Exploiting Jenkins RCE Vulnerability (CVE-2024-43044) Via Agents – Technical Analysis

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical vulnerability has been identified in Jenkins, a widely used automation server. If exploited further, this vulnerability allows attackers to read arbitrary files from the Jenkins controller. If exploited …

Iran State-Sponsored Hackers Intelligence Operations Using Fake Job Offers

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Mandiant has discovered one of the unusual Iranian counterintelligence activities that focuses on prospective agents of foreign intelligence services, especially in Israel. The operation was run by Iranian state-sponsored hackers …

How Threat Actors Establish Persistence on Linux Systems – Elastic Security Labs

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

In a detailed continuation of the Linux Detection Engineering series, Elastic Security’s Ruben Groenewoud has released an in-depth exploration of advanced persistence mechanisms used by threat actors on Linux systems. …

VirusTotal for Threat Research: A Detailed Guide Released – 2024

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

VirusTotal is an essential tool for cybersecurity professionals. It offers a comprehensive platform for analyzing files, URLs, domains, and IP addresses to detect malicious activities. This guide provides a detailed …

Hackers Use Rocinante Malware to Take Over The Android Device Remotely

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The ever-evolving malware landscape is evolving at an alarming rate, as a multitude of new strains have already been noticed. Hackers are becoming more innovative and sophisticated in their mode …

State-Sponsored Hackers Repeatedly Using Same iOS & Chrome Exploits

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Google’s Threat Analysis Group (TAG) has reported the discovery of multiple exploit campaigns targeting Mongolian government websites, spanning from November 2023 to July 2024. These campaigns involved sophisticated watering hole …

Beware! Cybercriminals Exploited Digital Marketing Tools to Launch Malicious Campaigns

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Researchers from Mandiant and Google have uncovered how cybercriminals are repurposing digital analytics and advertising tools to enhance their malicious campaigns. These tools, typically used by marketers and advertisers to …

Beware Of Fake Palo Alto Tool That Delivers Sophisticated Malware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated malware targeting organizations in the Middle East is posing a significant threat. Disguised as a legitimate Palo Alto GlobalProtect tool, the malware uses a two-stage infection process and …

RansomHub Exploiting RDP Services To Exfiltrate Large Volumes Of Data

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Ransomware-as-a-Service (RaaS) significantly lowers the technical barriers for threat actors to launch ransomware attacks, even it also enables threat actors with minimal skills to execute sophisticated cyber attacks. On a …