Sneaky Skimmer Malware Targets Magento Sites Ahead of Black Friday
A stealthy JavaScript injection attack steals data from the checkout page of sites, either by creating a fake credit card form or extracting data directly from payment fields.
Design flaw in Fortinet VPN server lets attackers hide logins
While failed login attempts are logged during the authentication phase, successful logins are only logged if the process advances to the authorization phase.
U.K. launches AI security lab to combat nation-state cyber threats
The lab, which was described as part of the "new AI arms race," will receive initial funding of around $10.3 million from the government, with additional contributions expected from private industry partners through a catalytic model.
Chinese hackers eyeing U.S. critical infrastructure for potential conflict
Morgan Adamski, executive director of U.S. Cyber Command, revealed that these operations aim to secure strategic advantages by compromising systems essential for national functionality, such as energy, water, and IT infrastructure.
Cybercriminals target Black Friday shoppers with AI-made fake online stores
Between August and October, the detection of fraudulent e-commerce sites rose by 110%, with tens of thousands of these hosted on SHOPYY, a Chinese e-commerce platform exploited by cybercriminals.
High severity RCE flaws among several newly addressed IBM bugs
Attackers could exploit the Data Virtualization Manager for z/OS flaw, tracked as CVE-2024-52899, to facilitate malicious JDBC URL parameter injections and run arbitrary code, while the Security SOAR prototype pollution issue, tracked as CVE-2024...