Apache MINA Vulnerability Let Attackers Execute Remote Code

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A new critical vulnerability (CVE-2024-52046) has been discovered in Apache MINA, potentially allowing attackers to execute remote code by exploiting insecure deserialization processes. This flaw affects multiple versions of the popular networking library, raising significant security concerns. The Vulnerability Explained …

Dell SupportAssist Vulnerability Let Attackers Escalate Privileges

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A newly disclosed high-impact vulnerability in Dell’s widely used SupportAssist software could allow attackers to escalate privileges on affected systems. Identified as CVE-2024-52535, the vulnerability has raised significant concern among cybersecurity experts and end-users, given its potential to compromise system integrity …

IBM AIX Vulnerability Let Attackers Trigger DoS Condition

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

IBM has reported vulnerabilities in its AIX operating system that could allow attackers to cause a Denial of Service (DoS) condition. The identified vulnerabilities affect specific kernel extensions, potentially disrupting normal system operations. Details of the Vulnerabilities: IBM AIX is …

Researchers Uncovered Dark Web Operation Acquiring KYC Details

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

iProov, a leading provider of biometric identity verification solutions, has uncovered a covert dark web operation aimed at undermining Know Your Customer (KYC) protocols. Detailed in the company’s Quarterly Threat Intelligence Update for Q4 2024, the operation reveals how cybercriminals exploit …

Japan Airlines System Hit by Cyber Attack, Flight Operations Affected

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Japan Airlines (JAL), the nation’s second-largest airline, reported a significant cyberattack on its systems early Thursday morning, causing disruptions to both domestic and international flight operations. The attack, which began at 7:24 AM local time (2224 GMT), targeted the airline’s …

New Sophisticated Attack Weaponizes Windows Defender to Bypass EDR

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated attack technique that weaponizes Windows Defender Application Control (WDAC) to disable Endpoint Detection and Response (EDR) sensors on Windows machines. WDAC, a technology introduced with Windows 10 and Windows Server 2016, was designed to give organizations fine-grained control …

Apache Traffic Control Vulnerability Let Attackers Inject Malicious SQL Commands

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical SQL injection vulnerability, identified as CVE-2024-45387, has been discovered in Apache Traffic Control, a widely used open-source platform for managing large-scale content delivery networks (CDNs). This vulnerability affects versions 8.0.0 through 8.0.1 of the software and has been …

Postman Data Leak – 30,000 Publicly Accessible Workspaces Could Lead Massive Hack

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Researchers uncovered a widespread and alarming trend involving data leaks from Postman, a widely used cloud-based API development and testing platform. The investigation reveals that improper management of Postman workspaces has resulted in over 30,000 publicly accessible collections exposing sensitive …

Apache HugeGraph-Server Vulnerability Lets Attackers Bypass Authentication

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A new security vulnerability, CVE-2024-43441, has been identified in Apache HugeGraph-Server, a widely used open-source graph database system. This flaw, classified as an Authentication Bypass by Assumed-Immutable Data vulnerability, affects versions 1.0 to 1.3 of the software prior to the …

OilRig Hackers Exploiting Windows Kernel 0-day to Attack Organizations

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The Iranian state-sponsored hacking group OilRig, also known as APT34, has intensified its cyber espionage activities, targeting critical infrastructure and government entities in the United Arab Emirates and the broader Gulf region. Security researchers from Picus Labs have uncovered a …