Leaked Wallpaper Exploit Let Attackers Escalate Privilege on Windows Systems

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical security flaw in Windows’ wallpaper handling mechanism has been uncovered. It allows attackers to gain system-level privileges on affected machines. Security researcher Andrea Pierini disclosed the vulnerability, which …

Hackers Can Use HDMI Cables to Capture Your Passwords

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Security researchers have discovered a new way that hackers can steal sensitive information, like passwords. This involves eavesdropping on HDMI cables, a concerning development for computer users. The technique, detailed …

Telegram-Controlled TgRat Attacking Linux Servers to Exfiltrate Data

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

TgRat, a Telegram-controlled trojan, was discovered attacking Linux servers in an attempt to steal data from a compromised system. In 2022, the TgRat trojan was first identified. Although the original …

Beware! Fake Google Authenticator Sites Spreading DeerStealer Malware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Researchers from ANY RUN identified a malware distribution campaign dubbed DeerStealer that leverages deceptive websites masquerading as legitimate Google Authenticator download pages.  The initial discovered website, “authentificcatorgoolglte[.]com,” closely resembles the …

Threat Actors Exploiting ChatGPT’s Sora AI Excitement To Deliver Malware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Threat actors exploit AI to make their attacks more effective through automation, scanning large data sets for security gaps and creating intricate phishing scams that are harder to spot. In …

DEV#POPPER Attacking developers via New Social Engineering Tactics

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Threat actors masquerade as interviewers and send a ZIP file (onlinestoreforhirog.zip) to candidates as part of a fake interview, which contains legitimate files and a malicious JavaScript file (printfulRoute.js) that …

Tricky OneDrive Phishing Campaign Tricks Users To Execute PowerShell Script

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated phishing campaign targets Microsoft OneDrive users, employing social engineering to trick victims into executing malicious PowerShell scripts.  The attack leverages a false sense of urgency by claiming a …