Two New Malicious PyPI Packages Attacking Users to Steal Login Details

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Two malicious Python Package Index (PyPI) packages: Zebo-0.1.0 and Cometlogger-0.1, have been identified, posing a significant threat to user security. These packages, uploaded in November 2024, exploit unsuspecting developers and users, aiming to steal sensitive data such as login credentials, browsing history, …

Adobe ColdFusion Vulnerability Let Attackers Read arbitrary files – PoC Released

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Adobe has issued updates to address a vulnerability in its ColdFusion software that could allow attackers to read arbitrary files from affected systems. The flaw, identified as CVE-2024-53961, has a proof-of-concept (PoC) exploit publicly available, heightening the urgency for system administrators …

Node.js “systeminformation” Vulnerability Exposes Millions of Systems to RCE Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical security vulnerability has been discovered in the widely-used Node.js package “systeminformation,” potentially exposing millions of systems to remote code execution (RCE) attacks. The flaw, identified as CVE-2024-56334, affects versions up to and including 5.23.6 of the package, which …

Brazilian Hacker Charged for Selling Data Stolen From Hacked Computers

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Junior Barros De Oliveira, a 29-year-old resident of Curitiba, Brazil, has been indicted in the United States for orchestrating an extortion scheme involving data stolen from the computer systems of a Brazilian subsidiary of a New Jersey-based company. U.S. Attorney …

Hackers Deploy AsyncRAT and SectopRAT Using ScreenConnect Software on Windows

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cybercriminal groups are increasingly blending new and traditional techniques to steal sensitive information from unsuspecting users by deploying remote access tools (RATs) such as AsyncRAT and SectopRAT. Recent activity in the cyber threat landscape highlights how attackers are leveraging methods …

Webmin RCE Vulnerability Let Attackers Execute Arbitrary Code & Gain Server Control

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Webmin, the popular web-based system administration tool, has been found to contain a critical security vulnerability that could allow attackers to seize control of servers. The vulnerability, identified as CVE-2024-12828, has been assigned a CVSS score of 9.9, indicating its …

New G-Door Vulnerability Lets Hackers Bypass Microsoft 365 Security With Google Docs

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A newly discovered vulnerability, dubbed “G-Door,” allows malicious actors to circumvent Microsoft 365 security measures by exploiting unmanaged Google Docs accounts. This security flaw poses a significant threat to organizations relying on Microsoft 365’s Conditional Access (CA) policies for protection. …

Threat Actors Exploiting Microsoft Office Vulnerability to Execute Malicious Code

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated cyber-espionage group known as Cloud Atlas has been observed leveraging a critical Microsoft Office vulnerability to launch targeted attacks against organizations in Eastern Europe and Central Asia. According to researchers, the group, active since 2014, has recently unveiled …

WPA3 Network Password Bypassed via MITM Attack & Social Engineering

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Researchers have successfully bypassed the Wi-Fi Protected Access 3 (WPA3) protocol to obtain network passwords using a combination of Man-in-the-Middle attacks and social engineering techniques. The research, conducted by Kyle Chadee, Wayne Goodridge, and Koffka Khan from the University of …

Italy Imposed EUR 15 million Fine to Open AI For Violating GDPR

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The Italian Data Protection Authority (known as “Il Garante”) has imposed a €15 million fine on OpenAI for violations of the General Data Protection Regulation (GDPR). This punitive measure follows an investigation into the operation of OpenAI’s ChatGPT service, initiated …