shelLM – A New AI-Based Honeypot to Engage Attackers as a Real System

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A honeypot is a trap on a network that lures and studies cyber-attack techniques of threat actors, alerting defenders to unauthorized access attempts. Though Honeypots help and assist cybersecurity researchers …

Freecycle Urges Users to Change Passwords Following Data Breach

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Freecycle, a popular online platform for giving away and receiving free items, reported a significant data breach.  The Freecycle Network (TFN) is a nonprofit organization registered in Arizona, USA, and …

Hackers Exploit Pre-Authentication RCE Vulnerabilities in Adobe ColdFusion

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Adobe ColdFusion is a Java-based, commercial web app development platform using CFML for server-side programming. ColdFusion is primarily known for its tag-based approach, which is unique. Besides this, it is …

Beware of New Fileless Malware that Propagates Through Spam Mail

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Recent reports suggest threat actors have used phishing emails to distribute fileless malware. The attachment consists of a .hta (HTML Application) file, which can be used for deploying other malware …

Hackers Attacking MSSQL Servers To Deploy Ransomware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Recently, threat actors have been utilizing brute force attacks to compromise exposed MSSQL databases to distribute the FreeWorld ransomware. This attack campaign, dubbed DB#JAMMER, is notable, according to Securonix Threat Labs, …

Sophisticated Earth Estries Group Hack Government Agencies and Tech Companies

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A new sophisticated cyber espionage group named Earth Estries, which overlaps notorious threat group FamousSparrow, was unveiled. The group has been active since 2020 and targets multiple government and technology …

Apple Opens Application for Security Research Device Program

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Apple launched the Security Research Device (SRD) program, enabling security researchers to examine the security features of a specially-built hardware variant of the iPhone 14 Pro. Apple Security Bounty is …

Vulnerability in IBM Security Verify Let Attacker Extract Sensitive Information

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Multiple Information Disclosure vulnerabilities were discovered in the IBM Security Verify Information Queue, which can reveal several internal product details. This information can then be used to conduct further attacks.  …

Threat and Vulnerability Roundup for the week of August 27th to September 2nd

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

We are glad to present the most recent news on cybersecurity in this week’s Threat and Vulnerability Roundup from Cyber Writes.  The latest attack techniques, significant weaknesses, and exploits have …