Internet Archive Breached Again, Hackers Exploited Unrotated API Tokens

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The Internet Archive has fallen victim to another cyberattack, marking the third major security incident in October 2024. On October 20, hackers successfully exploited unrotated API tokens to gain unauthorized access to the organization’s Zendesk support platform, potentially compromising sensitive …

Cisco Investigating Cyber Security Incident, Takes DevHub Portal Offline

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cisco, has launched an investigation into a potential cyber security incident and has taken its public DevHub portal offline as a precautionary measure. On October 18, 2024, the company confirmed that it is looking into reports of an unauthorized actor …

Brazil Arrests ‘USDoD,’ Hacker in FBI Infragard Breach

Blog WriterCybersecurity News - Original News Source is krebsonsecurity.com

Brazilian authorities reportedly have arrested a 33-year-old man on suspicion of being “USDoD,” a prolific cybercriminal who rose to infamy in 2022 after infiltrating the FBI’s InfraGard program and leaking contact information for 80,000 members. More recently, USDoD was behind …

Bitdefender Total Security Vulnerability Exposes Users to Man-in-the-Middle Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Bitdefender Total Security has been found vulnerable to Man-in-the-Middle (MITM) attacks due to improper certificate validation in its HTTPS scanning functionality. This vulnerability, identified under multiple CVEs, poses a serious risk to users by potentially allowing attackers to intercept and …

10 Best Mobile App Security Scanners to Detect Vulnerability in Applications 2024

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

In this era, mobile technology and smartphone are trendy terms often used. 90% of the population holds a smartphone in their hands. Their purpose is not only to “call” other parties but to use other features like Bluetooth, camera, Wi-Fi, …

Vulnerabilities In WebRTC Implementations Let Attackers Trigger DoS Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

WebRTC (Web Real-Time Communication) is an open-source project that facilitates real-time audio, video, and data sharing directly between web browsers and mobile applications without the need for plugins. Its integration into HTML5 and support across major browsers make it a …

Critical SolarWinds Web Help Desk Vulnerability Exposes Systems To Remote Attack

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical vulnerability has been identified in SolarWinds Web Help Desk, potentially allowing attackers to execute remote code on affected systems. The Trend Micro Zero Day Initiative (ZDI) team discovered the flaw, designated CVE-2024-28988. This vulnerability stems from a Java …

Cisco ATA 190 Telephone Adapter Flaw Expose Devices To Remote Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cisco has issued a critical security advisory concerning multiple vulnerabilities in its ATA 190 Series Analog Telephone Adapters. These vulnerabilities could potentially allow remote attackers to execute arbitrary code, posing significant risks to affected devices. The vulnerabilities impact both on-premises …

PoC Exploit Released for BIG-IP Privilege Escalation Vulnerability

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical vulnerability in F5 BIG-IP, a popular network traffic management and security solution tracked as CVE-2024-45844, allows authenticated attackers to bypass access control restrictions and potentially compromise the system. According to the security advisory issued by F5, the vulnerability …

New macOS Vulnerability Allows Attackers to Bypass Security Controls

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A recently discovered vulnerability in macOS, dubbed “HM Surf,” allows attackers to bypass the operating system’s Transparency, Consent, and Control (TCC) technology, gaining unauthorized access to a user’s protected data. This vulnerability, identified as CVE-2024-44133, was uncovered by Microsoft Threat Intelligence and has since been addressed by Apple in the latest security updates for macOS Sequoia, …