Threat Actors Actively Exploiting Cisco IOS XE Zero-day Vulnerability

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Threat actors exploit zero-day vulnerabilities because these flaws are unknown to the software developers, making them highly effective for launching attacks.  Exploiting zero-days allows malicious actors to bypass security measures …

ChatGPT for Vulnerability Detection – Prompts Used and their Responses

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Software vulnerabilities are essentially errors in code that malicious actors can exploit. Advanced language models such as CodeBERT, GraphCodeBERT, and CodeT5 can detect these vulnerabilities, provide detailed analysis assessments, and …

EtherHiding: A Novel Technique to Hide Malicious Code Using Binance’s Smart Chain

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Threat actors have employed a new technique to distribute malicious code named “EtherHiding,” which abuses Binance’s Smart Chain (BSC) contracts to host parts of a malicious code chain to hide …

IBM QRadar SIEM XSS Flaw Let Attackers Execute JavaScript code

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Two medium-severity vulnerabilities have been discovered in the widely used IBM QRadar SIEM, associated with Cross-Site Scripting (XSS) and Information disclosure. The vulnerabilities have been assigned with CVE-2023-40367 and CVE-2023-30994. …

CISA to Flag Vulnerabilities & Misconfigurations Exploited in Ransomware Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Ransomware attacks have grown to be a serious concern for businesses of all sizes, with the potential to seriously harm the operations, finances, and reputation of the targeted enterprises. Many ransomware …

Hackers Abusing Skype and Teams to Deliver the DarkGate Malware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Hackers utilized the Teams and Skype messaging platforms to spread the DarkGate malware to the targeted businesses. When DarkGate malware is installed, a Visual Basic for Applications (VBA) loader script …

Telegram, AWS, and Alibaba Cloud Users Targeted in Latest Supply Chain Attack

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A new supply-chain attack, which was active throughout September 2023, has been discovered in which threat actors used Typosquatting and Startjacking techniques to lure developers using Alibaba cloud services, AWS, …