Critical Vulnerabilities Impact Millions Of D-Link Routers: Patch Now!

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

In a significant security alert, millions of D-Link routers are at risk due to critical vulnerabilities that have been discovered in several models, including the DIR-X5460 and DIR-X4860. These vulnerabilities could allow remote attackers to execute arbitrary code, potentially compromising …

Windows MSHTML Zero-Day Vulnerability Exploited In The Wild

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The Windows MSHTML platform spoofing vulnerability, CVE-2024-43461, which affects all supported Windows versions, has been exploited in the wild. CVE-2024-43461 was used in attacks by the Void Banshee APT hacking group. Research from Trend Micro claims that Void Banshee lures …

Creating An AI Honeypot To Engage With Attackers Sophisticatedly

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

In cybersecurity, a honeypot is a bait system specifically designed to attract and analyze cyber-attacks, functioning as a trap for potential intruders.  By mimicking legitimate targets, honeypots divert threat actors from real assets while gathering intelligence on their methods and …

What is Security Auditing?

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

With the global cost of cybercrime reaching nearly $9.4 million in 2024, organizations are under immense pressure to protect their data and systems from potential breaches. Security auditing is one of the most effective ways to ensure the security of …

Threat Actor 888 Allegedly Claims Leak of SAP Employees Data

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A Twitter account known as DarkWebInformer has claimed that a notorious hacker, identified only by the alias “888,” has allegedly leaked sensitive data belonging to SAP employees. A member of BreachForums has claimed responsibility for leaking an employee database purportedly …

Beware of Fake AppleCare+ Service that Steals Money from Users

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A malicious campaign targeting Mac users seeking support or extended warranty services through AppleCare+ has been uncovered. This scam involves perpetrators purchasing Google ads to lure victims into visiting fraudulent websites hosted on GitHub, a platform owned by Microsoft. The …

Medusa Ransomware Exploiting Fortinet Flaw For Sophisticated Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The notorious Medusa ransomware group has been exploiting a critical vulnerability in Fortinet’s FortiClient EMS software to launch sophisticated ransomware attacks. The SQL injection flaw, tracked as CVE-2023-48788, allows attackers to execute malicious code on vulnerable systems and gain a …

Azure API Management Vulnerability Let Users Escalate Privileges

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical vulnerability was recently discovered in Azure API Management (APIM) that allowed users with Reader-level access to escalate their privileges to the equivalent of Contributor-level access. This security flaw enabled users to read, modify, and even delete configurations of …

New Linux Malware Exploiting Oracle Weblogic Servers

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Oracle WebLogic Server is an application server that is primarily designed to develop, deploy, and manage enterprise applications based on Java EE and Jakarta EE standards. It serves as a critical component of Oracle’s Fusion Middleware, which provides a reliable …

Kawasaki Europe Confirms Cyber Attack, RansomHub Claims Responsibility

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Kawasaki Motors Europe (KME) has officially confirmed it was the target of a cyberattack in early September, causing temporary disruptions to its operations. The company stated that while the attack was “not successful,” it resulted in the isolation of its …