Microsoft Seized Storm-1152 Websites Used to Sell Microsoft Products & Accounts

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Hackers sell fake Microsoft products and accounts because it allows them to profit from illicit activities, taking advantage of unsuspecting users. Microsoft’s security team, partnered with Arkose Labs, is cracking …

Beware of Malicious 7ZIP on the Microsoft App Store that Delivers Malware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Hackers target 7ZIP due to its widespread use and popularity, making it a lucrative vector for spreading malware.  Exploiting vulnerabilities in 7ZIP allows them to compromise a large number of …

Hackers Abuse OAuth Applications to Launch Automated Financial Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

OAuth (Open Authorization) is an industry-standard protocol that allows third-party applications to access a user’s data without exposing login credentials.  This standard protocol facilitates secure authorization and authentication, commonly used …

Lazarus Group’s Operation Blacksmith Attacking Organizations Worldwide

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The Lazarus Group is a notorious North Korean state-sponsored hacking organization known for:- Cyber espionage Financial Theft Destructive attacks They have been implicated in high-profile incidents, including the 2014 Sony …

New Editbot Stealer in Action; Stealing Browser Passwords & Cookies

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A new malicious campaign, Editbot Stealer, was discovered in which threat actors use WinRAR archive files with minimal detection to perform a multi-stage attack. Threat actors have been utilizing the …

Apple Urgently Patches Zero-day Flaw Exploited in the Wild

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Apple has released an emergency security update for patching two actively exploited zero-day vulnerabilities on iOS. The vulnerabilities were discovered earlier this month and are tracked as CVE-2023-42916, and CVE-2023-42917 …

Apache ActiveMQ Vulnerability Exploited by Kinsing to Attack Linux Servers

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Threat actors actively targeted the Apache ActiveMQ vulnerability to get unauthorized access to messaging systems, leading to potential data breaches and system compromise. Meanwhile, the Apache ActiveMQ vulnerability, which was …