Chinese Hackers use .chm files to Hijack Execution Chain and Deploy Malware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The Chinese state-backed group TAG-74 is known for conducting intelligence collection on organizations in the following countries:- South Korea Japan Russia The TAG-74 utilizes .chm files to trigger a DLL …

Magento Security Checklist: 8 Steps To a Secure Magento Store – 2023

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

As one of the leading eCommerce platforms, Magento hosts many online businesses, each holding vast amounts of sensitive customer and transaction data. However, like all software, Magento is susceptible to …

Silent Skimmer Group Attacking Online Shopping Websites

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The “Silent Skimmer” is a financially motivated group that has been detected targeting vulnerable online payment infrastructure, such as online businesses and Point of Sales (POS) providers. They are mostly …

LockBit Using Remote Monitoring Tools to Infect Employees with Ransomware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

In a recent wave of cyberattacks, eSentire, a global Managed Detection and Response (MDR) security services provider, has thwarted three separate ransomware attacks orchestrated by affiliates of the notorious LockBit …

Researchers Uncover the Bond Between the Infamous Remcos RAT and GuLoader

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

There have been two instances of software distributors that have disguised themselves as having legitimate purposes but were actually operating with malicious intent. Threat actors adopting the use of two …

CrowdStrike to Acquire Cloud-Native App Security Startup Bionic for $350 Million

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

In a groundbreaking move within the cybersecurity arena, CrowdStrike, a leading name in cloud security, has announced its agreement to acquire Bionic, the pioneer of Application Security Posture Management (ASPM).  …

Konni APT Exploits WinRAR Vulnerability To Attack Financial & Crypto Industries

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Konni, a North Korean APT group, launched the first attack against the cryptocurrency industry, exploiting a recently found WinRAR vulnerability tagged as CVE-2023-38831. According to the study, Konni’s decision to focus on …

Trend Micro Zero-day Vulnerability Let Attackers Run Arbitrary Code

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

If you are using Trend Micro Apex One, be aware that there may be a vulnerability in the third-party Antivirus uninstaller module. This vulnerability could potentially allow for arbitrary code …

Fortinet FortiOS Flaw Let Attacker Execute Malicious JavaScript Code

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A high-severity cross-site scripting (XSS) vulnerability tracked as (CVE-2023-29183) affecting several FortiOS and FortiProxy versions has been patched by Fortinet. Additionally, the cybersecurity firm provided updates for a high-severity flaw in …