XMLRPC npm Library Turns Malicious, Steals Data, Deploys Crypto Miner

28/11/2024 0 Comments 0 tags

Cybersecurity researchers have discovered a software supply chain attack that has remained active for over a year on the npm package registry by starting off as an innocuous library and

U.S. Telecom Giant T-Mobile Detects Network Intrusion Attempts from Wireline Provider

28/11/2024 0 Comments 0 tags

U.S. telecom service provider T-Mobile said it recently detected attempts made by bad actors to infiltrate its systems in recent weeks but noted that no sensitive data was accessed. These

Critical Flaw in ProjectSend Under Active Exploitation Against Public-Facing Servers

27/11/2024 0 Comments 0 tags

A critical security flaw impacting the ProjectSend open-source file-sharing application has likely come under active exploitation in the wild, according to findings from VulnCheck. The vulnerability, originally patched over a

Researchers Discover “Bootkitty” – First UEFI Bootkit Targeting Linux Kernels

27/11/2024 0 Comments 0 tags

Cybersecurity researchers have shed light on what has been described as the first Unified Extensible Firmware Interface (UEFI) bootkit designed for Linux systems. Dubbed Bootkitty by its creators who go

Latest Multi-Stage Attack Scenarios with Real-World Examples

27/11/2024 0 Comments 0 tags

Multi-stage cyber attacks, characterized by their complex execution chains, are designed to avoid detection and trick victims into a false sense of security. Knowing how they operate is the first

APT-C-60 Exploits WPS Office Vulnerability to Deploy SpyGlace Backdoor

27/11/2024 0 Comments 0 tags

The threat actor known as APT-C-60 has been linked to a cyber attack targeting an unnamed organization in Japan that used a job application-themed lure to deliver the SpyGlace backdoor.

INTERPOL Busts African Cybercrime: 1,006 Arrests, 134,089 Malicious Networks Dismantled

27/11/2024 0 Comments 0 tags

An INTERPOL-led operation has led to the arrest of 1,006 suspects across 19 African countries and the takedown of 134,089 malicious infrastructures and networks as part of a coordinated effort

Matrix Botnet Exploits IoT Devices in Widespread DDoS Botnet Campaign

27/11/2024 0 Comments 0 tags

A threat actor named Matrix has been linked to a widespread distributed denial-of-service (DoD) campaign that leverages vulnerabilities and misconfigurations in Internet of Things (IoT) devices to co-opt them into

Critical WordPress Anti-Spam Plugin Flaws Expose 200,000+ Sites to Remote Attacks

26/11/2024 0 Comments 0 tags

Two critical security flaws impacting the Spam protection, Anti-Spam, and FireWall plugin WordPress could allow an unauthenticated attacker to install and enable malicious plugins on susceptible sites and potentially achieve

Intruder Launches Intel: A Free Vulnerability Intelligence Platform For Staying Ahead of the Latest Threats

26/11/2024 0 Comments 0 tags

When CVEs go viral, separating critical vulnerabilities from the noise is essential to protecting your organization. That’s why Intruder, a leader in attack surface management, built Intel – a free