracting PDF books …

Spyware Provider for Windows, Mac & Android Hacked, Sensitive Data Exposed

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

TechCrunch has learned that Spytech, a little-known spyware maker based in Minnesota, has been hacked, exposing sensitive data from thousands of devices worldwide. The breach has unveiled the covert surveillance …

RADIUS Protocol Vulnerability Impacted Multiple Cisco Products

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical vulnerability in the Remote Authentication Dial-In User Service (RADIUS) protocol has been disclosed, affecting multiple Cisco products. The vulnerability, CVE-2024-3596, allows an on-path attacker to forge RADIUS responses, …

Hackers Abuse Microsoft Office Forms to Launch Two-Step Phishing Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cybercriminals are increasingly using Microsoft Office Forms to launch sophisticated two-step phishing attacks. At present, certain individuals are being tricked into divulging their Microsoft 365 (M365) login information through Office Forms. …

Beware Of Malicious Chrome Installer From Chinese Hackers

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A malicious Chrome installer, ChromeSetup.msi, distributed via drive-by download, delivers a novel Gh0st RAT variant, dubbed Gh0stGambit, that evasively retrieves and executes encrypted payloads.  The RAT is a modified open-source …

Threat Actors Exploiting Selenium Grid Services For Cryptomining

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Threat actors often exploit the cloud services for cryptomining, as doing so allows them to abuse the huge computational resources available.  This enables them to significantly maximize their mining efficiency …

Crooks Bypassed Google’s Email Verification to Create Workspace Accounts, Access 3rd-Party Services

Blog WriterCybersecurity News - Original News Source is krebsonsecurity.com

July 26, 2024 0 Comments Google says it recently fixed an authentication weakness that allowed crooks to circumvent the email verification required to create a Google Workspace account, and leverage that …