Saturday, December 28, 2024

Cyware Social-Cybersecurity News.

"Latest cybersecurity news and articles."

Views expressed in this cybersecurity, cyber crime update are those of the reporters and correspondents.  Accessed on 28 December 2024, 2259 UTC.

Content and Source:  https://social.cyware.com/cyber-security-news-articles

Please check link or scroll down to read your selections.  Thanks for joining us today.

Russ Roberts (https://www.hawaiicybersecurityjournal.net).

Latest Cybersecurity News and Articles


Please scroll down to bring up your articles.  There are spaces between each article.

December 27, 2024

Cyber Espionage Cluster Paper Werewolf Engages in Destructive Behavior

The BI.ZONE Threat Intelligence team has recorded a surge in the activity of the Paper Werewolf cluster (aka GOFFEE), which has conducted at least seven campaigns since 2022. Victims include government, energy, financial, media, and other sectors.

Critical SSRF Vulnerability (CVE-2024-53353) Found in Invoice Ninja

The flaw allows both local and remote users with permissions to create or edit invoices and low-privileged client portal users to inject malicious payloads during PDF generation in Invoice Ninja.

Fake Zoom Meeting Links Lead to Million-Dollar Cryptocurrency Heist

The phishing links, designed to mimic legitimate Zoom meeting invitations, directed users to a fraudulent domain, “app[.]us4zoom[.]us”, which closely resembled the genuine Zoom interface.

FICORA and Kaiten Botnets Exploit Old D-Link Vulnerabilities for Global Attacks

Cybersecurity researchers are warning about a spike in malicious activity that involves roping vulnerable D-Link routers into two different botnets, a Mirai variant dubbed FICORA and a Kaiten (aka Tsunami) variant called CAPSAICIN.

Cybersecurity Expert Reveals Alarming Tactics Used in Google Impersonation Scams

Cybersecurity expert Brian Krebs uncovered alarming new stories of two victims, Adam Griffin and Tony, who together lost millions of dollars in cryptocurrency to social engineering attacks that combined technical precision and emotional manipulation.

Palo Alto Releases Patch for PAN-OS DoS Flaw — Update Immediately

The flaw, tracked as CVE-2024-3393 (CVSS score: 8.7), impacts PAN-OS versions 10.X and 11.X, and Prisma Access running PAN-OS versions. It has been addressed in PAN-OS 10.1.14-h8, PAN-OS 10.2.10-h12, PAN-OS 11.1.5, PAN-OS 11.2.3, and later versions.

New 'OtterCookie' Malware Used to Backdoor Developers in Fake Job Offers

A report from NTT Security Japan found that the Contagious Interview operation is now using a new piece of malware called OtterCookie, which was likely introduced in September and with a new variant appearing in the wild in November.

Critical XXE Vulnerability Discovered in libxml2

The vulnerability, tracked as CVE-2024-40896 (CVSS 9.1) and assigned a critical severity score of 9.1, affects libxml2 versions 2.11 prior to 2.11.9, 2.12 prior to 2.12.9, and 2.13 prior to 2.13.3.

AI Could Generate 10,000 Malware Variants, Evading Detection in 88% of Case

Unit 42 used LLMs to rewrite malware samples, bypassing detection by ML models like Innocent Until Proven Guilty (IUPG) and PhishingJS, creating 10,000 functional JavaScript variants without altering the functionality.

Clop Ransomware is Now Extorting 66 Cleo Data-Theft Victims

The Cleo data theft attack represents another major success for Clop, who leveraged leveraging a zero-day vulnerability in Cleo LexiCom, VLTransfer, and Harmony products to steal data from the networks of breached companies.


No comments:

Post a Comment

Please leave a comment about our recent post.

ZDNet | Security.

"It's official:  All your Office apps are getting AI and a price increase." Views expressed in this cybersecurity, cyber crime...