Category: Uncategorized
-
Progress Software Issues Patch for Vulnerability in LoadMaster and MT Hypervisor [email protected] (The Hacker News)
Progress Software has released security updates for a maximum-severity flaw in LoadMaster and Multi-Tenant (MT) hypervisor that could result in the execution of arbitrary operating system commands. Tracked as CVE-2024-7591 (CVSS score: 10.0), the vulnerability has been described as an improper input validation bug that results in OS command injection. “It is possible for unauthenticated,…
-
New Android SpyAgent Malware Uses OCR to Steal Crypto Wallet Recovery Keys [email protected] (The Hacker News)
Android device users in South Korea have emerged as a target of a new mobile malware campaign that delivers a new type of threat dubbed SpyAgent. The malware “targets mnemonic keys by scanning for images on your device that might contain them,” McAfee Labs researcher SangRyol Ryu said in an analysis, adding the targeting footprint…
-
TIDRONE Espionage Group Targets Taiwan Drone Makers in Cyber Campaign [email protected] (The Hacker News)
A previously undocumented threat actor with likely ties to Chinese-speaking groups has predominantly singled out drone manufacturers in Taiwan as part of a cyber attack campaign that commenced in 2024. Trend Micro is tracking the adversary under the moniker TIDRONE, stating the activity is espionage-driven given the focus on military-related industry chains. The exact initial…
-
U.S. Offers $10 Million for Info on Russian Cadet Blizzard Hackers Behind Major Attacks [email protected] (The Hacker News)
The U.S. government and a coalition of international partners have officially attributed a Russian hacking group tracked as Cadet Blizzard to the General Staff Main Intelligence Directorate (GRU) 161st Specialist Training Center (Unit 29155). “These cyber actors are responsible for computer network operations against global targets for the purposes of espionage, sabotage, and reputational harmRead…
-
North Korean Threat Actors Deploy COVERTCATCH Malware via LinkedIn Job Scams [email protected] (The Hacker News)
Threat actors affiliated with North Korea have been observed leveraging LinkedIn as a way to target developers as part of a fake job recruiting operation. These attacks employ coding tests as a common initial infection vector, Google-owned Mandiant said in a new report about threats faced by the Web3 sector. “After an initial chat conversation,…
-
FBI Cracks Down on Dark Web Marketplace Managed by Russian and Kazakh Nationals [email protected] (The Hacker News)
Two men have been indicted in the U.S. for their alleged involvement in managing a dark web marketplace called WWH Club that specializes in the sale of sensitive personal and financial information. Alex Khodyrev, a 35-year-old Kazakhstan national, and Pavel Kublitskii, a 37-year-old Russian national, have been charged with conspiracy to commit access device fraud…
-
US Gov Removing Four-Year-Degree Requirements for Cyber Jobs SecurityWeek News
The US government will remove “unnecessary degree requirements” in favor of skills-based hiring to help fill 500,000 open cybersecurity jobs. The post US Gov Removing Four-Year-Degree Requirements for Cyber Jobs appeared first on SecurityWeek. Read More
-
SonicWall Urges Users to Patch Critical Firewall Flaw Amid Possible Exploitation [email protected] (The Hacker News)
SonicWall has revealed that a recently patched critical security flaw impacting SonicOS may have come under active exploitation, making it essential that users apply the patches as soon as possible. The vulnerability, tracked as CVE-2024-40766, carries a CVSS score of 9.3 out of a maximum of 10. “An improper access control vulnerability has been identified…
-
Top API risks and how to mitigate them
Post ContentRead More
-
GeoServer Vulnerability Targeted by Hackers to Deliver Backdoors and Botnet Malware [email protected] (The Hacker News)
A recently disclosed security flaw in OSGeo GeoServer GeoTools has been exploited as part of multiple campaigns to deliver cryptocurrency miners, botnet malware such as Condi and JenX, and a known backdoor called SideWalk. The security vulnerability is a critical remote code execution bug (CVE-2024-36401, CVSS score: 9.8) that could allow malicious actors to take…