Hackers Weaponizing Typosquatted Libraries To Inject SSH Backdoors

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated attack targeting npm users has been recently uncovered by the Socket’s threat research team in a concerning development for the open-source community. The threat actor, identified as “sanchezjosephine180,” …

Kansas City Man Charged for Hacking Computer Systems of Health Clubs

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A 31-year-old Kansas City man has been indicted on federal charges for allegedly hacking into the computer systems of a health club chain and a nonprofit organization. Nicholas Michael Kloster …

Palo Alto certification validation Flaw Let Attackers Escalate Privilege

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A significant security vulnerability has been discovered in Palo Alto Networks’ GlobalProtect app, potentially allowing attackers to escalate privileges on affected systems. The flaw, which stems from insufficient certification validation, …

WordPress Plugin Flaw Exposes 200,000 WordPress Sites To Hacking

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical vulnerability was discovered on October 30th, 2024 in the Anti-Spam by CleanTalk WordPress plugin, potentially affecting over 200,000 active installations. This flaw allows unauthenticated attackers to install and …

CISA Details Red Team’s Activity Including TTPs & Network Defense

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A comprehensive Red Team Assessment (RTA) was conducted recently by the Cybersecurity and Infrastructure Security Agency (CISA) on a critical infrastructure organization in the United States. This assessment, which spanned …

7 New Flaws In Android & Google Pixel Devices Let Attackers Elevate Privileges

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Seven critical vulnerabilities affecting Android and Google Pixel devices were recently uncovered during a recent analysis of mobile applications. These security flaws, discovered through the Oversecured Mobile Application Vulnerability Scanner, …

Starbucks Hit by Ransomware Attack Via Third-party Software Supplier

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A ransomware attack on Blue Yonder, a critical supply chain management software provider, has forced Starbucks to revert to manual processes for managing employee schedules and payroll systems. The incident, …

Hackers Abuse Avast Anti-Rootkit driver To Evade Detection

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A malicious campaign has been discovered in which the malware employs a more nefarious tactic, dropping the legitimate Avast Anti-Rootkit driver (aswArPot.sys) to evade detection. The malware takes advantage of …

Critical QNAP Vulnerability Let Attackers Execute Remote Code

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Multiple vulnerabilities have been identified in QNAP’s QuRouter, specifically affecting version 2.4.x. The vulnerabilities are tracked as CVE-2024-48860 and CVE-2024-48861, which pose a serious risk as they allow remote attackers …