Threat Actors Weaponize Smart Contracts to Drain User Crypto Wallets of More Than $900k

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

In a sophisticated campaign uncovered in early 2024, cybercriminals have begun distributing malicious Ethereum smart contracts masquerading as lucrative trading bots. These weaponized contracts leverage Web3 development platforms such as …

Mustang Panda Attacking Windows Users With ToneShell Malware Mimic as Google Chrome

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated new cyber campaign has emerged targeting Windows users through a deceptive malware variant known as ToneShell, which masquerades as the legitimate Google Chrome browser. The advanced persistent threat …

UAC-0099 Hackers Weaponizing HTA Files to Deliver MATCHBOIL Loader Malware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The Ukrainian threat intelligence group UAC-0099 has significantly evolved its cyber warfare capabilities, deploying a sophisticated new malware toolkit targeting Ukrainian state authorities, Defense Forces, and defense industrial enterprises. The …

Google’s Salesforce Instances Hacked in Ongoing Attack: Hackers Exfiltrate User Data

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Google has confirmed that one of its corporate Salesforce instances was compromised in June by the threat group tracked as UNC6040. This incident is part of a Salesforce attack campaign …

WhatsApp’s New Security Feature Allows Users to Pause, Question, and Verify Malicious Messages

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

WhatsApp has unveiled a comprehensive security enhancement that implements a “pause, question, and verify” protocol to protect users from sophisticated messaging scams.  The platform has simultaneously disrupted over 6.8 million …

CAPTCHAgeddon – New ClickFix Attack Leverages Fake Captcha to Deliver Malware Payload

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated new malware campaign has emerged that weaponizes fake CAPTCHA verification pages to trick users into executing malicious PowerShell commands, marking a significant evolution in browser-based attack methodologies. The …

Akira Ransomware Uses Windows Drivers to Bypass AV/EDR in SonicWall Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated evasion technique employed by Akira ransomware affiliates, exploiting legitimate Windows drivers to bypass antivirus and endpoint detection and response (EDR) systems during recent SonicWall VPN attack campaigns.  The …

Chinese Hackers Exploit SharePoint Vulnerabilities to Deploy Toolsets Includes Backdoor, Ransomware and Loaders

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated Chinese threat actor has been exploiting critical vulnerabilities in Microsoft SharePoint to deploy an advanced malware toolset dubbed “Project AK47,” according to new research published by Palo Alto …

Chinese Hackers Compromised Up To 115 Million Payment Cards In The US

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated Chinese cybercriminal syndicate has orchestrated one of the most devastating payment card fraud operations in recorded history, potentially compromising between 12.7 million and 115 million payment cards across …