High-Severity BIND DNS Flaw Let Attackers Exploit Remotely

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Security fixes have been issued that address three high-severity vulnerabilities in several versions of the Internet Systems Consortium (ISC’s) Berkeley Internet Name Domain (BIND DNS Flaw) 9. An attacker might …

Hackers Use Weaponized OpenSSH Tool to Hijack Linux Systems

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cybersecurity researchers at Microsoft recently found an attack targeting Linux-based systems and IoT devices. It has been identified that the exploit employs custom and open-source tools to gain control of …

New PoC Exploit Published for Cisco AnyConnect Flaw Granting System Privileges

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Many organizations worldwide have used Cisco AnyConnect VPNs due to their security and other great features. Cisco has many products for VPN depending upon the platforms with various versions of …

Hackers compromised the Roundcube Email Servers of Ukrainian organizations

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

APT28 (aka BlueDelta, Fancy Bear, Sednit, and Sofacy), a threat group connected to Russia’s GRU, hacked the Roundcube email servers of over 40 Ukrainian organizations, including government bodies. The cyber-espionage …

UPS Hacked – Attackers Using Smishing Technique To Harvest Customer Data

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

As reports suggest, UPS shipping and logistics recently faced a security incident after finding an unauthorized access issue on their internal audit. There was a package-lookup tool used by UPS …

SMS Phishers Harvested Phone Numbers, Shipment Data from UPS Tracking Tool

Blog WriterCybersecurity News - Original News Source is krebsonsecurity.com

The United Parcel Service (UPS) says fraudsters have been harvesting phone numbers and other information from its online shipment tracking tool in Canada to send highly targeted SMS phishing (a.k.a. …

Kimsuky APT Hackers Dropping Malware Via Weaponized CHM (MS Compiled HTML) Files

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

AhnLab Security Emergency Response Center (ASEC) researchers discovered the Kimsuky APT group’s recent strikes, in which attackers have been using CHM files to distribute malware to the targeted machines, downloading …

First Directory of Virtual CISO Providers Launched by Cynomi

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

 The industry’s first-ever directory of virtual Chief Information Security Officer service providers has gone live today at www.thevcisodirectory.com. This extensive list of virtual CISO (vCISO) providers, collated by Cynomi, means …

What is Metasploit: Tools, Uses, History, Benefits & Limitations

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Metasploit provides a complete framework for building, testing, and carrying out attacks against sensitive systems, making it a must-have tool for any organization. Rapid7’s Metasploit is a valuable penetration testing …