❌

Normal view

There are new articles available, click to refresh the page.
Before yesterdaySecurity News

Experts Find Flaw in Replicate AI Service Exposing Customers' Models and Data

By: Newsroom
25 May 2024 at 09:11
Cybersecurity researchers have discovered a critical security flaw in an artificial intelligence (AI)-as-a-service providerΒ ReplicateΒ that could have allowed threat actors to gain access to proprietary AI models and sensitive information. "Exploitation of this vulnerability would have allowed unauthorized access to the AI prompts and results of all Replicate's platform customers,"

Pakistan-linked Hackers Deploy Python, Golang, and Rust Malware on Indian Targets

By: Newsroom
27 May 2024 at 06:31
The Pakistan-nexusΒ Transparent TribeΒ actor has been linked to a new set of attacks targeting Indian government, defense, and aerospace sectors using cross-platform malware written in Python, Golang, and Rust. "This cluster of activity spanned from late 2023 to April 2024 and is anticipated to persist," the BlackBerry Research and Intelligence TeamΒ saidΒ in a technical report

New Tricks in the Phishing Playbook: Cloudflare Workers, HTML Smuggling, GenAI

By: Newsroom
27 May 2024 at 09:02
Cybersecurity researchers are alerting of phishing campaigns that abuseΒ Cloudflare WorkersΒ to serve phishing sites that are used to harvest users' credentials associated with Microsoft, Gmail, Yahoo!, and cPanel Webmail. The attackΒ method,Β called transparent phishing or adversary-in-the-middle (AitM) phishing, "uses Cloudflare Workers to act as a reverse proxy server for a

Moroccan Cybercrime Group Steals Up to $100K Daily Through Gift Card Fraud

By: Newsroom
27 May 2024 at 12:12
Microsoft is calling attention to a Morocco-based cybercrime group dubbedΒ Storm-0539Β that's behind gift card fraud and theft through highly sophisticated email and SMS phishing attacks. "Their primary motivation is to steal gift cards and profit by selling them online at a discounted rate," the companyΒ saidΒ in its latest Cyber Signals report. "We've seen some examples where

Yesterday β€” 28 May 2024Security News

TP-Link Gaming Router Vulnerability Exposes Users to Remote Code Attacks

By: Newsroom
28 May 2024 at 05:11
A maximum-severity security flaw has been disclosed in theΒ TP-Link Archer C5400X gaming routerΒ that could lead to remote code execution on susceptible devices by sending specially crafted requests. The vulnerability, tracked asΒ CVE-2024-5035, carries a CVSS score of 10.0. It impacts all versions of the router firmwareΒ includingΒ andΒ prior toΒ 1_1.1.6. It has&nbsp

WordPress Plugin Exploited to Steal Credit Card Data from E-commerce Sites

By: Newsroom
28 May 2024 at 06:30
Unknown threat actors are abusing lesser-known code snippet plugins for WordPress to insert malicious PHP code in victim sitesΒ that areΒ capable of harvesting credit card data. The campaign, observed by Sucuri on May 11, 2024, entailsΒ the abuse ofΒ a WordPress plugin calledΒ Dessky Snippets, which allows users to add custom PHP code. It has over 200 active installations.

Researchers Warn of CatDDoS Botnet and DNSBomb DDoS Attack Technique

By: Newsroom
28 May 2024 at 10:15
The threat actors behind the CatDDoS malware botnet have exploited over 80 known security flaws in various software over the past three months to infiltrate vulnerable devices and co-opt them into a botnet for conducting distributed denial-of-service (DDoS) attacks. "CatDDoS-related gangs' samples have used a large number of known vulnerabilities to deliver samples," the QiAnXin XLab teamΒ 

Indian National Pleads Guilty to $37 Million Cryptocurrency Theft Scheme

By: Newsroom
28 May 2024 at 12:50
An Indian national has pleaded guilty in the U.S. over charges of stealing more than $37 million by setting up a website that impersonated the Coinbase cryptocurrency exchange platform. Chirag Tomar, 30, pleaded guilty to wire fraud conspiracy, which carries a maximum sentence of 20 years in prison and a $250,000 fine. He was arrested on December 20, 2023, upon entering the country. "Tomar and

Today β€” 29 May 2024Security News

BreachForums Returns Just Weeks After FBI Seizure - Honeypot or Blunder?

By: Newsroom
29 May 2024 at 07:11
The online criminal bazaar BreachForums has been resurrected merely two weeks after a U.S.-led coordinated law enforcement action dismantled and seized control of its infrastructure. Cybersecurity researchers and dark web trackers Brett Callow, Dark Web Informer, and FalconFeeds revealed the site's online return at breachforums[.]st – one of the dismantled sites – by a user named ShinyHunters,

Microsoft Uncovers 'Moonstone Sleet' β€” New North Korean Hacker Group

By: Newsroom
29 May 2024 at 10:35
A never-before-seen North Korean threat actor codenamed Moonstone Sleet has been attributed as behind cyber attacks targeting individuals and organizations in the software and information technology, education, and defense industrial base sectors with ransomware and bespoke malware previously associated with the infamous Lazarus Group. "Moonstone Sleet is observed to set up fake companies and

New Research Warns About Weak Offboarding Management and Insider Risks

By: Newsroom
29 May 2024 at 11:31
A recent study by Wing Security found that 63% of businesses may have former employees with access to organizational data, and that automating SaaS Security can help mitigate offboarding risks.Β  Employee offboarding is typically seen as a routine administrative task, but it can pose substantial security risks, if not handled correctly. Failing to quickly and thoroughly remove access for

U.S. Sentences 31-Year-Old to 10 Years for Laundering $4.5M in Email Scams

By: Newsroom
29 May 2024 at 11:50
The U.S. Department of Justice (DoJ) has sentenced a 31-year-old man to 10 years in prison for laundering more than $4.5 million through business email compromise (BEC) schemes and romance scams. Malachi Mullings, 31, of Sandy Springs, Georgia pleaded guilty to the money laundering offenses in January 2023. According to court documents, Mullings is said to have opened 20 bank accounts in the

Brazilian Banks Targeted by New AllaKore RAT Variant Called AllaSenha

By: Newsroom
29 May 2024 at 14:58
Brazilian banking institutions are the target of a new campaign that distributes a custom variant of the Windows-based AllaKore remote access trojan (RAT) called AllaSenha. The malware is "specifically aimed at stealing credentials that are required to access Brazilian bank accounts, [and] leverages Azure cloud as command-and-control (C2) infrastructure," French cybersecurity company HarfangLab

Check Point Warns of Zero-Day Attacks on its VPN Gateway Products

By: Newsroom
29 May 2024 at 15:16
Check Point is warning of a zero-day vulnerability in its Network Security gateway products that threat actors have exploited in the wild. Tracked as CVE-2024-24919, the issue impacts CloudGuard Network, Quantum Maestro, Quantum Scalable Chassis, Quantum Security Gateways, and Quantum Spark appliances. "The vulnerability potentially allows an attacker to read certain information on

Cybercriminals Abuse StackOverflow to Promote Malicious Python Package

By: Newsroom
29 May 2024 at 17:22
Cybersecurity researchers have warned of a new malicious Python package that has been discovered in the Python Package Index (PyPI) repository to facilitate cryptocurrency theft as part of a broader campaign. The package in question is pytoileur, which has been downloaded 316 times as of writing. Interestingly, the package author, who goes by the name PhilipsPY, has uploaded a new version of the

❌
❌