Foxit PDF Editor/Reader Vulnerabilities Let Attackers Execute Remote Code

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Foxit Software has released updates for its widely used Foxit PDF Reader and Foxit PDF Editor, addressing critical security vulnerabilities that could allow attackers to execute remote code. The updates, version 2024.4 for both products, were made available on December …

Critical Sophos Firewall Vulnerabilities Let Attckers Execute Remote Code

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Sophos, a leading cybersecurity firm, recently announced the resolution of three critical security vulnerabilities in its Sophos Firewall product. These vulnerabilities could potentially allow attackers to execute remote code on affected systems. These vulnerabilities, identified as CVE-2024-12727, CVE-2024-12728, and CVE-2024-12729, …

Krispy Kreme Hack Claimed by Play Ransomware – Threatens to Release Data

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The beloved doughnut chain Krispy Kreme has fallen victim to a significant cybersecurity incident, with the notorious Play ransomware group claiming responsibility for the attack. The attackers have threatened to release sensitive company data within two days unless their demands …

Web Hacking Service ‘Araneida’ Tied to Turkish IT Firm

Blog WriterCybersecurity News - Original News Source is krebsonsecurity.com

Cybercriminals are selling hundreds of thousands of credential sets stolen with the help of a cracked version of Acunetix, a powerful commercial web app vulnerability scanner, new research finds. The cracked software is being resold as a cloud-based attack tool …

Criminals Abuse Microsoft Dynamics 365 to Steal User Credentials

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Phishing attacks continue to evolve, leveraging legitimate platforms and services to deceive unsuspecting victims. One such tactic, highlighted by recent research from ANY.RUN, involves the abuse of Microsoft Dynamics 365.  Let’s unpack how cybercriminals exploit this trusted service, the methods …

Raccoon Infostealer Admin Arrested for Hacking Computers

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Mark Sokolovsky, a 28-year-old Ukrainian national, has been sentenced to 60 months in federal prison for his role in operating the notorious “Raccoon Infostealer” malware-as-a-service (MaaS). The sentencing marks a significant step in combating international cybercrime. Raccoon Infostealer emerged as …

Hackers Exploiting FortiClient EMS Vulnerability (CVE-2023-48788) in the Wild

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cybersecurity researchers have uncovered active exploitation of a critical vulnerability in Fortinet’s FortiClient Enterprise Management Server (EMS), tracked as CVE-2023-48788. This flaw, stemming from improper filtering of SQL commands, allows attackers to execute unauthorized code or commands via SQL injection. …

Hackers Exploiting Azure Key Vault Access Policies To Read Sensitive Data

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical security configuration in Azure Key Vault has been discovered, potentially allowing users with the Key Vault Contributor role to access sensitive data contrary to Microsoft’s documented intentions. This finding, reported by Datadog to Microsoft Security Research Center (MSRC), …

Europol Reveals How Cyber Criminals Boost Economy By Hacking Legal Businesses

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Europol has unveiled its latest report, “Leveraging legitimacy: How the EU’s most threatening criminal networks abuse legal business structures,” shedding light on the alarming extent to which cybercriminals are infiltrating legitimate businesses to expand their illicit operations. Building upon Europol’s …

Hikvision Camera Driver Vulnerability Records Login details in Log files

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A newly disclosed security vulnerability, tracked under CVE-2024-12569, has been identified in Hikvision camera drivers integrated with Milestone’s XProtect® Device Pack. This vulnerability has raised concerns as it could log sensitive authentication details—including usernames and passwords—into plain-text log files during …