Lenovo PC/Laptop Flaws Enable Attackers to Run Arbitrary Code

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Lenovo has disclosed multiple BIOS security vulnerabilities affecting several vendors in their new security advisory. The potential impacts of these vulnerabilities could be Information Disclosure and Arbitrary code execution on …

SideCopy APT group Exploiting WinRAR Zero-Day to Deliver Ares RAT

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

SideCopy, the Pakistani-based threat actor, has been using the WinRAR vulnerability (CVE-2023-38831) to target Indian government entities for delivering multiple RATs (Remote Access Trojans) like AllaKore RAT, Ares RAT, and …

Watch Out For Malicious Python Packages That Can Hijack Your Computer

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Recently, security researchers have discovered that cybercriminals are distributing harmful Python packages that are camouflaged as genuine obfuscation tools, but in reality, they contain malicious code. These packages are being …

Multiple Videolan VLC Player Flaws Leads to Memory Corruption: Update Now!

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Recently, two significant vulnerabilities related to memory corruption have been uncovered in the popular VLC media player. These vulnerabilities were found in the Microsoft Media Server (MMS), which has two …

Script Tracer Tool – Threat Researchers to Trace & Deobfuscate the Malware Execution

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cyber forensic tools play a crucial role in cyber investigations by helping investigators collect, analyze, and preserve digital evidence.  These tools can extract data from various sources, such as:- Hard …

ChatGPT-Powered Malware Attacking Cloud Platforms to Steal Login Credentials

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Threat actors can potentially exploit ChatGPT to generate convincing phishing emails or deceptive content encouraging users to download malware.  They may also use the model to obfuscate malicious code or …

Google Calendar RAT Abusing Calendar Events to Create Red Teaming Infrastructure

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Google Calendar RAT (GCR) is a proof of concept for Command & Control (C2) via Google Calendar Events. It’s useful when setting up a full red team infrastructure is challenging. …

NODLINK – First-ever Online System for APT Attack Detection

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Researchers point out that APTs (Advanced Persistent Threats) cause financial harm to organizations. For APT modeling, provenance graphs may be used to cut down on these losses and make detection better. …