Beijing has claimed that the Volt Typhoon attack gang, accused by Five Eyes nations of being a Beijing-backed threat to critical infrastructure, was actually fabricated by the US intelligence community. This article has been indexed from Cyware News – Latest…
Category: Cyware News – Latest Cyber News
New Play Ransomware Linux Variant Targets ESXi Shows Ties With Prolific Puma
The Play ransomware group has introduced a Linux variant that targets ESXi environments. This variant verifies its environment before executing and has been successful in evading security measures. This article has been indexed from Cyware News – Latest Cyber News…
OilAlpha Malicious Applications Target Humanitarian Aid Groups Operating in Yemen
The attacks, linked to a group called OilAlpha, involved malicious mobile apps and targeted CARE International, Norwegian Refugee Council (NRC), and Saudi Arabian King Salman Humanitarian Aid and Relief Centre. This article has been indexed from Cyware News – Latest…
North Korean Hackers May Have Attacked Indian Crypto Exchange WazirX
Indian crypto exchange WazirX disclosed a loss of virtual assets worth more than $230 million due to a cyber attack linked to North Korea. The attack targeted a multi-signature wallet with six signatories, leading to a breach in security measures.…
Larger Deals Propel Cybersecurity Funding to Two-Year High in Q2 2024
According to Crunchbase data, cybersecurity funding reached a two-year high in Q2 of 2024, with venture capitalists investing $4.4 billion in startups, the strongest quarter since 2022. This marked a 144% increase from the previous year. This article has been…
Operation Spincaster Targets Crypto Pig-Butchering Scams
Operation Spincaster, involving law enforcement and government agencies across six countries, as well as 17 cryptocurrency exchanges, has identified 7,000 leads and $162 million in losses. This article has been indexed from Cyware News – Latest Cyber News Read the…
Critical TE.0 HTTP Request Smuggling Vulnerability Impacts Thousands of Google Cloud-hosted Websites
This new class of HTTP Request Smuggling vulnerabilities poses a significant risk to thousands of websites, including those protected by Google’s Load Balancer and Identity-Aware Proxy (IAP). This article has been indexed from Cyware News – Latest Cyber News Read…
Critical Splunk Flaw can be Exploited to Grab Passwords
A critical vulnerability (CVE-2024-36991) in Splunk Enterprise on Windows is considered more severe than initially thought, allowing attackers to grab passwords. Various proof-of-concept exploits have been published. This article has been indexed from Cyware News – Latest Cyber News Read…
New Hacker Group Uses Open-Source Tools to Spy on Entities in Asia-Pacific Region
Targets of TAG-100’s attacks include intergovernmental and diplomatic entities in the Asia-Pacific region, religious organizations in the U.S. and Taiwan, as well as a political party supporting an investigation into the Chinese government. This article has been indexed from Cyware…
Majority of SEC Civil Fraud Case Against SolarWinds Dismissed, but Core Remains
Most of the SEC civil fraud case against SolarWinds was dismissed by a U.S. District Court judge, but key allegations related to misleading investors about cybersecurity practices leading up to the 2020 Sunburst hack remain. This article has been indexed…
Grype: Open-Source Vulnerability Scanner for Container Images, Filesystems
Grype is an open-source vulnerability scanner for container images and filesystems that works with Syft to detect vulnerabilities in major operating system and language-specific packages like Alpine, Debian, Ruby, Java, Python, and more. This article has been indexed from Cyware…
Revolver Rabbit Gang Registers 500,000 Domains for Malware Campaigns
The Revolver Rabbit cybercriminal gang has registered over 500,000 domain names for infostealer campaigns targeting Windows and macOS systems. They utilize registered domain generation algorithms (RDGAs) to rapidly register multiple domains at once. This article has been indexed from Cyware…
CISA Appoints New Cybersecurity, Stakeholder Group Leaders
The Cybersecurity and Infrastructure Security Agency (CISA) has appointed new leaders to its cybersecurity division and stakeholder engagement role to enhance national cyber defenses and foster collaboration between the public and private sectors. This article has been indexed from Cyware…
Exchange Online Adds Inbound DANE with DNSSEC for Security Boost
This new capability combines DNS-based Authentication of Named Entities (DANE) for SMTP and Domain Name System Security Extensions (DNSSEC) to protect against downgrade and man-in-the-middle attacks. This article has been indexed from Cyware News – Latest Cyber News Read the…
New Malware Campaign Exploiting RDPWrapper and Tailscale Targets Cryptocurrency Users
By configuring multiple RDP sessions with RDPWrapper and using Tailscale for secure network connections, attackers can maintain access and exfiltrate sensitive data discreetly. This article has been indexed from Cyware News – Latest Cyber News Read the original article: New…
New Cyware Survey Reveals Critical Gaps in Cybersecurity Threat Intelligence Sharing and Collaboration
As per the Cyware survey, 91% of respondents recognize the significance of collaboration in cybersecurity, but many struggle to effectively combine insights across teams and platforms. This article has been indexed from Cyware News – Latest Cyber News Read the…
Attacks on Israeli Orgs ‘More Than Doubled’ Since October 7, Cyber Researcher Says
Cyberattacks on Israeli organizations have more than doubled since the October 7 terrorist attack, with politically-motivated groups like hackers affiliated with Iran and Hezbollah, along with hacktivists, being the main drivers behind these attacks. This article has been indexed from…
Critical Cisco Bug Lets Hackers Add Root Users on SEG Devices
Cisco has addressed a critical vulnerability that allows attackers to add new users with root privileges and crash Security Email Gateway (SEG) appliances by sending emails with malicious attachments. This article has been indexed from Cyware News – Latest Cyber…
SolarWinds Fixes Eight Critical Bugs in Access Rights Audit Software
The vulnerabilities (CVE-2024-23469, CVE-2024-23466, CVE-2024-23467, CVE-2024-28074, CVE-2024-23471, and CVE-2024-23470) were all rated with severity scores of 9.6/10 and posed risks of unauthorized actions and information disclosure. This article has been indexed from Cyware News – Latest Cyber News Read the…
Firms Skip Security Reviews of Updates About Half the Time
A recent poll of tech managers from CrowdStrike’s 2024 State of Application Security Report revealed that cybersecurity workers only review major updates to software applications 54% of the time. This article has been indexed from Cyware News – Latest Cyber…