Category: Uncategorized
-

CanesSpy Spyware Discovered in Modified WhatsApp Versions [email protected] (The Hacker News)
Cybersecurity researchers have unearthed a number of WhatsApp mods for Android that come fitted with a spyware module dubbed CanesSpy. These modified versions of the instant messaging app have been observed propagated via sketchy websites advertising such software as well as Telegram channels used primarily by Arabic and Azerbaijani speakers, one of which boasts 2 million…
-

48 Malicious npm Packages Found Deploying Reverse Shells on Developer Systems [email protected] (The Hacker News)
A new set of 48 malicious npm packages have been discovered in the npm repository with capabilities to deploy a reverse shell on compromised systems. “These packages, deceptively named to appear legitimate, contained obfuscated JavaScript designed to initiate a reverse shell on package install,” software supply chain security firm Phylum said. All the counterfeit packages have…
-
Citrix Bleed Attack
CVE-2023-4966 is being widely exploited, with multiple threat actors, including ransomware groups, targeting internet-accessible NetScaler ADC and Gateway instances. After exploiting CVE-2023-4966, the attackers may engage in network reconnaissance, stealing account credentials and moving laterally via RDP.Read More
-
Microsoft launches Secure Future Initiative to bolster security
Post ContentRead More
-
Zscaler finds 117 Microsoft 365 bugs via SketchUp 3D file type
Post ContentRead More
-

Mysterious Kill Switch Disrupts Mozi IoT Botnet Operations [email protected] (The Hacker News)
The unexpected drop in malicious activity connected with the Mozi botnet in August 2023 was due to a kill switch that was distributed to the bots. “First, the drop manifested in India on August 8,” ESET said in an analysis published this week. “A week later, on August 16, the same thing happened in China. While the…
-

SaaS Security is Now Accessible and Affordable to All [email protected] (The Hacker News)
This new product offers SaaS discovery and risk assessment coupled with a free user access review in a unique “freemium” model Securing employees’ SaaS usage is becoming increasingly crucial for most cloud-based organizations. While numerous tools are available to address this need, they often employ different approaches and technologies, leading to unnecessary confusion and complexity.…
-

Iran’s MuddyWater Targets Israel in New Spear-Phishing Cyber Campaign [email protected] (The Hacker News)
The Iranian nation-state actor known as MuddyWater has been linked to a new spear-phishing campaign targeting two Israeli entities to ultimately deploy a legitimate remote administration tool from N-able called Advanced Monitoring Agent. Cybersecurity firm Deep Instinct, which disclosed details of the attacks, said the campaign “exhibits updated TTPs to previously reported MuddyWater activity,”Read More
-

Researchers Find 34 Windows Drivers Vulnerable to Full Device Takeover [email protected] (The Hacker News)
As many as 34 unique vulnerable Windows Driver Model (WDM) and Windows Driver Frameworks (WDF) drivers could be exploited by non-privileged threat actors to gain full control of the devices and execute arbitrary code on the underlying systems. “By exploiting the drivers, an attacker without privilege may erase/alter firmware, and/or elevate [operating system] privileges,” Takahiro…
-

FIRST Announces CVSS 4.0 – New Vulnerability Scoring System [email protected] (The Hacker News)
The Forum of Incident Response and Security Teams (FIRST) has officially announced CVSS v4.0, the next generation of the Common Vulnerability Scoring System standard, more than eight years after the release of CVSS v3.0 in June 2015. “This latest version of CVSS 4.0 seeks to provide the highest fidelity of vulnerability assessment for both industry and the public,”…
