Synology DiskStation Manager Vulnerability Allow Remote Attackers to Execute Arbitrary Commands

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical security advisory has been issued for a severe vulnerability in DiskStation Manager (DSM) that allows unauthenticated remote attackers to execute arbitrary commands. Given the widespread use of Synology …

Cisco Secure Firewall Vulnerability Allows Remote Code Execution as Root User

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cisco has released an urgent security advisory addressing a critical vulnerability in its Secure Firewall Management Center (FMC) software. This severe flaw allows unauthenticated remote attackers to execute arbitrary code …

Microsoft Entra ID New Feature Removes MFA Limitations for Users

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Multifactor authentication operates as a critical defense mechanism for securing user identities against targeted cyber attacks. Microsoft reports that implementing MFA effectively reduces the risk of account compromise by more …

New Kiss Loader Malware Uses Early Bird APC Injection in Emerging Attack Campaign

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A newly discovered malware loader called Kiss Loader has emerged as a serious threat, using advanced code injection techniques to quietly infiltrate Windows systems without raising alarms. First spotted in …

Fake npm Install Messages Hide RAT Malware in New Open Source Supply Chain Campaign

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A new and carefully crafted software supply chain campaign is targeting developers through the npm package registry, using fake installation messages to hide malicious activity. The campaign, which security researchers …

Fake VS Code Security Alerts on GitHub Used to Push Malware in Widespread Phishing Campaign

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A large-scale phishing campaign is targeting software developers on GitHub, using fake Visual Studio Code security alerts posted in GitHub Discussions to trick users into downloading malicious software. The attacks …

Ghost SPN Attack Lets Hackers Conduct Stealthy Kerberoasting Under the Radar

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated evolution of Kerberoasting dubbed the “Ghost SPN” attack that allows adversaries to extract Active Directory credentials while erasing all traces of their activity, rendering traditional detection models effectively …

China-Linked Hackers Breach Southeast Asian Military Systems in Long-Running Spy Campaign

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated and long-running cyber espionage campaign, tracked as CL-STA-1087, has been quietly targeting military organizations across Southeast Asia since at least 2020. The operation, assessed with moderate confidence to be …

Open Directory Malware Campaign Uses Obfuscated VBS, PNG Loaders and RAT Payloads

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated multi-stage malware campaign has surfaced, deploying obfuscated Visual Basic Script (VBS) files, PNG-embedded loaders, and remote access trojans (RATs) to target systems without leaving a trace on disk. …