New Windows Zero-click RCE Flaw Let Attackers Exploit Outlook Clients

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Microsoft recently reported that CVE-2023-23397, a critical Outlook vulnerability, is currently being exploited in the wild by a Russian-state-sponsored threat actor known as Forrest Blizzard.  This vulnerability allowed threat actors …

Zoom Launches Open-source Vulnerability Impact Scoring System

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Zoom, the popular video conferencing platform, has recently announced the launch of its Open-Source Vulnerability Impact Scoring System. This system is designed to provide a standardized method for evaluating the …

PikaBot Attacking Windows Machine via Malicious Search Ads

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

In the labyrinth of cyber threats that define the digital landscape, 2023 has witnessed the resurgence of a particularly pernicious foe — malicious advertisements, colloquially known as “malvertising.”  This nefarious …

Ransomware Gangs Are Collaborating To Attack Financial Services Firms

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The Cyber-Extortion Trinity—the BianLian, White Rabbit, and Mario ransomware gangs—was observed by researchers working together to launch a joint extortion campaign against publicly traded financial services companies. Although these joint …

Hackers Actively Exploiting QNAP VioStor NVR Vulnerability to Deploy Mirai Malware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Hackers exploit QNAP devices because they often have known vulnerabilities or misconfigurations that can be exploited for unauthorized access. Besides this, QNAP devices store valuable data, which makes them lucrative …

Security Engineer Pleads Guilty For Hacking into Cryptocurrency Exchange

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

In the intricate tapestry of the cyber landscape, Shakeeb Ahmed’s saga transcends the ordinary, featuring a downfall unparalleled in its significance—the inaugural conviction for hacking a smart contract.  A tale …

Hackers are Actively Exploiting Apache Struts 2 Vulnerability

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Hackers are taking advantage of a Critical Apache Struts Bug’s initial activity with limited IP addresses engaged in exploitation attempts. Apache is an open-source framework for creating Java EE web …

Rhadamanthys – A Fast-evolving Multi-layer Malware Sold on The Dark Web

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Threat actors make use of fast-evolving multi-layer malware for their complexity and sophistication, as they offer the ability to rapidly adapt and change their code. To make analysis and countermeasures …

Research Discovered 116 Malicious PyPI Packages Downloaded Over 10,000 Times

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A cluster of malicious Python projects has been identified in PyPI, the official Python PyPI package repository, which targets both Windows and Linux systems and often deploys a custom backdoor. In certain …