New WordPress Malware as Cache Plugin Creates Rogue Admin Account

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A novel kind of malware that acts as a sophisticated backdoor that can carry out several operations while impersonating a legitimate plugin has been identified. The malware has several features, …

Large-scale Akira Ransomware Attacking Unsecured Computers

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

In order to disrupt human-operated ransomware attacks and prevent attackers from advancing their objectives through lateral movement, it is crucial to swiftly contain any compromised user accounts. Taking this step …

Google Initiates the End of Passwords, Making Passkeys the Default for Users

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Google, a well-known tech giant, has introduced a new feature called “passwordless by default”. This feature aims to simplify the login process for users by eliminating the need for traditional …

Heap-based Buffer Overflow Flaw in cURL Library Using SOCKS5 Proxy

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Previously, the maintainers of the popular curl command line tool posted a pre-announcement regarding two vulnerabilities that affected both the curl tool and the libcurl library. However, the details of …

How LLM-like Models like ChatGPT patch the Security Gaps in SoC Functions

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The emergence of Large Language Models (LLMs) is transforming NLP, enhancing performance across NLG, NLU, and information retrieval tasks. They are primarily excellent in text-related tasks like generation, summarization, translation, …

Nation-state Hackers Exploiting Confluence Zero-day Vulnerability

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Microsoft has detected the nation-state threat actor Storm-0062, also known as DarkShadow or Oro0lxy, exploiting CVE-2023-22515 in the wild since September 14, 2023.  The vulnerability was publicly disclosed on October …

Top 10 Best SaaS Security Tools

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Security management across multiple Software-as-a-Service (SaaS) clouds can present challenges, primarily stemming from the heightened prevalence of malware and ransomware attacks. In the present landscape, organizations encounter many challenges with …

HTTP/2 Rapid Reset Zero-day Flaw Exploited to Launch Massive DDoS Attack

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cloudflare was unexpectedly hit by an enormous HTTP attack that peaked at over 201 million requests per second. Starting on August 25, 2023, this onslaught posed a significant challenge, especially …