Researcher Discloses OpenCart Vulnerability; Company Reacts Aggressively

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A security researcher who goes under the name “0xbro” discovered a Static code injection vulnerability in OpenCart, which allows the writing of arbitrary untrusted data on config.php and admin/config.php files …

SysJoker Malware Attacking Windows, Linux and Mac Users Abusing OneDrive

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

SysJoker malware, a multi-platform backdoor with several variants for Windows, Linux, and Mac, has been observed being used by a Hamas-affiliated APT to target Israel. This malware was first identified by …

Loader Malware Steal Sensitive System Data & Installs Other Malware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

In the intricate dance of cybersecurity threats, loader malware emerges as a silent force, discreetly breaching unsuspecting systems and setting the stage for more sophisticated onslaughts.  Despite its subtle nature, …

PolarDNS – A Free DNS Server For Vulnerability Research & Pentesting

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

DNS (Domain Name System) decodes human-readable domain names into IP addresses. In vulnerability research and pentesting, analyzing DNS can reveal the following potential attack vectors that could help in identifying …

Hackers Using Malicious Browser Extensions to Steal Facebook Business Accounts

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

It has come to light that Facebook Business accounts have been compromised through the use of harmful browser extensions developed by the notorious Ducktail family. Ducktail is a specifically designed …

ClearFake a New Malware Attacking Mac users via fake browser updates

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Mac users were targeted by a fake browser update chain called ‘ClearFake’, which was delivered by Atomic Stealer to compromise their systems. Malwarebytes has reported that one of the most …

Hackers using Weaponized Office Document to Exploit Windows Search RCE

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A new attack chain campaign has been discovered, which involves the exploitation of CVE-2023-36884 and CVE-2023-36584. CVE-2023-36884 was a remote code execution vulnerability, and CVE-2023-36584 was a security bypass vulnerability …