Cyber News - Page 12

Home > Cyber News

This category contains informative articles and news.
Cyber News about data breaches, online privacy and security, computer security threats, cybersecurity reports, vulnerability reports. News about the latest malware attacks.
Hot news about the security of Microsoft (Patch Tuesdays), Google, Android, Apple, Linux, and other big companies and software vendors.

CYBER NEWS
CVE-2022-2856 Critical Chrome Bug Exploited in the Wild

CVE-2022-2856 Critical Chrome Bug Exploited in the Wild

An actively exploited, highly severe zero-day vulnerability has been fixed in Google Chrome desktop. The vulnerability has been assigned the CVE-2022-2856 identifier. Details about CVE-2022-2856 According to the official description, CVE-2022-2856 relates to an insufficient validation of untrusted input in…

CYBER NEWS
SOVA Android Malware Upgraded with a Ransomware Module [.enc Files]

SOVA Android Malware Upgraded with a Ransomware Module [.enc Files]

SOVA is an Android banking trojan that first appeared in an underground forum in September 2021. Even the first iterations of the malware had plenty of functionalities, with the most recent ones updated with new features and code improvements. SOVA…

CYBER NEWS
orchard botnet

Orchard Botnet Uses Satoshi Nakamoto’s Account Information to Generate Domain Names

Orchard is the name of a new botnet taking advantage of Bitcoin’s creator Satoshi Nakamoto’s account transaction information to generate DGA [Domain Generation Algorithms] domain names. This is done to conceal the botnet’s command-and-control infrastructure. “Because of the uncertainty of…

CYBER NEWS
GwisinLocker ransomware

GwisinLocker Ransomware Targets Windows and Linux in Attacks against Companies

GwisinLocker is a new ransomware family targeting South Korean industrial and pharmaceutical companies. Capable of compromising both Windows and Linux systems, GwisinLocker has been coded by a relatively unknown threat actor, called Gwisin (meaning ghost or spirit in Korean). Security…

CYBER NEWS
CVE-2022-31656: Critical VMware Authentication Bypass Vulnerability

CVE-2022-31656: Critical VMware Authentication Bypass Vulnerability

VMware recently released another set of patches addressing a number of vulnerabilities in several products. The vulnerabilities (CVE-2022-31656, CVE-2022-31657, CVE-2022-31658, CVE-2022-31659, CVE-2022-31660, CVE-2022-31661, CVE-2022-31662, CVE-2022-31663, CVE-2022-31664, CVE-2022-31665) were reported privately. The severity scores of the flaws vary from 4.7 to…

CYBER NEWS
LockBit Ransomware Leverages Windows Defender to Drop Cobalt Strike

LockBit Ransomware Leverages Windows Defender to Drop Cobalt Strike

The well-known LockBit ransomware has been receiving significant updates, as evident by the reports of several cybersecurity vendors. New Version of LockBit Observed in the Wild According to SentinelLabs, a new iteration of the ransomware has been deployed in the…

CYBER NEWS
hiddenads android malware

HiddenAds Android Malware Can Auto-Start on Your Device

New auto-starting malware on the Google Play Store has been identified. HiddenAds Android Malware The malware is propagated with the help of malicious apps masquerading themselves as cleaner and optimization apps for device management. The Android apps were distributed on…

CYBER NEWS
Beware: High Quality Fake Investment Phishing Scams in the Wild

Beware: High Quality Fake Investment Phishing Scams in the Wild

Security researchers recently uncovered a large network of fake investment scamming sites targeting specific European countries and North America. Fake Investment Phishing Sites Targeting European Countries The network consists of at least 11,000 domains that target the United Kingdom, Belgium,…

CYBER NEWS
Decentralized IPFS Platform Is the Latest Trend in Phishing Campaigns

Decentralized IPFS Platform Is the Latest Trend in Phishing Campaigns

Security researchers share a new trend in phishing campaigns which now utilize the so-called IPFS URLs as payload. The discovery comes from TrustWave researchers who came across a site called the Chameleon Phishing page. Websites like this one can change…

CYBER NEWS
Robin Banks Phishing-as-a-Service Platform Targets Citibank Credentials

Robin Banks Phishing-as-a-Service Platform Targets Citibank Credentials

Security researchers detail a new phishing-as-a-service (Phaas) platform in a recently released report. The platform is an example of how initial access brokers gain a foothold in organizations’ networks. Robin Banks is the name of a new PhaaS platform which,…

CYBER NEWS
countries with the most unsecured wi-fi networks-sensorstechforum-com

Which Countries Have the Most Unsecured Wi-Fi Networks?

Unsecured wi-fi networks have proven to be a gateway to many attacks. More particularly, poorly configured access point encryption (or services that allow data to be sent without being encrypted) has been outlined as one of the biggest threats to…

CYBER NEWS
Lightning Framework: New Stealthy, Sophisticated Linux Malware on the Rise

Lightning Framework: New Stealthy, Sophisticated Linux Malware on the Rise

Security researchers detailed the discovery of a new, previously undetected malware sample specifically designed to target the Linux environment. The malware showcases sophisticated capabilities and is “an intricate framework developed for targeting Linux systems,” Intezer researchers said in their technical…

CYBER NEWS
New Luna Ransomware Targets Windows, Linux, and ESXi Systems

New Luna Ransomware Targets Windows, Linux, and ESXi Systems

Security researchers reported the discovery of a new cross-platform ransomware strain coded to target Windows, Linux, and ESXi systems. Meet the New Cross-Platform Luna Ransomware Discovered by Kaspersky’s Darknet Threat Intelligence monitoring system, the so-called Luna ransomware is advertised on…

CYBER NEWS
Apple Fixes 37 Vulnerabilities, Including CVE-2022-2294 Chrome Flaw

Apple Fixes 37 Vulnerabilities, Including CVE-2022-2294 Chrome Flaw

Apple has released fixes addressing 37 software vulnerabilities in its operating systems iOS, iPadOS, macOS, tvOS, and watchOS. The flaws affect different parts of iOS and macOS and could be used for escalation of privilege, arbitrary code execution, information disclosure…

CYBER NEWS
CloudMensis macOS Backdoor Uses Public Cloud Services for Communication

CloudMensis macOS Backdoor Uses Public Cloud Services for Communication

A new macOS backdoor is making rounds in the wild in targeted attacks aiming to steal sensitive information. CloudMensis macOS Backdoor: What’s Known So Far The backdoor, called CloudMensis, is exclusively using public cloud storage services to communicate with the…

CYBER NEWS
Adversary-in-the-Middle (AiTM) Phishing Attacks Target Numerous Organizations

Adversary-in-the-Middle (AiTM) Phishing Attacks Target Numerous Organizations

Microsoft 365 Defender Research Team and Microsoft Threat Intelligence Center (MSTIC) detailed a large-scale phishing campaign that utilized the so-called adversary-in-the-middle (AiTM) phishing sites. The sites were deployed to harvest passwords, hijack sign-in sessions, and skip authentication processes, including MFA…

CYBER NEWS
CVE-2022-26706: Microsoft Uncovers macOS App Sandbox Escape vulnerability

CVE-2022-26706: Microsoft Uncovers macOS App Sandbox Escape vulnerability

Microsoft recently disclosed a macOS vulnerability, identified as CVE-2022-26706, that could allow specially crafted codes to escape the App Sandbox and run unrestricted. The findings have been shared with Apple via the Coordinated Vulnerability Disclosure and Microsoft Security Vulnerability Research…

CYBER NEWS
CVE-2021-22048: Patch Available for VMware Server Flaw

CVE-2021-22048: Patch Available for VMware Server Flaw

CVE-2021-22048 is a high-severity privilege escalation vulnerability in the VMware vCenter Server IWA mechanism, which also affects the Cloud Foundation hybrid platform. Eight months after the vulnerability was disclosed, the company released a patch for one of the affected versions.…

CYBER NEWS
Axie Infinity NFT Gaming Platform Loses $540M in a Spear Phishing Attack

Axie Infinity NFT Gaming Platform Loses $540M in a Spear Phishing Attack

Axie Infinity is a popular blockchain gaming platform which was involved in a large hacking incident resulting in the loss of $540 million in cryptocurrency. The platform is a non-fungible token-based online video game developed by Vietnamese studio Sky Mavis,…

CYBER NEWS
CVE-2022-34265: High Severity Vulnerability in the Django Project

CVE-2022-34265: High Severity Vulnerability in the Django Project

CVE-2022-34265 is a new high severity vulnerability in the Django project, an open-source Python-based web framework. The vulnerability has been reported by Takuto Yoshikai from Aeye Security Lab. CVE-2022-34265: Short Technical Overview The vulnerability has been fixed in Django 4.0.6…

This website uses cookies to improve user experience. By using our website you consent to all cookies in accordance with our Privacy Policy.
I Agree