Next.js Authorization Bypass Vulnerability Exposes Root-Level Pages

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical security vulnerability tracked as CVE-2024-51479 has been identified in Next.js, a widely used React framework for building web applications. The flaw allowed unauthorized access to certain pages directly under the application’s root directory, bypassing middleware-based authorization checks. This …

New Phishing Attack Exploiting HubSpot Tools To Steal Microsoft Azure Logins

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated phishing campaign targeting European companies. The attack, which peaked in June 2024, aims to harvest Microsoft Azure cloud credentials and compromise victims’ cloud infrastructure. The campaign primarily targets automotive, chemical, and industrial compound manufacturing companies in Germany and …

CISA Warns of 4 New Vulnerabilities Exploited in the Wild

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

 The Cybersecurity and Infrastructure Security Agency (CISA) has added four new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, highlighting significant security risks for various devices used worldwide. These vulnerabilities, which have been actively exploited in the wild, emphasize the …

CISA Released National Cyber Incident Response Plan (NCIRP) – 2024

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The Cybersecurity and Infrastructure Security Agency (CISA) has unveiled an updated version of the National Cyber Incident Response Plan (NCIRP), a strategic framework for coordinating how federal, state, local, tribal, and territorial (SLTT) governments, private sector entities, and international partners …

Fortinet Vulnerabilities Let Attackers Execute Arbitrary Code Remotely

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Fortinet, a leading cybersecurity solutions provider, has issued urgent advisories regarding two critical vulnerabilities affecting its FortiWLM and FortiManager products. These flaws could enable attackers to execute unauthorized code or commands remotely, posing significant risks to enterprise networks. FortiWLM Vulnerability …

GitHub Launches “Copilot Free” Access to 150 Million Developers

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

In a significant step towards empowering the global developer community, GitHub has announced the launch of GitHub Copilot Free an offering designed to enhance the productivity of developers, free of charge that is automatically integrated into Visual Studio Code (VS …

Critical Chrome Vulnerabilities Let Attackers Execute Remote Code – Update Now

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Google has released a significant update for its Chrome browser, addressing multiple high-severity vulnerabilities that could potentially allow unauthorized memory access and other exploits. The Stable channel has been updated to version 131.0.6778.204/.205 for Windows and macOS and 131.0.6778.204 for …

US to Ban TP-Link Routers, as They Fuel Chinese Cyber Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

US authorities are considering a ban on TP-Link routers due to concerns over their potential role in Chinese cyber attacks. The popular router manufacturer, which holds approximately 65% of the US market for home and small business routers, is under …

CISA Urges Use of End-to-End Encrypted Messaging Services like Signal, Following U.S. Telecoms Hack

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The Cybersecurity and Infrastructure Security Agency (CISA) has issued a stark warning to senior government officials and political figures to adopt end-to-end encrypted messaging services like Signal. This recommendation follows a series of cyber espionage activities attributed to Chinese state-affiliated …

Threat Actors Abusing Cloudflare Workers Service To Deliver Weaponized Application

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated attack campaign leveraging Cloudflare’s Workers service to distribute malicious applications disguised as legitimate software. The Computer Emergency Response Team of Ukraine (CERT-UA) reported on December 17, 2024, that several web resources imitating the official “Army+” application page were …