Cyber News - Page 12

Home > Cyber News

This category contains informative articles and news.
Cyber News about data breaches, online privacy and security, computer security threats, cybersecurity reports, vulnerability reports. News about the latest malware attacks.
Hot news about the security of Microsoft (Patch Tuesdays), Google, Android, Apple, Linux, and other big companies and software vendors.

CYBER NEWS
Nitrokod Crypto Miner Infects Thousands of Machines in 11 Countries

Nitrokod Crypto Miner Infects Thousands of Machines in 11 Countries

A Turkish-based cryptocurrency mining malware (crypto miner) campaign has been detected. Called Nitrokod and discovered by the Check Point Research team, the campaign has infected machines across 11 countries with a XMRig crypto miner. Nitrokod Cryptominer Campaign: Some Details The…

CYBER NEWS
Malware Statistics 2022: Ransomware Continues to Be the Top Threat

Malware Statistics 2022: Ransomware Continues to Be the Top Threat

A new report by NCC Group sheds light on the threat landscape for the past month (July 2022). Apparently, ransomware attacks are once again on the rise, with LockBit being the most active ransomware in the wild. What else has…

CYBER NEWS
LockBit Ransomware Adds DDoS and Triple Extortion to Its Operation

LockBit Ransomware Adds DDoS, Triple Extortion to Its Operation

The LockBit ransomware group is now working towards improving its protection against DDoS attacks as well as adding triple extortion to its malicious operations. These actions are triggered by a recent clash between LockBit criminals and security firm Entrust. LockBit…

CYBER NEWS
CVE-2022-36804: Critical Atlassian Bitbucket Server Flaw

CVE-2022-36804: Critical Atlassian Bitbucket Server Flaw

Another critical Atlassian vulnerability has been reported in numerous API endpoints of Bitbucket Server and Data Center. The vulnerability in question is CVE-2022-36804, a command injection issue in version 7.0.0 of Bitbucket Server and Data Center. CVE-2022-36804: Atlassian Bitbucket Server…

CYBER NEWS
MagicWeb Post-Exploitation Malware Targets AD FS Servers

MagicWeb Post-Exploitation Malware Targets AD FS Servers

MagicWeb is the name of a new post-exploitation (post-compromise) tool discovered and detailed by Microsoft security researchers. The tool is attributed to the Nobelium APT (advanced persistent threat) group which uses it to maintain persistent access to compromised systems. This…

CYBER NEWS
CVE-2022-2884 gitlab vulnerability

CVE-2022-2884: Critical GitLab Vulnerability Enables Remote Code Execution

GitLab revealed a critical vulnerability for branches 15.1, 15.2, and 15.3 of its community and enterprise editions. The vulnerability, identified as CVE-2022-2884 and rated 9.9 on the CVSS scale, could enable a threat actor to carry out remote command execution…

CYBER NEWS
CVE-2022-2588: Dirty Cred Linux Kernel Vulnerability

CVE-2022-2588: Dirty Cred Linux Kernel Vulnerability

CVE-2022-2588, also known as Dirty Cred, is an eight-year old vulnerability in the Linux kernel that has been described as “as nasty as Dirty Pipe”. The Connection Between CVE-2022-2588 and CVE-2022-0847 Dirty Pipe, or CVE-2022-0847, was disclosed earlier this year…

CYBER NEWS
PureCrypter: Fully Featured Malware Loader for Sale for $59

DarkTortilla Crypter Malware Delivers Cobalt Strike, Metasploit

DarkTortilla is a sophisticated and highly configurable crypter malware that delivers popular infostealers and remote access trojans including AgentTesla, AsyncRAT, Redline and NanoCore. What Is the DarkTortilla Crypter? A crypter is a type of software that has the capabilities to…

CYBER NEWS
VibeProfile Mac Virus - How to Remove [Free Guide]

Apple Fixed Two Actively Exploited Zero-Days [CVE-2022-32893]

Two zero-days were fixed by Apple in the following operating systems – macOS, iOS and iPadOS. The zero-days, known as CVE-2022-32893 and CVE-2022-32894, have been exploited in the wild against exposed devices. CVE-2022-32893 and CVE-2022-32894 in macOS, iOS and iPadOS…

CYBER NEWS
CVE-2022-2856 Critical Chrome Bug Exploited in the Wild

CVE-2022-2856 Critical Chrome Bug Exploited in the Wild

An actively exploited, highly severe zero-day vulnerability has been fixed in Google Chrome desktop. The vulnerability has been assigned the CVE-2022-2856 identifier. Details about CVE-2022-2856 According to the official description, CVE-2022-2856 relates to an insufficient validation of untrusted input in…

CYBER NEWS
SOVA Android Malware Upgraded with a Ransomware Module [.enc Files]

SOVA Android Malware Upgraded with a Ransomware Module [.enc Files]

SOVA is an Android banking trojan that first appeared in an underground forum in September 2021. Even the first iterations of the malware had plenty of functionalities, with the most recent ones updated with new features and code improvements. SOVA…

CYBER NEWS
orchard botnet

Orchard Botnet Uses Satoshi Nakamoto’s Account Information to Generate Domain Names

Orchard is the name of a new botnet taking advantage of Bitcoin’s creator Satoshi Nakamoto’s account transaction information to generate DGA [Domain Generation Algorithms] domain names. This is done to conceal the botnet’s command-and-control infrastructure. “Because of the uncertainty of…

CYBER NEWS
GwisinLocker ransomware

GwisinLocker Ransomware Targets Windows and Linux in Attacks against Companies

GwisinLocker is a new ransomware family targeting South Korean industrial and pharmaceutical companies. Capable of compromising both Windows and Linux systems, GwisinLocker has been coded by a relatively unknown threat actor, called Gwisin (meaning ghost or spirit in Korean). Security…

CYBER NEWS
CVE-2022-31656: Critical VMware Authentication Bypass Vulnerability

CVE-2022-31656: Critical VMware Authentication Bypass Vulnerability

VMware recently released another set of patches addressing a number of vulnerabilities in several products. The vulnerabilities (CVE-2022-31656, CVE-2022-31657, CVE-2022-31658, CVE-2022-31659, CVE-2022-31660, CVE-2022-31661, CVE-2022-31662, CVE-2022-31663, CVE-2022-31664, CVE-2022-31665) were reported privately. The severity scores of the flaws vary from 4.7 to…

CYBER NEWS
LockBit Ransomware Leverages Windows Defender to Drop Cobalt Strike

LockBit Ransomware Leverages Windows Defender to Drop Cobalt Strike

The well-known LockBit ransomware has been receiving significant updates, as evident by the reports of several cybersecurity vendors. New Version of LockBit Observed in the Wild According to SentinelLabs, a new iteration of the ransomware has been deployed in the…

CYBER NEWS
hiddenads android malware

HiddenAds Android Malware Can Auto-Start on Your Device

New auto-starting malware on the Google Play Store has been identified. HiddenAds Android Malware The malware is propagated with the help of malicious apps masquerading themselves as cleaner and optimization apps for device management. The Android apps were distributed on…

CYBER NEWS
Beware: High Quality Fake Investment Phishing Scams in the Wild

Beware: High Quality Fake Investment Phishing Scams in the Wild

Security researchers recently uncovered a large network of fake investment scamming sites targeting specific European countries and North America. Fake Investment Phishing Sites Targeting European Countries The network consists of at least 11,000 domains that target the United Kingdom, Belgium,…

CYBER NEWS
Decentralized IPFS Platform Is the Latest Trend in Phishing Campaigns

Decentralized IPFS Platform Is the Latest Trend in Phishing Campaigns

Security researchers share a new trend in phishing campaigns which now utilize the so-called IPFS URLs as payload. The discovery comes from TrustWave researchers who came across a site called the Chameleon Phishing page. Websites like this one can change…

CYBER NEWS
Robin Banks Phishing-as-a-Service Platform Targets Citibank Credentials

Robin Banks Phishing-as-a-Service Platform Targets Citibank Credentials

Security researchers detail a new phishing-as-a-service (Phaas) platform in a recently released report. The platform is an example of how initial access brokers gain a foothold in organizations’ networks. Robin Banks is the name of a new PhaaS platform which,…

CYBER NEWS
countries with the most unsecured wi-fi networks-sensorstechforum-com

Which Countries Have the Most Unsecured Wi-Fi Networks?

Unsecured wi-fi networks have proven to be a gateway to many attacks. More particularly, poorly configured access point encryption (or services that allow data to be sent without being encrypted) has been outlined as one of the biggest threats to…

This website uses cookies to improve user experience. By using our website you consent to all cookies in accordance with our Privacy Policy.
I Agree