TECHZONE™
Open in Telegram
TECHZONE CYBERNEWS && UPDATES Wᴇʟᴄᴏᴍᴇ Tᴏ TECHZONE™ ✔️Infosec Facts ✔️Cheatsheets ✔️Free Courses ✔️Open source tools ✔️Tech news
Show more591
Subscribers
No data24 hours
-17 days
-430 days
Posts Archive
591
North Korean Threat Actors Deploy COVERTCATCH Malware via LinkedIn Job Scams
https://thehackernews.com/2024/09/north-korean-threat-actors-deploy.html
Threat actors affiliated with North Korea have been observed leveraging LinkedIn as a way to target developers as part of a fake job recruiting operation.
These attacks employ coding tests as a common initial infection vector, Google-owned Mandiant said in a new report about threats faced by the Web3 sector.
"After an initial chat conversation, the attacker sent a ZIP file that contained
591
FBI Cracks Down on Dark Web Marketplace Managed by Russian and Kazakh Nationals
https://thehackernews.com/2024/09/fbi-cracks-down-on-dark-web-marketplace.html
Two men have been indicted in the U.S. for their alleged involvement in managing a dark web marketplace called WWH Club that specializes in the sale of sensitive personal and financial information.
Alex Khodyrev, a 35-year-old Kazakhstan national, and Pavel Kublitskii, a 37-year-old Russian national, have been charged with conspiracy to commit access device fraud and conspiracy to commit wire
591
ESET Research Podcast: HotPage
https://www.welivesecurity.com/en/podcasts/eset-research-podcast-hotpage/
ESET researchers discuss HotPage, a recently discovered adware armed with a highest-privilege, yet vulnerable, Microsoft-signed driver
591
SonicWall Urges Users to Patch Critical Firewall Flaw Amid Possible Exploitation
https://thehackernews.com/2024/09/sonicwall-urges-users-to-patch-critical.html
SonicWall has revealed that a recently patched critical security flaw impacting SonicOS may have come under active exploitation, making it essential that users apply the patches as soon as possible.
The vulnerability, tracked as CVE-2024-40766, carries a CVSS score of 9.3 out of a maximum of 10.
"An improper access control vulnerability has been identified in the SonicWall SonicOS management
591
GeoServer Vulnerability Targeted by Hackers to Deliver Backdoors and Botnet Malware
https://thehackernews.com/2024/09/geoserver-vulnerability-targeted-by.html
A recently disclosed security flaw in OSGeo GeoServer GeoTools has been exploited as part of multiple campaigns to deliver cryptocurrency miners, botnet malware such as Condi and JenX, and a known backdoor called SideWalk.
The security vulnerability is a critical remote code execution bug (CVE-2024-36401, CVSS score: 9.8) that could allow malicious actors to take over susceptible instances.
In
591
GitHub Actions Vulnerable to Typosquatting, Exposing Developers to Hidden Malicious Code
https://thehackernews.com/2024/09/github-actions-vulnerable-to.html
Threat actors have long leveraged typosquatting as a means to trick unsuspecting users into visiting malicious websites or downloading booby-trapped software and packages.
These attacks typically involve registering domains or packages with names slightly altered from their legitimate counterparts (e.g., goog1e.com vs. google.com).
Adversaries targeting open-source repositories across
591
The State of the Virtual CISO Report: MSP/MSSP Security Strategies for 2025
https://thehackernews.com/2024/09/the-state-of-virtual-ciso-report.html
The 2024 State of the vCISO Report continues Cynomi’s tradition of examining the growing popularity of virtual Chief Information Security Officer (vCISO) services. According to the independent survey, the demand for these services is increasing, with both providers and clients reaping the rewards. The upward trend is set to continue, with even faster growth expected in the future. However,
591
Critical Security Flaw Found in LiteSpeed Cache Plugin for WordPress
https://thehackernews.com/2024/09/critical-security-flaw-found-in.html
Cybersecurity researchers have discovered yet another critical security flaw in the LiteSpeed Cache plugin for WordPress that could allow unauthenticated users to take control of arbitrary accounts.
The vulnerability, tracked as CVE-2024-44000 (CVSS score: 7.5), impacts versions before and including 6.4.1. It has been addressed in version 6.5.0.1.
"The plugin suffers from an
591
Apache OFBiz Update Fixes High-Severity Flaw Leading to Remote Code Execution
https://thehackernews.com/2024/09/apache-ofbiz-update-fixes-high-severity.html
A new security flaw has been addressed in the Apache OFBiz open-source enterprise resource planning (ERP) system that, if successfully exploited, could lead to unauthenticated remote code execution on Linux and Windows.
The high-severity vulnerability, tracked as CVE-2024-45195 (CVSS score: 7.5), affects all versions of the software before 18.12.16.
"An attacker with no valid
591
Pavel Durov Criticizes Outdated Laws After Arrest Over Telegram Criminal Activity
https://thehackernews.com/2024/09/paul-durov-criticizes-outdated-laws.html
Telegram CEO Pavel Durov has broken his silence nearly two weeks after his arrest in France, stating the charges are misguided.
"If a country is unhappy with an internet service, the established practice is to start a legal action against the service itself," Durov said in a 600-word statement on his Telegram account.
"Using laws from the pre-smartphone era to charge a CEO with crimes committed
591
Chinese-Speaking Hacker Group Targets Human Rights Studies in Middle East
https://thehackernews.com/2024/09/chinese-speaking-hacker-group-targets.html
Unnamed government entities in the Middle East and Malaysia are the target of a persistent cyber campaign orchestrated by a threat actor known as Tropic Trooper since June 2023.
"Sighting this group's [Tactics, Techniques, and Procedures] in critical governmental entities in the Middle East, particularly those related to human rights studies, marks a new strategic move for them," Kaspersky
591
Veeam Releases Security Updates to Fix 18 Flaws, Including 5 Critical Issues
https://thehackernews.com/2024/09/veeam-releases-security-updates-to-fix.html
Veeam has shipped security updates to address a total of 18 security flaws impacting its software products, including five critical vulnerabilities that could result in remote code execution.
The list of shortcomings is below -
CVE-2024-40711 (CVSS score: 9.8) - A vulnerability in Veeam Backup & Replication that allows unauthenticated remote code execution.
CVE-2024-42024 (CVSS score: 9.1
591
The key considerations for cyber insurance: A pragmatic approach
https://www.welivesecurity.com/en/business-security/the-key-considerations-for-cyber-insurance-a-pragmatic-approach/
Would a more robust cybersecurity posture impact premium costs? Does the policy offer legal cover? These are some of the questions organizations should consider when reviewing their cyber insurance options
591
U.S. Seizes 32 Pro-Russian Propaganda Domains in Major Disinformation Crackdown
https://thehackernews.com/2024/09/us-seizes-32-pro-russian-propaganda.html
The U.S. Department of Justice (DoJ) on Wednesday announced the seizure of 32 internet domains used by a pro-Russian propaganda operation called Doppelganger as part of a sweeping set of actions.
Accusing the Russian government-directed foreign malign influence campaign of violating U.S. money laundering and criminal trademark laws, the agency called out companies Social Design Agency (SDA),
591
NIST Cybersecurity Framework (CSF) and CTEM – Better Together
https://thehackernews.com/2024/09/nist-cybersecurity-framework-csf-and.html
It’s been a decade since the National Institute of Standards and Technology (NIST) introduced its Cybersecurity Framework (CSF) 1.0. Created following a 2013 Executive Order, NIST was tasked with designing a voluntary cybersecurity framework that would help organizations manage cyber risk, providing guidance based on established standards and best practices. While this version was originally
591
Malware Attackers Using MacroPack to Deliver Havoc, Brute Ratel, and PhantomCore
https://thehackernews.com/2024/09/malware-attackers-using-macropack-to.html
Threat actors are likely employing a tool designated for red teaming exercises to serve malware, according to new findings from Cisco Talos.
The program in question is a payload generation framework called MacroPack, which is used to generate Office documents, Visual Basic scripts, Windows shortcuts, and other formats for penetration testing and social engineering assessments. It was developed
591
New Cross-Platform Malware KTLVdoor Discovered in Attack on Chinese Trading Firm
https://thehackernews.com/2024/09/new-cross-platform-malware-ktlvdoor.html
The Chinese-speaking threat actor known as Earth Lusca has been observed using a new backdoor dubbed KTLVdoor as part of a cyber attack targeting an unnamed trading company based in China.
The previously unreported malware is written in Golang, and thus is a cross-platform weapon capable of targeting both Microsoft Windows and Linux systems.
"KTLVdoor is a highly obfuscated malware that
591
Cisco Fixes Two Critical Flaws in Smart Licensing Utility to Prevent Remote Attacks
https://thehackernews.com/2024/09/cisco-fixes-two-critical-flaws-in-smart.html
Cisco has released security updates for two critical security flaws impacting its Smart Licensing Utility that could allow unauthenticated, remote attackers to elevate their privileges or access sensitive information.
A brief description of the two vulnerabilities is below -
CVE-2024-20439 (CVSS score: 9.8) - The presence of an undocumented static user credential for an administrative account
591
In plain sight: Malicious ads hiding in search results
https://www.welivesecurity.com/en/malware/in-plain-sight-malicious-ads-hiding-in-search-results/
Sometimes there’s more than just an enticing product offer hiding behind an ad
591
North Korean Hackers Targets Job Seekers with Fake FreeConference App
https://thehackernews.com/2024/09/north-korean-hackers-targets-job.html
North Korean threat actors have leveraged a fake Windows video conferencing application impersonating FreeConference.com to backdoor developer systems as part of an ongoing financially-driven campaign dubbed Contagious Interview.
The new attack wave, spotted by Singaporean company Group-IB in mid-August 2024, is yet another indication that the activity is also leveraging native installers for
