Red Art Games Hacked, Customers Personal Information Exposed

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Red Art Games, a prominent publisher and distributor of limited-edition video games, has fallen victim to a cyberattack. The breach has resulted in the exposure of sensitive customer information, causing …

Threat Actors Using Telegram APIs To Steal Login Credentials

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Threat actors are exploiting Telegram APIs to avoid detection and illicitly obtain users’ login credentials. Be cautious of a phishing email containing a disguised URL (hxxps[://]www[.]astunet[.]com/wp-plug/imu0nni5/3rhenqt2/) that directs you to …

North Korean APT45 Hackers, Long Running Digital Military Since 2009

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The FBI and Google-owned Mandiant have recently revealed a sophisticated North Korean hacking group known as APT45. This group, previously dubbed Andariel, has been conducting cyber espionage campaigns globally since …

Hackers Claiming Breach of CrowdStrike’s Threat Actor Database

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A hacktivist entity known as USDoD has claimed to have leaked CrowdStrike’s “entire threat actor list” and alleged possession of the company’s “entire IOC [indicators of compromise] list”, which contains …

Google Chrome Enhances Security to Block Malicious Downloads

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Google has recently unveiled significant updates to Chrome’s download protection features, aiming to provide users with enhanced security against potentially harmful files. These changes come as part of Google’s ongoing …

6600+ Vulnerable GeoServer instances Exposed to the Internet

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Security analysts have identified 6,635 GeoServer instances exposed to the Internet, which makes them vulnerable to critical remote code execution (RCE) attacks. A recent tweet from the Shadowserver Foundation stated …

Microsoft’s Windows Hello for Business Flaw Let Attackers Bypass Authentication

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A recently discovered vulnerability in Microsoft’s Windows Hello for Business (WHfB) authentication system allowed attackers to bypass the supposedly phishing-resistant login method, raising concerns about the security of this widely …

DDoS Attack Lasted for 6 Days, Record created for the duration of the Cyberattack

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A financial institution in the Middle East endured a record-breaking Distributed Denial of Service (DDoS) attack for six days. The attack, orchestrated by the hacktivist group SN_BLACKMETA, set a new …

Progress Telerik Report Server Flaw Let Attackers Execute Remote Code

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical security vulnerability has been discovered in the Progress® Telerik® Report Server, potentially allowing attackers to execute remote code on affected systems. The flaw, identified as CVE-2024-6327, has been …

GitLab Patch XSS Vulnerability that Lets Attackers to Execute Arbitrary Code

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

GitLab has released new Community Edition (CE) and Enterprise Edition (EE) versions to address multiple vulnerabilities. Among these, a high-severity cross-site scripting (XSS) vulnerability has garnered particular attention due to …