Beware Of Weaponized AWS Packages That Deliver Malware Via JPEG Files

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Attackers hide malicious payloads deep within seemingly legitimate Python packages, where two such packages were found. One, img-aws-s3-object-multipart-copy, is a copy of a real library on GitHub.  They modified the …

Critical Apache HTTP Server Vulnerabilities Expose Millions of Websites to Cyber Attack

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The Apache Software Foundation has disclosed several critical vulnerabilities in the Apache HTTP Server, which could potentially expose millions of websites to cyber-attacks. These vulnerabilities, identified by their Common Vulnerabilities …

Leaked Cellebrite Docs Reveal List of Phones That Can Be Unlocked

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Confidential documents from mobile forensics company Cellebrite, recently obtained and verified by 404 Media, provide a rare glimpse into the capabilities and limitations of phone unlocking technology used by law …

Cisco Smart Software Manager Flaw Let Attackers Change Any User Passwords

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cisco has disclosed a critical vulnerability in its Smart Software Manager On-Prem (SSM On-Prem) that permits unauthenticated, remote attackers to change the passwords of any user, including administrative users. This …

Beware of Fake Microsoft Teams That Deliver macOS Malware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Hackers often mimic popular tools like Microsoft Teams to exploit people’s trust and familiarity with these applications.  This strategy increases the probability of users’ subsequent downloading and installation of this …

Resonance Security Launches Harmony to Help Businesses Combat Web2 and Web3 App Threats

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cybersecurity firm Resonance Security has rolled out ‘Harmony’, a new asset monitoring tool to guard Web2 and Web3 apps from major threats.  The launch comes as cybersecurity threats are getting …

Ivanti Endpoint Manager SQLi Vulnerability Allows Remote Code Execution

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical security flaw, CVE-2024-37381, has been discovered in the Ivanti Endpoint Manager (EPM) 2024 flat. The vulnerability is an unspecified SQL injection flaw in the core server component of EPM, potentially …

FIN7 Hackers Employ New Tools to Bypass EDR & Conduct Automated Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The notorious cybercrime group FIN7 has once again made headlines with the development of new tools designed to bypass Endpoint Detection and Response (EDR) solutions and conduct automated attacks. This …

Killer Ultra Malware Attacking EDR Tools From Symantec, Microsoft, And Sentinel One

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Killer Ultra malware has been found to be targeting endpoint detection and response (EDR) tools from Symantec, Microsoft, and Sentinel One in ransomware attacks. Killer Ultra gathers all Windows event …