Latest Cybersecurity News and Articles
06 November 2023
Cybersecurity researchers have shed light on a new dropper-as-a-service (DaaS) for Android called SecuriDropper that bypasses new security restrictions imposed by Google and delivers the malware.
Dropper malware on Android is designed to function as a conduit to install a payload on a compromised device, making it a lucrative business model for threat actors, who can advertise the capabilities
06 November 2023
According to a report by Sophos, the rate of data encryption following a ransomware attack in the healthcare sector has reached its highest level in the last three years.
06 November 2023
Last week, KrebsOnSecurity broke the news that one of the largest cybercrime services for laundering stolen merchandise was hacked recently, exposing its internal operations, finances and organizational structure. In today's Part II, we'll examine clues about the real-life identity left behind by "Fearless," the nickname chosen by the proprietor of the SWAT USA Drops service.
06 November 2023
The first vulnerability, tracked as CVE-2023-23368, allows remote attackers to execute commands via a network. The second vulnerability, identified as CVE-2023-23369, can also be exploited by remote attackers.
06 November 2023
Google has warned about a new threat called Google Calendar RAT (GCR) that uses the Calendar service as command-and-control infrastructure. It creates a covert channel by exploiting event descriptions in Google Calendar, making detection difficult.
06 November 2023
The US Treasury has sanctioned Ekaterina Zhdanova for laundering money on behalf of cybercriminals and Russian elites.
The post US Sanctions Russian National for Helping Ransomware Groups Launder Money appeared first on SecurityWeek.
06 November 2023
Glibc vulnerability affecting major Linux distributions and tracked as Looney Tunables exploited in cloud attacks by Kinsing group.
The post ‘Looney Tunables’ Glibc Vulnerability Exploited in Cloud Attacks appeared first on SecurityWeek.
06 November 2023
The botnet uses a domain generation algorithm (DGA) to connect with its command and control server and can be instructed to establish backconnect server connections, allowing infected devices to be used as proxy servers.
06 November 2023
Threat actors have started exploiting a recent critical vulnerability in Confluence Data Center and Confluence Server.
The post Exploitation of Critical Confluence Vulnerability Begins appeared first on SecurityWeek.
06 November 2023
The Iran-linked APT Agrius has been targeting higher education and technology organizations in Israel with new wipers.
The post Iranian APT Targets Israeli Education, Tech Sectors With New Wipers appeared first on SecurityWeek.
06 November 2023
Researchers at Positive Security demonstrated that by integrating a keylogger with a Bluetooth transmitter into a USB keyboard, passwords and other sensitive data typed on the keyboard can be relayed through the Find My network via Bluetooth.
06 November 2023
The Mobile Application Security Assessment (MASA) allows developers to have their apps independently validated against a global security standard, such as the Mobile Application Security Verification Standard (MASVS).
06 November 2023
The data, which is being sold on Breach Forums for $50,000 in cryptocurrency, includes bank statements, personal information of 730,000 individuals, and sensitive details such as Russian Social Security Numbers and bank routing information.
06 November 2023
Israeli higher education and tech sectors have been targeted as part of a series of destructive cyber attacks that commenced in January 2023 with an aim to deploy previously undocumented wiper malware.
The intrusions, which took place as recently as October, have been attributed to an Iranian nation-state hacking crew it tracks under the name Agonizing Serpens, which is also known as Agrius,
06 November 2023
In 2023 alone, there has been a 60% year-on-year increase in large breaches impacting over 88 million individuals, with hacking accounting for 77% of these breaches, according to the HHS.
06 November 2023
The website of BrickLink, a popular LEGO marketplace, is currently down due to a reported hacking incident. Hackers are allegedly demanding payments in cryptocurrency in exchange for not deleting store inventories and other items on BrickLink.
06 November 2023
Microsoft says four Exchange ‘zero-days’ disclosed by ZDI have either already been patched or they don’t require immediate attention.
The post Microsoft Says Exchange ‘Zero Days’ Disclosed by ZDI Already Patched or Not Urgent appeared first on SecurityWeek.
06 November 2023
Election officials in Mississippi’s most populous county had to scramble to complete required poll worker training after an early September breach involving county computers.
The post A Cyber Breach Delays Poll Worker Training in Mississippi’s Largest County Before the Statewide Vote appeared first on SecurityWeek.
06 November 2023
The ongoing tensions between Armenia and Azerbaijan, particularly around the disputed Nagorno-Karabakh region, have created a backdrop for the use of Pegasus spyware, targeting various individuals including politicians, activists, and journalists.
06 November 2023
States have been demanding increased federal funding to support election infrastructure security, establish federal cybersecurity and audit standards for voting equipment, and replace outdated technologies.