Windows Remote Registry Client EoP Flaw Exposes Systems to Relay Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical elevation of privilege (EoP) vulnerability, identified as CVE-2024-43532, has been discovered in the Windows Remote Registry client. This vulnerability potentially allows attackers to relay NTLM authentication and gain …

Crypto Payment Firm Transak Hit by Data Breach After Employee’s Laptop Hack

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Transak, a leading crypto payment services provider, has been affected by a significant data breach that affected over 92,000 users. The incident, which came to light on October 21, 2024, …

Beast Ransomware Attacking Windows, Linux, And ESXi Systems

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Ransomware groups are cybercriminal organizations that deploy malware to encrypt victims’ data, which helps render it inaccessible until a “ransom” is paid. The rise in ransomware incidents has significantly impacted …

Over 10 Million Personal And Corporate Devices Infected By Information Stealers

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Kaspersky has reported that nearly 10 million personal and corporate devices were compromised by data-stealing malware in 2023, marking a staggering 643% increase over the past three years. This alarming …

Hackers Exploiting Roundcube XSS Vulnerability To Steal Login Credentials

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Security researchers have uncovered a new phishing campaign targeting users of the popular open-source Roundcube webmail software. Unknown threat actors are exploiting a now-patched cross-site scripting (XSS) vulnerability to steal …

Hackers Mimic As  ESET To Attack Organizations With Wiper Malware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Hackers impersonated ESET, a prominent cybersecurity firm, to attack organizations with destructive wiper malware. The attack, which began on October 8, 2024, involved a phishing campaign that exploited ESET’s brand …

New AI Tool to Discover 0-Days at Large Scale with a Click of a Button

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A new AI tool named Vulnhuntr has been introduced, revolutionizing the way vulnerabilities are discovered in open-source projects. This innovative tool leverages the power of large language models (LLMs) to …

Internet Archive Breached Again, Hackers Exploited Unrotated API Tokens

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The Internet Archive has fallen victim to another cyberattack, marking the third major security incident in October 2024. On October 20, hackers successfully exploited unrotated API tokens to gain unauthorized …