Hackers Launch Zero-Day Attacks to Exploits Corrupted Files to Evade Security Tools

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cybersecurity experts at ANY.RUN have uncovered an active zero-day attack campaign that leverages corrupted files to bypass antivirus software, sandbox environments, and even email spam filters. The attack, first identified by the ANY.RUN team, poses a significant threat by enabling …

Firefox 133 Released With Fix For Multiple Security Vulnerabilities

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Mozilla has officially launched Firefox 133.0, introducing a host of new features, performance improvements, and critical security fixes. The release, first offered to the Release channel on November 26, 2024, brings significant advancements in privacy protection, developer tools, and overall …

Bootkitty, The First UEFI Bootkit Targeting Linux Servers

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Researchers have uncovered the first UEFI bootkit designed specifically for Linux systems, named Bootkitty. This discovery marks a pivotal moment in the evolution of UEFI threats, which have traditionally targeted Windows systems exclusively. The UEFI threat landscape has seen considerable …

NVIDIA UFM Vulnerability Let Attackers Escalate Privileges

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A high-severity vulnerability has been disclosed recently on November 26, 2024 by NVIDIA affecting its UFM Enterprise, UFM Appliance, and UFM CyberAI products. The flaw, identified as CVE-2024-0130, could allow attackers to escalate privileges, tamper with data, cause denial of …

IBM Engineering Systems Flaw Let Attackers Bypass Security Restrictions

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical security vulnerability has been discovered in IBM Engineering Systems Design Rhapsody – Model Manager (RMM), potentially allowing remote attackers to bypass security restrictions and execute code. The flaw, identified as CVE-2024-41779, affects versions 7.0.2 and 7.0.3 of the …

Junior School Student Charges For Infecting Computers With ‘Test of Skill’ Virus

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A 15-year-old junior high school student from Saitama Prefecture has been charged with creating and distributing a computer virus. The Fukui Police Station and the Cyber Crime Division of the Fukui Prefectural Police forwarded the case to the prosecutor’s office …

20 Years Old macOS Vulnerability Allow Attackers To Gain Root Access Remotely

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A security researcher, Gergely Kalman, uncovered a severe macOS vulnerability privilege escalation in Apple’s MallocStackLogging framework, which had remained undetected for approximately 20 years. The bug, tracked as CVE-2023-32428, was discovered in March 2023 and subsequently patched by Apple in …

VMware Aria Operations Vulnerabilities Allow Privilege Escalation & XSS Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

VMware, a leading cloud computing and virtualization software provider, has disclosed multiple critical vulnerabilities in its Aria Operations product. The most severe flaws could allow attackers to escalate privileges to the root user on affected systems. The advisory, identified as …

Hacker in Snowflake Extortions May Be a U.S. Soldier

Blog WriterCybersecurity News - Original News Source is krebsonsecurity.com

Two men have been arrested for allegedly stealing data from and extorting dozens of companies that used the cloud data storage company Snowflake, but a third suspect — a prolific hacker known as Kiberphant0m — remains at large and continues …

Interpol Arrested 1,000+ Cybercriminals and Dismantled 130,000+ Malicious Networks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A joint operation by INTERPOL and AFRIPOL has led to the arrest of 1,006 suspects and the dismantling of 134,089 malicious infrastructures across 19 African countries. The operation, codenamed Operation Serengeti, targeted cybercriminals involved in ransomware, business email compromise (BEC), …