New Phishing Attack Hijacks Email Thread to Inject Malicious URL

Researchers discovered a new campaign delivering DarkGate and PikaBot that employs strategies similar to those employed in QakBot phishing attempts. This operation sends out a large number of emails to a variety of industries, and because the malware transmitted has loader capabilities, recipients may be vulnerable to more complex threats such as reconnaissance malware and […]

The post New Phishing Attack Hijacks Email Thread to Inject Malicious URL appeared first on GBHackers on Security | #1 Globally Trusted Cyber Security News Platform.

November 21, 2023
Read More >>

Former Infosec COO Pleads Guilty for Hacking Hospitals

Former COO of the Atlanta-based cybersecurity company Securolytics, Vikas Singla, launched a series of cyberattacks on the non-profit healthcare organization Gwinnett Medical Center (GMC), which has locations in Lawrenceville and Duluth, Georgia. GMC suffered a financial loss of $817,804.12 as a result of the defendant’s computer intrusions that affected the GMC ASCOM phone system, printers, […]

The post Former Infosec COO Pleads Guilty for Hacking Hospitals appeared first on GBHackers on Security | #1 Globally Trusted Cyber Security News Platform.

November 21, 2023
Read More >>

Hackers Abusing WhatsApp Messages to Install Android Malware

Embarking on a journey into the realm of cyber threats, Microsoft recently uncovered a series of mobile banking trojan campaigns meticulously designed to exploit unsuspecting users in India.  This expose delves into the sophisticated strategies employed by cybercriminals utilizing social media platforms like WhatsApp and Telegram to manipulate users into installing malicious apps, posing as […]

The post Hackers Abusing WhatsApp Messages to Install Android Malware appeared first on GBHackers on Security | #1 Globally Trusted Cyber Security News Platform.

November 21, 2023
Read More >>

FCC Implemented New Rules to Combat SIM Swapping Attacks

In a pivotal decision on November 15, 2023, the Federal Communications Commission (FCC) orchestrated a formidable defensive strategy against insidious scams targeting consumers’ cell phone accounts.  This comprehensive report delves into the intricacies of the newly adopted rules, designed to thwart the increasingly prevalent threats of SIM swapping and port-out fraud. The heart of the […]

The post FCC Implemented New Rules to Combat SIM Swapping Attacks appeared first on GBHackers on Security | #1 Globally Trusted Cyber Security News Platform.

November 21, 2023
Read More >>

Yamaha Ransomware Attack: Employees Personal Information Exposed

A ransomware attack targeted Yamaha Motor Co., Ltd., resulting in a partial disclosure of the personal information maintained by the company. Notably, a third party gained unauthorized access to one of the servers run by Yamaha Motor Philippines, Inc. (YMPH), its motorcycle manufacturing and sales division in the Philippines. “Yamaha Motor Philippines, Inc. (YMPH) was […]

The post Yamaha Ransomware Attack: Employees Personal Information Exposed appeared first on GBHackers on Security | #1 Globally Trusted Cyber Security News Platform.

November 20, 2023
Read More >>

AMIDES – Open-source Detection System to Uncover SIEM Blind Points

Cyberattacks pose a significant risk, and prevention alone isn’t enough, so timely detection is crucial. That’s why most organizations use SIEM (Security Information and Event Management) systems to centrally collect and analyze security events with expert-written rules for detecting intrusions. Organizations use SIEM rulesets for intrusion detection, focusing on misuse patterns for known attacks. It’s […]

The post AMIDES – Open-source Detection System to Uncover SIEM Blind Points appeared first on GBHackers on Security | #1 Globally Trusted Cyber Security News Platform.

November 20, 2023
Read More >>

Critical AI Tool Vulnerabilities Let Attackers Execute Arbitrary Code

Multiple critical flaws in the infrastructure supporting AI models have been uncovered by researchers, which raise the risk of server takeover, theft of sensitive information, model poisoning, and unauthorized access. Affected are platforms that are essential for hosting and deploying large language models, including Ray, MLflow, ModelDB, and H20. While some vulnerabilities have been addressed, others have not received a […]

The post Critical AI Tool Vulnerabilities Let Attackers Execute Arbitrary Code appeared first on GBHackers on Security | #1 Globally Trusted Cyber Security News Platform.

November 20, 2023
Read More >>

Kubernetes Security on AWS: A Practical Guide

Kubernetes security is safeguarding your Kubernetes clusters, the applications they host, and the infrastructure they rely on from threats. As a container orchestration platform, Kubernetes is incredibly powerful but presents a broad attack surface for potential adversaries. Kubernetes security encompasses several strategies and best practices to mitigate this risk, including hardening your containers and hosts, […]

The post Kubernetes Security on AWS: A Practical Guide appeared first on GBHackers on Security | #1 Globally Trusted Cyber Security News Platform.

November 18, 2023
Read More >>

FortiSIEM Injection Flaw: Let Attackers Execute Malicious Commands

Fortinet notifies users of a critical OS command injection vulnerability in the FortiSIEM report server that might enable an unauthenticated, remote attacker to execute malicious commands via crafted API requests. FortiSIEM is Fortinet’s security information and event management (SIEM) solution, which assists in identifying insider and incoming threats that could pass standard defenses.  “An improper […]

The post FortiSIEM Injection Flaw: Let Attackers Execute Malicious Commands appeared first on GBHackers on Security | #1 Globally Trusted Cyber Security News Platform.

November 17, 2023
Read More >>