WordPress Plugin SQl Injection Exposes 1,000,000 Sites to Cyber Attack

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Over a million WordPress websites have been at risk due to a critical SQL Injection vulnerability discovered in the popular LayerSlider plugin. The flaw, CVE-2024-2879, could allow unauthenticated attackers to …

Feds Stepping to Patch Years-old SS7 Vulnerability in Phone Networks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The FCC (Federal Communications Commission) seeks public input regarding measures by communications providers to address vulnerabilities in SS7 and Diameter protocols that enable tracking consumers’ mobile device locations without consent. …

Aembit Selected as Finalist for RSA Conference 2024 Innovation Sandbox Contest

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The Leading Company for Securing Access Between Workloads Recognized for the Aembit Workload IAM Platform Aembit, the Workload Identity and Access Management (IAM) Company, has been named one of the …

‘The Manipulaters’ Improve Phishing, Still Fail at Opsec

Blog WriterCybersecurity News - Original News Source is krebsonsecurity.com

Roughly nine years ago, KrebsOnSecurity profiled a Pakistan-based cybercrime group called “The Manipulaters,” a sprawling web hosting network of phishing and spam delivery platforms. In January 2024, The Manipulaters pleaded …

WP-Members Plugin Expose WordPress Sites To Injection Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A security researcher reported a critical vulnerability in the WP-Members Membership Plugin that allows attackers to inject malicious scripts and potentially take over websites.  Administrators could take advantage of the …

StrelaStealer Attacking Users to Steal Logins from Outlook & Thunderbird

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated variant of StrelaStealer malware has been identified, targeting Spanish-speaking users with the primary aim of pilfering email account credentials from popular email clients Outlook and Thunderbird. This updated …

What is Malware Packers? How To Analyse With ANY.RUN Sandbox – SOC/DIFR Guide

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Antiviruses can quickly detect malicious executable files, but attackers can bypass this by using packers to compress and obfuscate the code, making it difficult for antivirus software to analyze. Packers …

Chinese Hackers Hijack Swedish Routers to Launch Cyber Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The Security Police (Säpo) has disclosed that a Chinese hacker group, APT31, has commandeered Swedish routers to perpetrate cyber attacks against multiple countries. This sophisticated cyber espionage campaign, believed to …

New Pikabot Campaign Weaponizes HTML, Javascript & Excel Files

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A new player has emerged with a sophisticated approach to infiltrating systems worldwide. Dubbed Pikabot, this malicious backdoor has been active since early 2023, but recent activities have showcased its …