Tag: latestcybersecuritynews

Lokibot AgentTesla Grow in January 2023’s Most Wanted Malware List
Risk, Security

Lokibot AgentTesla Grow in January 2023’s Most Wanted Malware List

According to Check Point's Global Threat Index report for January 2023, AgentTesla is back in the top three spots on the list of the Most Wanted Malware for January 2023 after falling to ninth place in December 2022. The Lokibot info stealer has also advanced significantly, moving up the ranking from not even making the top 10 to second. Furthermore, the data-stealer Vidar, which was seen spreading through phony domains purporting to be connected with remote desktop software provider AnyDesk, has re-entered the top 10 list following an upsurge in incidents of "brandjacking." To drive users to a single IP address posing as the legitimate AnyDesk website, the malware employed URL jacking for a number of well-known applications Check Point read more Lokibot AgentTesla Grow in January ...
Threat Actors Use ClickFunnels to Bypass Security Services
Risk, Security

Threat Actors Use ClickFunnels to Bypass Security Services

Threat actors have been observed navigating around security measures and rerouting users to malicious links by using the trusted ClickFunnels service. Avanan, a Check Point Software company, had security researchers discuss the findings in an advisory that was shared with Infosecurity and released earlier today. According to Jeremy Fuchs, marketing content manager at Avanan, "ClickFunnels is an internet tool that helps entrepreneurs and small businesses generate leads, construct marketing engines, and expand their enterprises." However, hackers are using it to get around security measures. Threat actors have specifically taken advantage of ClickFunnels read the complete article Threat Actors Use ClickFunnels to Bypass Security Services. You can protect your business and yourse...
CISA Alert: Oracle E-Business Suite and SugarCRM Vulnerabilities Under Attack
Risk, Security

CISA Alert: Oracle E-Business Suite and SugarCRM Vulnerabilities Under Attack

On February 2, the U.S. Cybersecurity and Infrastructure Security Agency (CISA), citing evidence of active exploitation, added two security weaknesses to its Known Exploited Vulnerabilities (KEV) Catalog. The first of the two flaws is CVE-2022-21587 (CVSS score: 9.8), a serious problem affecting Oracle Web Applications Desktop Integrator versions 12.2.3 through 12.2.11. An unauthenticated attacker with network access via HTTP could compromise Oracle Web Applications Desktop Integrator by using a vulnerability in the Oracle E-Business Suite, according to CISA read the complete article Oracle E Business Suite and SugarCRM Vulnerabilities Under Attack. You can protect your business and yourself by keeping up with the latest cybersecurity news and articles with the help of reconbee.c...