Category: Uncategorized
-

Critical Flaws Found in ConnectWise ScreenConnect Software – Patch Now [email protected] (The Hacker News)
ConnectWise has released software updates to address two security flaws in its ScreenConnect remote desktop and access software, including a critical bug that could enable remote code execution on affected systems. The vulnerabilities, which currently lack CVE identifiers, are listed below – Authentication bypass using an alternate path or channel (CVSS score: 10.0) Improper limitation ofRead…
-

WordPress Bricks Theme Under Active Attack: Critical Flaw Impacts 25,000+ Sites [email protected] (The Hacker News)
A critical security flaw in the Bricks theme for WordPress is being actively exploited by threat actors to run arbitrary PHP code on susceptible installations. The flaw, tracked as CVE-2024-25600 (CVSS score: 9.8), enables unauthenticated attackers to achieve remote code execution. It impacts all versions of the Bricks up to and including 1.9.6. It has…
-

Iran and Hezbollah Hackers Launch Attacks to Influence Israel-Hamas Narrative [email protected] (The Hacker News)
Hackers backed by Iran and Hezbollah staged cyber attacks designed to undercut public support for the Israel-Hamas war after October 2023. This includes destructive attacks against key Israeli organizations, hack-and-leak operations targeting entities in Israel and the U.S., phishing campaigns designed to steal intelligence, and information operations to turn public opinion against Israel. IranRead More
-

LockBit Ransomware’s Darknet Domains Seized in Global Law Enforcement Raid [email protected] (The Hacker News)
An international law enforcement operation has led to the seizure of multiple darknet domains operated by LockBit, one of the most prolific ransomware groups, marking the latest in a long list of digital takedowns. While the full extent of the effort, codenamed Operation Cronos, is presently unknown, visiting the group’s .onion website displays a seizure banner containing…
-
Ukrainian Raccoon Infostealer Operator Extradited to US Ionut Arghire
Alleged Raccoon Infostealer operator Mark Sokolovsky is awaiting trial in the US, after being extradited from the Netherlands. The post Ukrainian Raccoon Infostealer Operator Extradited to US appeared first on SecurityWeek. Read More
-

Meta Warns of 8 Spyware Firms Targeting iOS, Android, and Windows Devices [email protected] (The Hacker News)
Meta Platforms said it took a series of steps to curtail malicious activity from eight different firms based in Italy, Spain, and the United Arab Emirates (U.A.E.) operating in the surveillance-for-hire industry. The findings are part of its Adversarial Threat Report for the fourth quarter of 2023. The spyware targeted iOS, Android, and Windows devices. “Their various…
-
Russian Cyberspies Exploit Roundcube Flaws Against European Governments Ionut Arghire
Russian cyberespionage group targets European government, military, and critical infrastructure entities via Roundcube vulnerabilities. The post Russian Cyberspies Exploit Roundcube Flaws Against European Governments appeared first on SecurityWeek. Read More
-
Ransomware Group Takes Credit for LoanDepot, Prudential Financial Attacks Eduard Kovacs
The BlackCat/Alphv ransomware group has taken credit for the LoanDepot and Prudential Financial attacks, threatening to sell or leak data. The post Ransomware Group Takes Credit for LoanDepot, Prudential Financial Attacks appeared first on SecurityWeek. Read More
-

How to Achieve the Best Risk-Based Alerting (Bye-Bye SIEM) [email protected] (The Hacker News)
Did you know that Network Detection and Response (NDR) has become the most effective technology to detect cyber threats? In contrast to SIEM, NDR offers adaptive cybersecurity with reduced false alerts and efficient threat response. Are you aware of Network Detection and Response (NDR) and how it’s become the most effective technology to detect cyber threats? NDR…
-

Anatsa Android Trojan Bypasses Google Play Security, Expands Reach to New Countries [email protected] (The Hacker News)
The Android banking trojan known as Anatsa has expanded its focus to include Slovakia, Slovenia, and Czechia as part of a new campaign observed in November 2023. “Some of the droppers in the campaign successfully exploited the accessibility service, despite Google Play’s enhanced detection and protection mechanisms,” ThreatFabric said in a report shared with The Hacker News.Read More
