Krispy Kreme Hacked, Attackers Gain Unauthorized Access to IT Systems

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Krispy Kreme, the iconic doughnut chain, has become the latest victim of a cyberattack that has disrupted its online ordering system in parts of the United States. The company first detected unauthorized activity on its IT systems on November 29, …

Apple Intelligence is live! iOS 18.2 is Released – What’s New!

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Apple today announced the launch of iOS 18.2, iPadOS 18.2, and macOS Sequoia 15.2, featuring groundbreaking updates to Apple Intelligence, its user-friendly and privacy-first personal intelligence system. The updates introduce new tools such as the Image Playground for creating custom …

What is Cryptographic Failures?

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cryptographic failures occur when the mechanisms and protocols designed to secure data and communications through encryption break down, become compromised, or fail to perform as expected. These failures compromise the foundational principles of data security—confidentiality, integrity, and authenticity—and leave sensitive …

Chinese Hacker Charged for Hacking 81,000+ Firewalls Worldwide

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The cybersecurity firm Sichuan Silence and one of its employees, Guan Tianfeng, have been sanctioned by the Department of the Treasury’s Office of Foreign Assets Control (OFAC) for their involvement in the April 2020 hack of tens of thousands of …

Microsoft Office & Excel Vulnerabilities Expose Systems To RCE & Privilege Escalation

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Microsoft disclosed two significant vulnerabilities affecting its Office and Excel products as part of its December Patch Tuesday updates. These vulnerabilities tracked as CVE-2024-49059 and CVE-2024-49069, pose serious security risks by enabling attackers to execute remote code or escalate privileges …

Hackers Exploiting HTML Functions to Bypass Email Security Filters

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cybercriminals increasingly leverage sophisticated HTML techniques to circumvent email security filters, putting users and organizations at greater risk of falling victim to phishing attacks. These attacks, often disguised as legitimate documents such as invoices or HR policies, exploit various HTML …

Critical Vulnerabilities in Ivanti CSA Let Attackers Bypass Admin Web Console Remotely

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Ivanti has released crucial security updates to address multiple vulnerabilities in its Cloud Services Application (CSA) software, including critical flaws that could allow attackers to bypass authentication and execute remote code. Organizations are urged to update their software immediately to …

Chrome Security Update, Patch for 3 High-severity Vulnerabilities

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Google has released a critical security update for its Chrome browser, addressing three high-severity vulnerabilities that could potentially expose users to significant risks. The latest update, version 131.0.6778.139/.140 for Windows and Mac and 131.0.6778.139 for Linux, is being rolled out …

Patch Tuesday, December 2024 Edition

Blog WriterCybersecurity News - Original News Source is krebsonsecurity.com

Microsoft today released updates to plug at least 70 security holes in Windows and Windows software, including one vulnerability that is already being exploited in active attacks. The zero-day seeing exploitation involves CVE-2024-49138, a security weakness in the Windows Common …

Windows Common Log File System Zero-day (CVE-2024-49138) Exploited in the Wild

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A new high-severity security vulnerability, CVE-2024-49138, has been identified in the Windows Common Log File System (CLFS) Driver as a zero-day that was exploited in the wild. Microsoft confirmed that this vulnerability is categorized as an Elevation of Privilege issue …