Hacking Laptop With a BBQ Lighter to Gain Root Access

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A simple BBQ lighter has been used to exploit vulnerabilities in laptops, gaining root access through an innovative method known as electromagnetic fault injection (EMFI). David Buchanan, a professional hardware researcher, demonstrated this unconventional approach and showcased how a piezo-electric …

macOS Gatekeeper Security Feature Bypassed to Execute Malicious Code

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Security researchers at Palo Alto Networks’ Unit 42 have uncovered significant vulnerabilities in macOS’s Gatekeeper security mechanism. This discovery reveals how certain third-party applications and even some of Apple’s native command-line tools can inadvertently bypass Gatekeeper, potentially allowing malicious code …

What is Lumma Stealer: Technical Details and Recent Fake CAPTCHA Attack

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Lumma Stealer, also known as LummaC2, is a widely known malware that first surfaced in 2022. Since then, it has steadily evolved, improving its techniques for stealing sensitive information. Lumma Stealer targets a wide range of credentials, including browser-stored passwords, …

SAP NetWeaver Code Injection Vulnerability Let Attackers Upload Malicious Files

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical security flaw in SAP NetWeaver AS Java has been uncovered, potentially allowing attackers to upload malicious files and execute unauthorized commands. The vulnerability, identified as CVE-2024-22127, affects the Administrator Log Viewer plug-in and has been assigned a CVSS …

Sudanese Brothers Arrested in ‘AnonSudan’ Takedown

Blog WriterCybersecurity News - Original News Source is krebsonsecurity.com

The U.S. government on Wednesday announced the arrest and charging of two Sudanese brothers accused of running Anonymous Sudan (a.k.a. AnonSudan), a cybercrime business known for launching powerful distributed denial-of-service (DDoS) attacks against a range of targets, including dozens of …

ANY.RUN’s Upgraded Linux Sandbox for Fast and Secure Malware Analysis

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

ANY.RUN upgraded its Linux sandbox with features to enhance malware analysis. It now uses a stable Chrome browser for smoother interaction with suspicious websites, while lag in the process tree view is eliminated, allowing for faster exploration of running processes.  Users can …

Authorities take down Gang Behind ATM Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Dutch, French, and German police forces arrested three members of a notorious criminal network responsible for a series of violent attacks on ATMs across Europe. The coordinated operation occurred in the early hours of October 16, 2024, marking a pivotal …

Multihomed Linux Devices Flaw Allows Spoof of Internal Communication

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical vulnerability has been discovered in multihomed Linux devices. It allows attackers to spoof and inject packets into internal communication streams via an external or public interface. Security researchers uncovered the flaw during several assessments, and it has been …

Iranian actors selling Login Access to Organizations networks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

International security agencies have raised alarms about Iranian cyber actors compromising networks across critical infrastructure sectors. These actors reportedly sell login access to these networks, posing significant risks to global cybersecurity. This article delves into the methods used by these …

Trend Micro Cloud Edge Vulnerability Let Attackers Execute Arbitrary Code

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Trend Micro has issued an urgent security bulletin warning users of a critical vulnerability in its Cloud Edge appliance that could allow remote attackers to execute arbitrary code without authentication. The vulnerability tracked as CVE-2024-48904 has been assigned a CVSS …