Zendesk Email Spoofing Flaw Let Attackers Gain Access To Support Tickets

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A severe vulnerability in Zendesk, a widely used customer service tool, has been exposed, allowing attackers to gain unauthorized access to sensitive support tickets of numerous Fortune 500 companies. The flaw, discovered by a 15-year-old bug hunter named Daniel, exploited …

GitHub Enterprise Server Vulnerability Allows Authentication Bypass

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical vulnerability has been identified in GitHub Enterprise Server, posing significant security risks by allowing attackers to bypass authentication mechanisms. This flaw, tracked as CVE-2024-9487, was discovered in the Security Assertion Markup Language (SAML) single sign-on (SSO) feature utilized …

87,000+ FortiOS Devices Vulnerable to Remote Code Execution Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical security vulnerability affecting over 87,000 FortiOS devices has been discovered, leaving them exposed to potential remote code execution (RCE) attacks. The flaw, identified as CVE-2024-23113, impacts multiple versions of FortiOS, FortiProxy, FortiPAM, and FortiWeb products. The vulnerability stems …

HashiCorp Cloud Vault Vulnerability Let Attackers Escalate Privileges

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

HashiCorp, a leading provider of cloud infrastructure automation software, has disclosed a critical security vulnerability in its Vault secret management platform. The flaw, identified as CVE-2024-9180, could allow privileged attackers to escalate their privileges to the highly sensitive root policy, …

OpenAI Confirms Hackers Using ChatGPT to Create Sophisticated Malware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

OpenAI has confirmed that hackers are exploiting its ChatGPT artificial intelligence model to create malware and conduct cyberattacks. The AI research company released a report detailing over 20 instances where threat actors attempted to use ChatGPT for malicious purposes since …

PureLogs, Low Cost Infostealer Attacking Chrome Browser

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The world of cyber threats is intricate and ever-changing. Threat actors are always improving their methods, and new strains of infostealer malware frequently surface. Infostealers are very easy to operate, inexpensive, and have low entry barriers, which makes them highly …

Mamba Toolkit Abuses 2FA In Sophisticated Phishing Attack

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Phishing attacks are stealthy cyber threats where threat actors impersonate reputable entities to trick individuals into revealing sensitive information (“passwords” or “financial details”).  These types of attacks are executed via “emails” or “messages” that create a sense of urgency.  Not …

New Exclusive Report Reveals Administrators Of BreachForums

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The administrators behind the infamous dark web data breach forum, BreachForums, have been exposed. Established in March 2022, BreachForums quickly became a hub for cybercriminals trading in stolen data. The forum has seen a series of administrators, each with their …

Foxit PDF Reader Vulnerability Let Attackers Execute Arbitrary Code

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Foxit PDF Reader has a memory corruption vulnerability that could allow an attacker to execute arbitrary code on the victim machine. Foxit PDF Reader is a free, highly powerful, and feature-rich PDF viewer and editor for Windows, macOS, iOS, Android, and …

US, UK Authorities Warn of Hackers Attacking Zimbra & TeamCity Servers

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

In a joint advisory issued on October 10, 2024, the US and UK cyber agencies have warned of ongoing attacks by Russian hackers targeting vulnerable Zimbra and JetBrains TeamCity servers. The advisory, released by the NSA, FBI, US Cyber Command’s …