en
Feedback
TECHZONE™

TECHZONE™

Open in Telegram

TECHZONE CYBERNEWS && UPDATES Wᴇʟᴄᴏᴍᴇ Tᴏ TECHZONE™ ✔️Infosec Facts ✔️Cheatsheets ✔️Free Courses ✔️Open source tools ✔️Tech news

Show more
591
Subscribers
No data24 hours
-17 days
-430 days
Posts Archive
North Korean Threat Actors Deploy COVERTCATCH Malware via LinkedIn Job Scams https://thehackernews.com/2024/09/north-korean-threat-actors-deploy.html Threat actors affiliated with North Korea have been observed leveraging LinkedIn as a way to target developers as part of a fake job recruiting operation. These attacks employ coding tests as a common initial infection vector, Google-owned Mandiant said in a new report about threats faced by the Web3 sector. "After an initial chat conversation, the attacker sent a ZIP file that contained

FBI Cracks Down on Dark Web Marketplace Managed by Russian and Kazakh Nationals https://thehackernews.com/2024/09/fbi-cracks-down-on-dark-web-marketplace.html Two men have been indicted in the U.S. for their alleged involvement in managing a dark web marketplace called WWH Club that specializes in the sale of sensitive personal and financial information. Alex Khodyrev, a 35-year-old Kazakhstan national, and Pavel Kublitskii, a 37-year-old Russian national, have been charged with conspiracy to commit access device fraud and conspiracy to commit wire

ESET Research Podcast: HotPage https://www.welivesecurity.com/en/podcasts/eset-research-podcast-hotpage/ ESET researchers discuss HotPage, a recently discovered adware armed with a highest-privilege, yet vulnerable, Microsoft-signed driver

SonicWall Urges Users to Patch Critical Firewall Flaw Amid Possible Exploitation https://thehackernews.com/2024/09/sonicwall-urges-users-to-patch-critical.html SonicWall has revealed that a recently patched critical security flaw impacting SonicOS may have come under active exploitation, making it essential that users apply the patches as soon as possible. The vulnerability, tracked as CVE-2024-40766, carries a CVSS score of 9.3 out of a maximum of 10. "An improper access control vulnerability has been identified in the SonicWall SonicOS management

GeoServer Vulnerability Targeted by Hackers to Deliver Backdoors and Botnet Malware https://thehackernews.com/2024/09/geoserver-vulnerability-targeted-by.html A recently disclosed security flaw in OSGeo GeoServer GeoTools has been exploited as part of multiple campaigns to deliver cryptocurrency miners, botnet malware such as Condi and JenX, and a known backdoor called SideWalk. The security vulnerability is a critical remote code execution bug (CVE-2024-36401, CVSS score: 9.8) that could allow malicious actors to take over susceptible instances. In

GitHub Actions Vulnerable to Typosquatting, Exposing Developers to Hidden Malicious Code https://thehackernews.com/2024/09/github-actions-vulnerable-to.html Threat actors have long leveraged typosquatting as a means to trick unsuspecting users into visiting malicious websites or downloading booby-trapped software and packages. These attacks typically involve registering domains or packages with names slightly altered from their legitimate counterparts (e.g., goog1e.com vs. google.com). Adversaries targeting open-source repositories across

The State of the Virtual CISO Report: MSP/MSSP Security Strategies for 2025 https://thehackernews.com/2024/09/the-state-of-virtual-ciso-report.html The 2024 State of the vCISO Report continues Cynomi’s tradition of examining the growing popularity of virtual Chief Information Security Officer (vCISO) services. According to the independent survey, the demand for these services is increasing, with both providers and clients reaping the rewards. The upward trend is set to continue, with even faster growth expected in the future. However,

Critical Security Flaw Found in LiteSpeed Cache Plugin for WordPress https://thehackernews.com/2024/09/critical-security-flaw-found-in.html Cybersecurity researchers have discovered yet another critical security flaw in the LiteSpeed Cache plugin for WordPress that could allow unauthenticated users to take control of arbitrary accounts. The vulnerability, tracked as CVE-2024-44000 (CVSS score: 7.5), impacts versions before and including 6.4.1. It has been addressed in version 6.5.0.1.  "The plugin suffers from an

Apache OFBiz Update Fixes High-Severity Flaw Leading to Remote Code Execution https://thehackernews.com/2024/09/apache-ofbiz-update-fixes-high-severity.html A new security flaw has been addressed in the Apache OFBiz open-source enterprise resource planning (ERP) system that, if successfully exploited, could lead to unauthenticated remote code execution on Linux and Windows. The high-severity vulnerability, tracked as CVE-2024-45195 (CVSS score: 7.5), affects all versions of the software before 18.12.16. "An attacker with no valid

Pavel Durov Criticizes Outdated Laws After Arrest Over Telegram Criminal Activity https://thehackernews.com/2024/09/paul-durov-criticizes-outdated-laws.html Telegram CEO Pavel Durov has broken his silence nearly two weeks after his arrest in France, stating the charges are misguided. "If a country is unhappy with an internet service, the established practice is to start a legal action against the service itself," Durov said in a 600-word statement on his Telegram account. "Using laws from the pre-smartphone era to charge a CEO with crimes committed

Chinese-Speaking Hacker Group Targets Human Rights Studies in Middle East https://thehackernews.com/2024/09/chinese-speaking-hacker-group-targets.html Unnamed government entities in the Middle East and Malaysia are the target of a persistent cyber campaign orchestrated by a threat actor known as Tropic Trooper since June 2023. "Sighting this group's [Tactics, Techniques, and Procedures] in critical governmental entities in the Middle East, particularly those related to human rights studies, marks a new strategic move for them," Kaspersky

Veeam Releases Security Updates to Fix 18 Flaws, Including 5 Critical Issues https://thehackernews.com/2024/09/veeam-releases-security-updates-to-fix.html Veeam has shipped security updates to address a total of 18 security flaws impacting its software products, including five critical vulnerabilities that could result in remote code execution. The list of shortcomings is below - CVE-2024-40711 (CVSS score: 9.8) - A vulnerability in Veeam Backup & Replication that allows unauthenticated remote code execution. CVE-2024-42024 (CVSS score: 9.1

The key considerations for cyber insurance: A pragmatic approach https://www.welivesecurity.com/en/business-security/the-key-considerations-for-cyber-insurance-a-pragmatic-approach/ Would a more robust cybersecurity posture impact premium costs? Does the policy offer legal cover? These are some of the questions organizations should consider when reviewing their cyber insurance options

U.S. Seizes 32 Pro-Russian Propaganda Domains in Major Disinformation Crackdown https://thehackernews.com/2024/09/us-seizes-32-pro-russian-propaganda.html The U.S. Department of Justice (DoJ) on Wednesday announced the seizure of 32 internet domains used by a pro-Russian propaganda operation called Doppelganger as part of a sweeping set of actions. Accusing the Russian government-directed foreign malign influence campaign of violating U.S. money laundering and criminal trademark laws, the agency called out companies Social Design Agency (SDA),

NIST Cybersecurity Framework (CSF) and CTEM – Better Together https://thehackernews.com/2024/09/nist-cybersecurity-framework-csf-and.html It’s been a decade since the National Institute of Standards and Technology (NIST) introduced its Cybersecurity Framework (CSF) 1.0. Created following a 2013 Executive Order, NIST was tasked with designing a voluntary cybersecurity framework that would help organizations manage cyber risk, providing guidance based on established standards and best practices. While this version was originally

Malware Attackers Using MacroPack to Deliver Havoc, Brute Ratel, and PhantomCore https://thehackernews.com/2024/09/malware-attackers-using-macropack-to.html Threat actors are likely employing a tool designated for red teaming exercises to serve malware, according to new findings from Cisco Talos. The program in question is a payload generation framework called MacroPack, which is used to generate Office documents, Visual Basic scripts, Windows shortcuts, and other formats for penetration testing and social engineering assessments. It was developed

New Cross-Platform Malware KTLVdoor Discovered in Attack on Chinese Trading Firm https://thehackernews.com/2024/09/new-cross-platform-malware-ktlvdoor.html The Chinese-speaking threat actor known as Earth Lusca has been observed using a new backdoor dubbed KTLVdoor as part of a cyber attack targeting an unnamed trading company based in China. The previously unreported malware is written in Golang, and thus is a cross-platform weapon capable of targeting both Microsoft Windows and Linux systems. "KTLVdoor is a highly obfuscated malware that

Cisco Fixes Two Critical Flaws in Smart Licensing Utility to Prevent Remote Attacks https://thehackernews.com/2024/09/cisco-fixes-two-critical-flaws-in-smart.html Cisco has released security updates for two critical security flaws impacting its Smart Licensing Utility that could allow unauthenticated, remote attackers to elevate their privileges or access sensitive information. A brief description of the two vulnerabilities is below - CVE-2024-20439 (CVSS score: 9.8) - The presence of an undocumented static user credential for an administrative account

In plain sight: Malicious ads hiding in search results https://www.welivesecurity.com/en/malware/in-plain-sight-malicious-ads-hiding-in-search-results/ Sometimes there’s more than just an enticing product offer hiding behind an ad

North Korean Hackers Targets Job Seekers with Fake FreeConference App https://thehackernews.com/2024/09/north-korean-hackers-targets-job.html North Korean threat actors have leveraged a fake Windows video conferencing application impersonating FreeConference.com to backdoor developer systems as part of an ongoing financially-driven campaign dubbed Contagious Interview. The new attack wave, spotted by Singaporean company Group-IB in mid-August 2024, is yet another indication that the activity is also leveraging native installers for