Apple Safari Remote Code Execution Vulnerability Exploited In The Wild

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical remote code execution vulnerability in Apple Safari, identified as CVE-2024-44308, has been discovered and actively exploited in the wild. The flaw affects multiple Apple platforms, including:- iOS iPadOS macOS visionOS The vulnerability, which resides in the JavaScriptCore component …

Critical MediaTek Bluetooth Chipset Vulnerabilities Affected of 1.5 Billion+ Android Users

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A series of security vulnerabilities have been identified in MediaTek chipsets, affecting several Android versions and other related software platforms. MediaTek leads the market in powering Android tablets and smart-feature phones and ranks as the world’s second-largest provider of smartphone …

Trellix Enterprise Security Manager Flaw Allows Access To Internal Snowservice API

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical vulnerability has been addressed by Trellix in its Enterprise Security Manager (ESM) that could potentially expose the internal Snowservice API to unauthorized access. The flaw, discovered in ESM version 11.6.10, has raised concerns among cybersecurity experts due to …

North Korean Hacking Group Launches Undected Malwareless URL Phishing Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Researchers from South Korea have discovered that the notorious North Korean hacking group, known as Kimsuky, has adapted its phishing tactics to use malwareless phishing attack tactics, which evade major EDR detection. The group, which has been active for several …

Windows Server 2012 0-day Vulnerability Let Attackers Bypass Security Checks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical security vulnerability in Windows Server 2012 and Server 2012 R2 has been uncovered, allowing attackers to bypass essential security checks enforced by the Mark of the Web (MotW) feature. This zero-day flaw, which has remained undetected for over …

10 Best Vulnerability Management Tools In 2024

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Vulnerability Management Tools play a significant role in detecting, analyzing, and patching vulnerabilities in web and network-based applications. The most common words used in security speak of vulnerability, risk, and threat. Risk is the potential for damage or loss, and …

“Rockstar 2FA” Phishing-as-a-Service Steals Microsoft 365 Credentials Via AiTM Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cybersecurity researchers have identified a concerning link between the advanced phishing toolkit known as ‘Rockstar 2FA’ and a surge in adversary-in-the-middle (AiTM) phishing attacks. Highly advanced methods are used in these campaigns to trick people into going to fake landing …

Microsoft to Deprecate Bring Your Own License Defender Feature for Cloud

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Microsoft has announced plans to deprecate the “Bring Your Own License” (BYOL) feature in Microsoft Defender for Cloud as part of a move towards a centralized vulnerability management experience. This significant change aims to enhance enterprise exposure management and streamline …

InputSnatch – A Side-Channel Attack Allow Attackers Steal The Input Data From LLM Models

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

In a recent study, cybersecurity researchers have unveiled a new side-channel attack that threatens the privacy of users interacting with large language models (LLMs). The attack, dubbed “InputSnatch,” exploits timing differences in cache-sharing mechanisms commonly used to optimize LLM inference. …

Critical GPU DDK Vulnerabilities Allow Attackers to Execute Arbitrary Code in Physical Memory

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A significant development for the tech community is the identification of 2 critical vulnerabilities in several versions of a widely-used GPU Driver Development Kit (DDK) that affect systems using Unified Memory Architecture (UMA). On November 29, 2024, researchers disclosed the …