CISA listed Over 270 Critical Vulnerabilities That Were Fixed Last Week – What’s New!

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The Cybersecurity and Infrastructure Security Agency (CISA) has published its latest vulnerability bulletin, detailing over 270 security vulnerabilities identified in the past week across a wide range of software and hardware. These vulnerabilities affect popular applications, operating systems, IoT devices, …

Critical Vulnerability in Python Affected MacOS or Linux Leads to Exploiting The Memory

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A high-severity vulnerability (CVE-2024-12254) impacting CPython has been publicly disclosed, affecting Python versions 3.12.0 and later. The flaw, identified in the asyncio module, specifically lies in the _SelectorSocketTransport.writelines() method, potentially leading to memory exhaustion under certain conditions. Leveraging 2024 MITRE …

Uncovering Attacker’s Infrastructre & Tactics Via Passive DNS

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

In the ever-evolving landscape of cybersecurity, understanding how attackers establish and maintain their attack infrastructure is crucial for building robust defenses. A recent study by Juniper Threat Labs sheds light on the sophisticated methods attackers use to set up their …

Let’s Encrypt to End Support for Online Certificate Status Protocol (OCSP)

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Let’s Encrypt, a leading provider of free SSL/TLS certificates, has officially announced its timeline for discontinuing support for the Online Certificate Status Protocol (OCSP) in favor of Certificate Revocation Lists (CRLs). This decision, driven by privacy and efficiency concerns, marks …

Romania’s Leading Energy Provider Electrica Group Hit by Ransomware Attack

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Electrica Group, one of Romania’s most prominent energy service providers, has confirmed it is grappling with a ransomware attack. The cyber incident has prompted the company to activate its emergency response protocols and collaborate closely with national cybersecurity authorities to …

Mauri Ransomware Exploiting Apache ActiveMQ Vulnerability

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The Apache ActiveMQ Vulnerability, identified as CVE-2023-46604, was exploited by Mauri Ransomware threat actors to install CoinMiners. Threat actors were detected continuously launching attacks on unpatched, vulnerable Apache ActiveMQ services. Once the compromised machine has been infected, threat actors can …

Cipla Allegedly Hacked, Akira Ransomware Claims 70GB Data Stolen

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cipla, the Indian pharmaceutical giant, has reportedly fallen victim to a cyberattack orchestrated by the Akira ransomware group. The hackers claim to have exfiltrated a staggering 70GB of sensitive data from the multinational company, which operates 47 manufacturing facilities globally …

OpenWrt Supply Chain Attack Via SHA-256 Collision & Command Injection

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical vulnerability in OpenWrt’s firmware upgrade system has been recently unveieled by the security researcher RyotaK from Flatt Security Inc.. The exploit, which combines a truncated SHA-256 collision with a command injection technique, could have potentially compromised the entire …

Hackers Attacking Global Sporting Championships Via Fake Domains To Steal Logins

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cybercriminals leverage high-profile events, such as global sporting championships, by registering fake domains to launch phishing and scam attacks. Researchers uncover suspicious domain registration campaigns, especially when event-specific terms or phrases are used in recently registered domains.  Event-related abuse focuses …

Microsoft Challenged AI Hackers To Break LLM Email Service, Rewards Up To $10,000

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Microsoft has launched an innovative cybersecurity challenge that puts artificial intelligence (AI) to the test. As Microsoft is inviting hackers and security researchers to attempt to break its simulated LLM-integrated email client, dubbed the LLMail service, with rewards of up …