Criminal IP Secures PCI DSS v4.0 Certification, Enhancing Payment Security with Top-Level Compliance

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

AI SPERA, a leading Cyber Threat Intelligence (CTI) company, has achieved PCI DSS v4.0 certification for its flagship search engine solution, Criminal IP. This accomplishment builds on last year’s attainment …

New Emansrepo Malware Weaponizing HTML Files To Attack Windows Users

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Emansrepo is a Python infostealer that was discovered by the FortiGuard Labs in August 2024 and has been disseminated through phishing emails containing fake purchase orders and invoices. It started …

RomCom Group Exploiting Microsoft Office 0-day To Deploy Ransomware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The Russian group RomCom, dubbed Storm-0978, distributes underground ransomware by leveraging the Microsoft Office and Windows HTML RCE zero-day vulnerability identified as CVE-2023-36884. This ransomware encrypts files on victims’ Windows …

Researchers Unpacked ViperSoftX Malware’s Evasion Tactics And Techniques

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Sophisticated threat actors, like those behind the ViperSoftX malware from 2020, often make use of existing tools to save time and resources.  ViperSoftX uses AutoIt, the CLR, and pre-made hacking …

Threat Actor Allegedly Claims Leak of BMW Customer Database

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A well-known threat actor identified as “888” has claimed responsibility for leaking sensitive customer data belonging to BMW Hong Kong. According to the Breachforums post, “888” has allegedly leaked sensitive …

Zyxel Critical Vulnerability Let Attackers Perform OS Command Injection

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Zyxel has issued patches to address a critical operating system (OS) command injection vulnerability identified as CVE-2024-7261. This vulnerability affects several versions of their access points (AP) and security routers. …

Hackers Abuse Red Team Tool MacroPack To Deliver Multiple Malicious Payloads

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

MacroPack is a convenient tool for creating obfuscated VBA malware, but it is still a risk even with the macro execution restricted in downloaded Office documents from Microsoft. This tool …

Travelers Beware of Sophisticated Booking.com Phishing Attack

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cybercriminals have launched a sophisticated phishing attack targeting Booking.com, one of the world’s leading online travel platforms. This attack, characterized by its complexity and high success rate, has been evolving …

Actively Exploited Android Zero-Day Elevation of Privilege vulnerability Patched

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Google has released a patch for a critical zero-day vulnerability, CVE-2024-32896, which was actively exploited in the wild. This vulnerability, classified as a high-severity elevation of privilege (EoP) flaw, was …