Sony Breached Via MOVEit Zero-Day Vulnerability

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Sony Interactive Entertainment (SIE) discloses a cybersecurity breach caused by the exploitation of a zero-day vulnerability in Progress Software’s MOVEit Transfer platform. Nearly 6791 current and former workers or members of …

Malicious npm Package from a Twin Developers Deliver r77 Rootkit

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A malicious supply chain attack affecting the popular npm platform, often used for Node.js projects, has been identified.  This attack employs a tactic known as typosquatting, where malicious actors create …

EvilProxy Attacking Microsoft 365 Users Abusing Open Redirection With Indeed.com

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

EvilProxy Attacking Microsoft 365 Users Abusing Open Redirection With Indeed.com By Guru – October 5, 2023 A recent phishing campaign, identified by Menlo Labs, has been actively targeting executives in …

Qualcomm Sys Hackers Actively Exploit 3 new Zero-Days – Patch Now

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Three new zero days have been reported to Qualcomm, which were CVE-2023-33106, CVE-2023-33107, and CVE-2023-33063. These vulnerabilities were discovered as part of Google Project Zero and were disclosed to Qualcomm …

Microsoft Teams & Edge Zero-Day Vulnerabilities Leads to Code Execution

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Microsoft has addressed two zero-day vulnerabilities in two Open-Source Software security vulnerabilities, which include Microsoft Edge, Microsoft Teams for Desktop, Skype for Desktop, and Webp images extension. These vulnerabilities were …

Exim SMTP Service Zero-day Flaw Let Attackers Execute Remote Code

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Six new zero-day vulnerabilities in Exim Message Transfer Agent have been reported as part of the Zero-Day initiative. These vulnerabilities were discovered in June 2022 but were not disclosed until …

New Android Banking Malware Pose as Government App to Target Users

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cybercriminals continue making malware for profit, with a recent report uncovering ASMCrypt in underground forums related to the DoubleFinger loader. In the cybercrime landscape, researchers at Securelist have also reported …

Apache NiFi RCE Vulnerability Let Attackers Exfiltrate Sensitive Data

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The widely used data integration tool Apache NiFi has been discovered to be susceptible to a critical security flaw tracked as CVE-2023-34468 that might allow remote code execution. Additionally, this significant issue might allow attackers …