NVIDIA Base Command Manager Vulnerability Let Attackers Remote Code

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

NVIDIA has issued a security advisory addressing a critical vulnerability (CVE-2024-0138) discovered in its Base Command Manager software. This flaw, located within the CMDaemon component, poses significant risks, including the potential for remote code execution, denial of service, privilege escalation, …

145,000+ Unsecured ICS Devices Exposed To Attackers

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A significant cybersecurity risk has been uncovered recently by Censys researchers that unveiled over 145,000 industrial control systems (ICS) devices are currently exposed to potential attackers on the internet. This alarming discovery highlights the growing vulnerability of critical infrastructure systems …

Multiple Linux Kernel Vulnerabilities In Defer Partition Scanning Patched

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The Linux kernel development team has recently addressed two significant vulnerabilities affecting various versions of the Linux operating system. These security issues, discovered in the kernel’s handling of NVMe multipath (CVE-2024-53093) and RDMA/siw (CVE-2024-53094) functionality, have been patched to prevent …

2000+ Palo Alto Firewalls Hacked Exploiting New Vulnerabilities

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Over 2,000 Palo Alto Networks firewalls have been compromised in a widespread attack exploiting recently patched vulnerabilities. The attack, which began in mid-November 2024, has raised alarm bells across the cybersecurity community and highlighted the critical importance of prompt patching …

Feds Charge Five Men in ‘Scattered Spider’ Roundup

Blog WriterCybersecurity News - Original News Source is krebsonsecurity.com

Federal prosecutors in Los Angeles this week unsealed criminal charges against five men alleged to be members of a hacking group responsible for dozens of cyber intrusions at major U.S. technology companies between 2021 and 2023, including LastPass, MailChimp, Okta, …

Top 6 Malware Persistence Mechanisms Used by Hackers: A Detailed Guide

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Persistence mechanisms play a critical role in modern cyberattacks, helping malware remain active on compromised systems even after reboots, log-offs, or restarts. By exploiting built-in system features, attackers ensure their malicious programs continue operating undetected. Below, we explore six common …

Decade-Old Flaws In Ubuntu Server Package Let Attackers Gain Root Access

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Multiple decade-old Local Privilege Escalation (LPE) vulnerabilities discovered within the needrestart component installed by default in Ubuntu Server might allow a local attacker to achieve root access. needrestart is a utility that checks your system to see whether it needs …

Ghost Tap Attack, Hackers Stolen Credit Card Linked To Google Pay Or Apple Pay

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Threat actors are actively using a new cash-out technique called “Ghost Tap” to cash out money using credit card information that has been stolen and connected to mobile payment services like Apple Pay or Google Pay.  This technique involves relaying …

Critical AnyDesk Vulnerability Let Attackers Uncover User IP Address

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical vulnerability in AnyDesk, a popular remote desktop application, has been discovered that could allow attackers to expose users’ IP addresses. The flaw, identified as CVE-2024-52940, affects AnyDesk versions 8.1.0 and earlier on Windows systems. Security researcher Ebrahim Shafiei …

Gelsemium APT Hackers Attacking Linux Servers With New WolfsBane Malware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A new Linux backdoor named WolfsBane has been recently uncovered by the ESET researchers, attributed to the Gelsemium advanced persistent threat (APT) group. This discovery marks the first public report of Gelsemium using Linux malware, signaling a shift in their …