Microsoft December 2024 Patch Tuesday – 71 Vulnerabilities Fixed, Including 1 Zero-day & 30 RCEs

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Microsoft released a security as part of the December Patch Tuesday that addressed 72 vulnerabilities, including 30 classified as critical Remote Code Execution (RCE) vulnerabilities. These fixes are crucial for securing Windows operating systems and related software against potential exploitation. …

Microsoft 365 Down: Web Apps and Admin Center are Affected

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Microsoft is investigating a widespread outage that disrupted access to Microsoft 365 web applications and the Microsoft 365 admin center earlier today. The issue affected users attempting to connect to services like Outlook, OneDrive, and other Office 365 applications through …

Cleo Zero-Day RCE Vulnerability Actively Exploited in the Wild

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical zero-day vulnerability (CVE-2024-50623) in Cleo’s file transfer products Harmony, VLTrader, and LexiComis being actively exploited by threat actors, cybersecurity researchers have warned. The flaw, stemming from an unrestricted file upload and download vulnerability, allows unauthenticated remote code execution …

Chinese Hackers Using Visual Studio Code Tunnels & RDP To Gain Remote Access

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

In a sophisticated cyber-espionage campaign dubbed ‘Operation Digital Eye,’ suspected Chinese state-backed hackers targeted major business-to-business IT service providers across Southern Europe between late June and mid-July 2024. The attackers employed a clever technique, exploiting Visual Studio Code Tunnels and …

RedLine Malware Weaponizing Pirated Corporate Softwares To Steal Logins

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

An ongoing RedLine info-stealer effort targets Russian-speaking entrepreneurs using unlicensed corporate software copies to automate business operations. Attackers were distributing a malicious version of the HPDxLIB activator to business process automation users that contained a RedLine stealer concealed in a …

SAP NetWeaver Vulnerabilities Let Attackers Upload Malicious PDF Files

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

SAP has issued a crucial security update addressing multiple high-severity vulnerabilities in its NetWeaver Application Server for Java, specifically within the Adobe Document Services component. The patch, released on December 10, 2024, as part of SAP’s monthly Security Patch Day, …

WhatsApp View Once Vulnerability Let Attackers Bypass The Privacy Feature

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Meta’s WhatsApp recently faced scrutiny after a significant vulnerability in its “View Once” feature was discovered, allowing attackers to bypass its privacy protections. This feature, designed to let users send media that can only be viewed once, was found to …

New Meeten Malware Targets macOS and Windows Users to Steal Login Credentials

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A new scam effort has been observed targeting Web3 leveraging fake video conferencing applications to deliver an information stealer dubbed Realst. Realst crypto stealer has been active for almost four months and targets both macOS and Windows users. Operating under …

Radiant Hacked – $50 Million USD Worth Crypto Stolen by North Korean Hackers

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Radiant Capital, a prominent decentralized finance (DeFi) protocol, has fallen victim to a major security breach, resulting in the loss of approximately $50 million USD. The attack, which exploited vulnerabilities in the devices of long-standing, trusted developers, has been described …

CISA listed Over 270 Critical Vulnerabilities That Were Fixed Last Week – What’s New!

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The Cybersecurity and Infrastructure Security Agency (CISA) has published its latest vulnerability bulletin, detailing over 270 security vulnerabilities identified in the past week across a wide range of software and hardware. These vulnerabilities affect popular applications, operating systems, IoT devices, …