Flipper Zero Firmware 1.0 Released After 3 Years of Development

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

After three years of intensive development, Flipper Zero has released its highly anticipated firmware version 1.0. This major milestone marks the completion of numerous features that have been in the works since the project’s inception. “We have completed work on …

Payment Gateway Platform SLIM CD Data Breach, 1.7 Million Users Data Exposed

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The Slim CD, Inc., a prominent payment processing gateway for US and Canadian merchants, has disclosed a data breach affecting approximately 1.7 million users. The unauthorized access between August 17, 2023, and June 15, 2024, potentially exposed sensitive credit card …

BreachSeek, AI-Based Automated Multi-Platform Penetration Testing Tool

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

AI is significantly evolving penetration testing by enhancing automation, accuracy, and adaptability.  AI-driven tools can simulate sophisticated attack techniques, analyze vast datasets for vulnerabilities, and determine genuine threats from false positives, allowing security teams to focus on critical risks. The …

What is Border Gateway Protocol (BGP)?

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Border Gateway Protocol (BGP) is a critical component of the modern internet, enabling data routing between different networks, known as autonomous systems (AS). As the primary protocol for exchanging routing information across the Internet, BGP ensures that data packets efficiently …

Quad7 Botnet Operators Compromising Several Routers & VPN Appliances

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The Quad7 botnet (aka 7777 botnet, xlogin botnet) has gained attention for its use of compromised TP-Link routers to conduct attacks on Microsoft 365 accounts.  This botnet primarily employs password-spraying techniques, which involve attempting to log in with a list …

Researcher Exploited CI / CD Pipelines To Gain Full Server Access

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A CI/CD pipeline is a series of automated steps that helps software teams deliver code faster, safer, and more reliably.  It coordinates all the processes involved in continuous integration (CI) and continuous delivery (CD). The CTO of Razz Security, Mukesh, …

Earth Preta Hackers Added New Tools To Their Arsenal

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Earth Preta, also known as Mustang Panda, Bronze President, RedDelta, and Red Lich, is a sophisticated Chinese APT group that has been active since at least 2012.  They are known for targeting government entities, academic institutions, foundations, and research sectors …

Zyxel NAS Devices Vulnerable to Command Injection Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Zyxel has issued critical hotfixes to address a command injection vulnerability identified in two of its Network Attached Storage (NAS) products, NAS326 and NAS542. These devices, which have reached end-of-vulnerability-support, are susceptible to attacks that could allow unauthorized command execution. …

What is Asymmetric Cryptography?

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Asymmetric cryptography, or public key cryptography, is a cornerstone of modern digital security. It plays a crucial role in ensuring secure communications over the internet and is fundamental to the functioning of various security protocols and applications. This article explores …

CISA Warns of Three Vulnerabilities That Are Actively Exploited in the Wild

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The Cybersecurity and Infrastructure Security Agency (CISA) has added three new vulnerabilities to its Known Exploited Vulnerabilities Catalog, warning that threat actors are actively exploiting them in the wild. The vulnerabilities affect various products and could lead to serious consequences …