10 Best Mobile App Security Scanners to Detect Vulnerability in Applications 2024

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

In this era, mobile technology and smartphone are trendy terms often used. 90% of the population holds a smartphone in their hands. Their purpose is not only to “call” other parties but to use other features like Bluetooth, camera, Wi-Fi, …

Vulnerabilities In WebRTC Implementations Let Attackers Trigger DoS Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

WebRTC (Web Real-Time Communication) is an open-source project that facilitates real-time audio, video, and data sharing directly between web browsers and mobile applications without the need for plugins. Its integration into HTML5 and support across major browsers make it a …

Critical SolarWinds Web Help Desk Vulnerability Exposes Systems To Remote Attack

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical vulnerability has been identified in SolarWinds Web Help Desk, potentially allowing attackers to execute remote code on affected systems. The Trend Micro Zero Day Initiative (ZDI) team discovered the flaw, designated CVE-2024-28988. This vulnerability stems from a Java …

Cisco ATA 190 Telephone Adapter Flaw Expose Devices To Remote Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cisco has issued a critical security advisory concerning multiple vulnerabilities in its ATA 190 Series Analog Telephone Adapters. These vulnerabilities could potentially allow remote attackers to execute arbitrary code, posing significant risks to affected devices. The vulnerabilities impact both on-premises …

PoC Exploit Released for BIG-IP Privilege Escalation Vulnerability

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical vulnerability in F5 BIG-IP, a popular network traffic management and security solution tracked as CVE-2024-45844, allows authenticated attackers to bypass access control restrictions and potentially compromise the system. According to the security advisory issued by F5, the vulnerability …

New macOS Vulnerability Allows Attackers to Bypass Security Controls

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A recently discovered vulnerability in macOS, dubbed “HM Surf,” allows attackers to bypass the operating system’s Transparency, Consent, and Control (TCC) technology, gaining unauthorized access to a user’s protected data. This vulnerability, identified as CVE-2024-44133, was uncovered by Microsoft Threat Intelligence and has since been addressed by Apple in the latest security updates for macOS Sequoia, …

Hacking Laptop With a BBQ Lighter to Gain Root Access

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A simple BBQ lighter has been used to exploit vulnerabilities in laptops, gaining root access through an innovative method known as electromagnetic fault injection (EMFI). David Buchanan, a professional hardware researcher, demonstrated this unconventional approach and showcased how a piezo-electric …

macOS Gatekeeper Security Feature Bypassed to Execute Malicious Code

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Security researchers at Palo Alto Networks’ Unit 42 have uncovered significant vulnerabilities in macOS’s Gatekeeper security mechanism. This discovery reveals how certain third-party applications and even some of Apple’s native command-line tools can inadvertently bypass Gatekeeper, potentially allowing malicious code …

What is Lumma Stealer: Technical Details and Recent Fake CAPTCHA Attack

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Lumma Stealer, also known as LummaC2, is a widely known malware that first surfaced in 2022. Since then, it has steadily evolved, improving its techniques for stealing sensitive information. Lumma Stealer targets a wide range of credentials, including browser-stored passwords, …

SAP NetWeaver Code Injection Vulnerability Let Attackers Upload Malicious Files

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical security flaw in SAP NetWeaver AS Java has been uncovered, potentially allowing attackers to upload malicious files and execute unauthorized commands. The vulnerability, identified as CVE-2024-22127, affects the Administrator Log Viewer plug-in and has been assigned a CVSS …