10-Year Old Flaws In Ubuntu Server needrestart Package Let Attackers Gain Root Access

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The cybersecurity community is on high alert following the discovery of five critical Local Privilege Escalation (LPE) vulnerabilities in the needrestart component, a default package in Ubuntu Server. These flaws, present for nearly a decade, potentially allow any unprivileged user …

CISA Warns of VMware VCenter Vulnerabilities Actively Exploited in Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The Cybersecurity and Infrastructure Security Agency (CISA) has issued a critical warning regarding two newly discovered vulnerabilities in VMware’s vCenter Server. These vulnerabilities, identified as CVE-2024-38812 and CVE-2024-38813, have the potential to be exploited by attackers, posing significant risks to …

Authorities Charged 5 Hackers For Attacking Companies via Phishing Text Messages

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Federal authorities have unveiled criminal charges against 5 individuals accused of directing a sophisticated phishing scheme targeting employees of companies across the United States. The defendants allegedly used stolen credentials to access corporate systems, steal sensitive data, and hack cryptocurrency …

Malicious PyPi Package Mimic ChatGPT & Claude Steals Developers Data

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Kaspersky’s Global Research and Analysis Team (GReAT) has recently uncovered a sophisticated supply chain attack targeting the Python Package Index (PyPI). The attack, which remained undetected for nearly a year, involved malicious packages masquerading as AI chatbot tools to distribute …

Critical Kubernetes Vulnerability Let Attackers Execute Arbitrary Commands

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A high-severity security vulnerability in Kubernetes has been discovered, potentially allowing attackers to execute arbitrary commands beyond container boundaries. The vulnerability has been tracked as CVE-2024-10220, affects Kubernetes clusters using the in-tree gitRepo volume to clone repositories to subdirectories. The …

macOS WorkflowKit Race Vulnerability Let Malicious Apps Intercept Shortcuts

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical vulnerability in macOS WorkflowKit, the framework underpinning Apple’s Shortcuts app, has been disclosed. This vulnerability allows malicious applications to intercept and modify user-imported shortcuts. Identified as CVE-2024-27821, this race condition in WorkflowKit poses a serious security risk, potentially enabling …

DDoS Attack Growing Bigger & Dangerous, New Report Reveals

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Distributed Denial of Service (DDoS) attacks are escalating at an alarming rate, as unveiled in a revelation by Cloudflare researchers and the recent data indicates that these attacks posing an increasingly severe threat to online services and infrastructure worldwide. Cloudflare, …

MITRE Lists 25 Most Dangerous Software Weaknesses of 2024

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

MITRE has released its annual list of the top 25 most dangerous software weaknesses for 2024, highlighting critical vulnerabilities that pose significant risks to software systems worldwide. This list, developed in collaboration with the Cybersecurity and Infrastructure Security Agency (CISA), …

Wireshark 4.4.2: Fixes Vulnerabilities & Enhances Protocol Support

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The Wireshark Foundation has announced the release of Wireshark 4.4.2, the latest version of its widely-used network protocol analyzer. This update brings many improvements, including critical bug fixes and enhanced protocol support, further solidifying Wireshark’s position as an essential tool …

SquareX Brings Industry’s First Browser Detection Response Solution to AISA Melbourne CyberCon 2024

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

SquareX, the leading browser security company, will make its Australian debut at Melbourne CyberCon 2024, hosted by AISA (Australian Information Security Association), from 26th to 28th November 2024. SquareX will showcase its groundbreaking Browser Detection and Response (BDR) solution at …