Iranian Hackers Deploy WezRat Malware in Attacks Targeting Israeli Organizations

November 15, 2024 at 01:00PM Cybersecurity company Check Point has identified a remote access trojan named WezRat, attributed to Iranian state-sponsored hackers. It enables malicious activities like keylogging and file uploads. Distributed via phishing emails mimicking Israeli authorities, WezRat shows ongoing development, indicating significant investment in cyber espionage targeting various global entities. ### Meeting Takeaways: … Read more

Check Point to Acquire External Cyber Risk Management Firm Cyberint

August 28, 2024 at 08:49AM Check Point Software Technologies, a cybersecurity firm, has agreed to acquire Cyberint Technologies for an estimated $200 million, combining threat intelligence with attack surface reconnaissance to enhance security operations. Cyberint’s platform, utilizing dark web data harvesting and continuous testing, will integrate into Check Point’s Infinity Platform to offer comprehensive security … Read more

20K Ubiquiti IoT Cameras & Routers Are Sitting Ducks for Hackers

August 5, 2024 at 04:17PM Researchers warn that tens of thousands of Ubiquiti Inc. small office/home office (SOHO) devices are vulnerable to a five-year-old bug, potentially leading to denial-of-service attacks. Despite patches, around 20,000 devices remain vulnerable, with risks of data leakage and unauthorized access. The issue highlights the broader challenge of IoT security and … Read more

Check Point warns customers to patch VPN vulnerability under active exploitation

June 3, 2024 at 08:12AM Cybersecurity software vendor Check Point detected a zero-day vulnerability being actively exploited. The vulnerability, assigned CVE-2024-24919, affects several Check Point products and can result in unauthorized access to sensitive information. Check Point advised users to update their software and harden their VPN posture. Additionally, various other critical vulnerabilities in different … Read more

Check Point VPN zero-day exploited in attacks since April 30

May 29, 2024 at 03:45PM Threat actors are exploiting a high-severity zero-day vulnerability in Check Point Remote Access VPN, stealing Active Directory data to move through victims’ networks. Check Point warns customers of attackers targeting their security gateways using old VPN local accounts with insecure password-only authentication. The company has released hotfixes to block exploitation … Read more

Check Point releases emergency fix for VPN zero-day exploited in attacks

May 29, 2024 at 09:34AM Check Point releases hotfixes for VPN zero-day exploited in attacks targeting remote access to firewalls and corporate networks. The vulnerability (CVE-2024-24919) affects Check Point Security Gateways and impacts various product versions. Security updates have been issued, and installation instructions provided. A remote access validation script is available to review results … Read more

Hackers target Check Point VPNs to breach enterprise networks

May 27, 2024 at 02:24PM Check Point warns of ongoing campaign targeting Remote Access VPN devices, affecting enterprise networks. Attackers exploit old local accounts’ insecure password-only authentication. Check Point advises customers to secure accounts and install a hotfix to block login attempts using password-only authentication. Cisco also reported credential brute-forcing attacks on VPN and SSH … Read more

Iranian MOIS-Linked Hackers Behind Destructive Attacks on Albania and Israel

May 20, 2024 at 12:27PM Iranian threat actor affiliated with the Ministry of Intelligence and Security (MOIS) conducts destructive wiping attacks in Albania and Israel. Cybersecurity firm Check Point tracks the activity as Void Manticore, also known as Storm-0842. The group uses wiper malware and leverages publicly available tools for attacks, demonstrating a high degree … Read more

Critical Flaw in AI Python Package Can Lead to System and Data Compromise

May 17, 2024 at 09:57AM A critical vulnerability, tracked as CVE-2024-34359 and named Llama Drama, was discovered in a Python package used by AI developers. The flaw allows for arbitrary code execution, posing a risk to systems and data. Cybersecurity firm Checkpoint detailed the issue, and a patch has been released with llama_cpp_python 0.2.72. More … Read more

Magnet Goblin hackers use 1-day flaws to drop custom Linux malware

March 10, 2024 at 11:42AM Magnet Goblin, a financially motivated hacking group, exploits 1-day vulnerabilities to breach public-facing servers and deploy custom malware on Windows and Linux systems. They target devices and services like Ivanti Connect Secure, Apache ActiveMQ, ConnectWise ScreenConnect, Qlik Sense, and Magento. Check Point analysts emphasize the importance of timely patching and … Read more