Beware Of New HR Payroll Phishing Attack Targeting Numerous Employees

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated phishing campaign dubbed “Payroll Pirates” is currently targeting employees of various high-profile organizations. While the targets include California Employment Development Department (EDD), Kaiser Permanente, Macy’s, New York Life, …

Secret Blizzard Hackers Attack Windows Infrastructure Using Multiple Hacking Tools

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

In a recent joint report by Microsoft Threat Intelligence and Black Lotus Labs, new insights have emerged about “Secret Blizzard,” a sophisticated Russian nation-state cyber actor attacking windows infrastructure using …

Chinese Salt Typhoon Hacked 8+ Telecoms To Stole U.S. Citizens Data

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A Chinese hacking campaign, codenamed “Salt Typhoon” by Microsoft, has infiltrated more than 8 American telecommunications companies, stealing vast amounts of U.S. citizens’ phone data. Officials describe it as one …

Isreali NSO Group’s Pegasus Spyware Detected in New Mobile Devices

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cybersecurity researchers from iVerify have revealed widespread new infections of the Pegasus spyware, developed by NSO Group (dubbed “Rainbow Ronin”), showing that spyware targets not only activists and journalists but …

Deloitte Hacked – Brain Cipher Ransomware Group Allegedly Stolen 1 TB of Data

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Notorious ransomware group Brain Cipher has claimed to have breacked Deloitte UK, allegedly exfiltrating over 1 terabyte of sensitive data from the professional services giant. Brain Cipher is a ransomware …

Operation Destabilise, Authorities Dismateled Cybercriminals Money Laundering Network

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

In a major international operation codenamed “Operation Destabilise,” law enforcement agencies have successfully dismantled sophisticated Russian money laundering networks that served cybercriminals, drug traffickers, and sanctioned Russian elites worldwide. The …

Hackers Exploit Docker Remote API Servers To Inject Gafgyt Malware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The Gafgyt malware (often referred to as Bashlite or Lizkebab) has expanded its attack scope by targeting publicly exposed Docker Remote API servers. Gafgyt malware, also known as Bashlite, and …

U.S. Offered $10M for Hacker Just Arrested by Russia

Blog WriterCybersecurity News - Original News Source is krebsonsecurity.com

In January 2022, KrebsOnSecurity identified a Russian man named Mikhail Matveev as “Wazawaka,” a cybercriminal who was deeply involved in the formation and operation of multiple ransomware groups. The U.S. …

SolarWinds Platform XSS Vulnerability Let Attackers Inject Malicious Code

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical security vulnerability has been recently disclosed by SolarWinds in its Platform product, a major player in IT management software. The flaw, identified as CVE-2024-45717, allows authenticated attackers to …

HR & IT-Related Phishing Emails Are Top-Clicked Among Phishing Email Types

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Phishing emails masquerading as HR and IT-related communications are the most likely to be clicked on by employees as unveiled in a recent study, posing a significant cybersecurity risk to …