Security News > 2024 > September

North Korean Hackers Targets Job Seekers with Fake FreeConference App
2024-09-04 15:52

North Korean threat actors have leveraged a fake Windows video conferencing application impersonating FreeConference.com to backdoor developer systems as part of an ongoing financially-driven...

Hackers inject malicious JS in Cisco store to steal credit cards, credentials
2024-09-04 15:48

Cisco's site for selling company-themed merchandise is currently offline and under maintenance due to hackers compromising it with JavaScript code that steals sensitive customer details provided...

Google backports fix for Pixel EoP flaw to other Android devices
2024-09-04 15:16

Google has released the September 2024 Android security updates to fix 34 vulnerabilities, including CVE-2024-32896, an actively exploited elevation of privilege flaw that was previously fixed on...

Cicada ransomware may be a BlackCat/ALPHV rebrand and upgrade
2024-09-04 14:29

Researchers find many similarities, and nasty new customizations such as embedded compromised user credentials The Cicada3301 ransomware, which has claimed at least 20 victims since it was spotted...

Criminal IP Earns PCI DSS v4.0 Certification for Top-Level Security
2024-09-04 14:02

AI Spera has achieved PCI DSS v4.0 certification for its threat intel search engine solution, Criminal IP. Learn more from the Criminal IP cyber threat intelligence search engine. [...]

Revival Hijack supply-chain attack threatens 22,000 PyPI packages
2024-09-04 13:43

Threat actors are utilizing an attack called "Revival Hijack," where they register new PyPi projects using the names of previously deleted packages to conduct supply chain attacks. [...]

Android Users Urged to Install Latest Security Updates to Fix Actively Exploited Flaw
2024-09-04 13:36

Google has released its monthly security updates for the Android operating system to address a known security flaw that it said has come under active exploitation in the wild. The high-severity...

Researchers Find Over 22,000 Removed PyPI Packages at Risk of Revival Hijack
2024-09-04 13:00

A new supply chain attack technique targeting the Python Package Index (PyPI) registry has been exploited in the wild in an attempt to infiltrate downstream organizations. It has been codenamed...

North Korean hackers’ social engineering tricks
2024-09-04 12:18

“North Korean malicious cyber actors conducted research on a variety of targets connected to cryptocurrency exchange-traded funds (ETFs) over the last several months,” the FBI has warned through a...

Zyxel Patches Critical OS Command Injection Flaw in Access Points and Routers
2024-09-04 11:27

Zyxel has released software updates to address a critical security flaw impacting certain access point (AP) and security router versions that could result in the execution of unauthorized...