Salesforce Applications Vulnerability Let Attackers Takeover The Accounts

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A recent penetration test conducted on Salesforce Communities revealed critical vulnerabilities that could allow attackers to take over user accounts. The security assessment, performed on multiple Salesforce instances, uncovered several issues related to misconfigured objects and broken access controls. The …

Apple Employee Suing Company For Monitoring Employee Personal Devices

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A current Apple employee has filed a lawsuit against the Apple, accusing the company of invasive surveillance practices that extend into workers’ personal lives. The lawsuit, filed in California state court on Sunday, December 1, 2024, alleges that Apple systematically …

TP-Link Archer Zero-Day Vulnerability Let Attackers Inject Malicious Commands

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical zero-day vulnerability has been discovered in TP-Link Archer, Deco, and Tapo series routers, potentially allowing attackers to inject malicious commands and fully compromise affected devices. This vulnerability, present in both old and recent firmware versions up to November …

Lifetime Jail For Hydra Dark Web Market Developer

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The Moscow Regional Court has sentenced Stanislav Moiseyev, the founder of the notorious Hydra darknet marketplace, to life imprisonment. The verdict, delivered on December 2, 2024, marks a significant milestone in Russia’s crackdown on cybercrime and illegal drug trafficking. Hydra, …

AWS Launched New Security Incident Response Service to Boost Enterprise Security

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Amazon Web Services (AWS) unveiled a new service, AWS Security Incident Response, designed to help organizations manage security events efficiently. As cyber threats become increasingly complex, this service offers a comprehensive solution to prepare for, respond to, and recover from …

Hackers Can Exploit Windows Driver Use-After-Free Vulnerability (CVE-2024-38193) to Gain Systems Privileges

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical use-after-free vulnerability called CVE-2024-38193 is found in the Windows driver afd.sys. It affects the Registered I/O (RIO) extension for Windows sockets and lets attachers take over the whole system remotely. The August 2024 Patch Tuesday update has addressed …

PoC Exploit Released for Windows Task Scheduler Zero-day Flaw, Exploited in Wild

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A proof-of-concept (PoC) exploit has been released for a critical zero-day vulnerability in the Windows Task Scheduler, identified as CVE-2024-49039. This privilege escalation flaw, which has been actively exploited in the wild, poses a significant threat to Windows users worldwide. …

Microsoft Ignite 2024 live : Highlights From Threat Intelligence to AI Governance

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

AI transformation starts with security. This theme echoed throughout Microsoft Ignite 2024, with security discussions drawing large crowds and securing top spots in the conference’s most-attended sessions. Hundreds of security and IT professionals gathered early for the Microsoft Ignite Security …

Sweet Security Introduces Evolutionary Leap in Cloud Detection and Response, Releasing First Unified Detection & Response Platform

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

With Sweet, customers can now unify detection and response for applications, workloads, and cloud infrastructure  Sweet Security today announced the release of its unified Cloud Native Detection and Response platform, designed to transform the way organizations protect their cloud environments …

Hackers Exploited Windows Event Logging Tool To Steal Data Secretly

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Wevtutil.exe, a Windows event log utility, can be used maliciously in Living Off the Land (LOLBAS) to export logs for exfiltration, query specific event data, or clear logs. Attackers increasingly use Living Off the Land Binaries and Scripts (LOLBAS) tactics. …