Windows 10 PLUGScheduler Vulnerability Allows Privilege Escalation

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical vulnerability in the Windows 10 operating system, tracked as CVE-2024-26238, could allow attackers to gain elevated privileges on affected systems. The flaw resides in the PLUGScheduler component of …

Beware of Fake Antivirus Websites Delivering Windows & Android Malware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Fake antivirus websites are now a major cybersecurity threat, spreading malware to both Windows and Android devices. These malicious sites mimic legitimate antivirus solutions from well-known brands such as Avast, …

Hackers Backdoored Courtroom Video Recording Software With System Hijacking Malware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A vulnerability (CVE-2024-4978) has been identified in JAVS Viewer v8.3.7, a critical component for managing digital recordings in legal and government environments.  The installer for this version is backdoored, allowing …

Japan To Launch Active Cyber Defense System To Prevent Cyber Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Japan is creating a consultative body to implement an active cyber defense system to improve its ability to counter cyberattacks on critical infrastructure. The government will tap railways, electricity, and …

Ransomhub Attacking Industrial Control Systems To Encrypt And Exfiltrate Data

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Ransomhub, a new ransomware group, has targeted the SCADA system of a Spanish bioenergy plant, Matadero de Gijón, which highlights the critical security risks associated with Industrial Control Systems (ICS) …

Sharp Dragon Hackers Attacking Government Entities Using Cobalt Strike & Custom Backdoors

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The activities of the Chinese threat actor group known as Sharp Dragon (formerly Sharp Panda) have been meticulously documented. Since 2021, this group has been involved in highly targeted phishing …

New DoS Attack ‘DNSBomb’ Exploiting DNS Queries & Responses

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cybersecurity researchers have unveiled a new and potent Denial of Service (DoS) attack, dubbed “DNSBomb.” This attack leverages the inherent mechanisms of the Domain Name System (DNS) to create a …

Ransomware Attacks Targeting VMware ESXi Infrastructure Adopt New Pattern

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cybersecurity professionals at Sygnia have noted a notable change in the strategies used by ransomware groups that are aiming at virtualized environments, specifically VMware ESXi infrastructure, in relation to development. …

Stark Industries Solutions: An Iron Hammer in the Cloud

Blog WriterCybersecurity News - Original News Source is krebsonsecurity.com

The homepage of Stark Industries Solutions. Two weeks before Russia invaded Ukraine in February 2022, a large, mysterious new Internet hosting firm called Stark Industries Solutions materialized and quickly became …