Russian Military Hackers Attacking Attacking U.S. and Global Critical Infrastructure

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The NSA, FBI, CISA, and allies have assessed the cyber actors associated with the Russian General Staff Main Intelligence Directorate (GRU), Unit 29155, who are responsible for conducting computer network operations against global targets with the intent of espionage, sabotage, …

Critical IBM webMethods Vulnerabilites Let Attackers Execute Arbitrary Commands

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

IBM has disclosed multiple critical vulnerabilities in its webMethods Integration Server, potentially allowing attackers to execute arbitrary commands on affected systems. These vulnerabilities, identified in version 10.15 of the software, pose a severe risk to organizations using this platform for …

Veeam Software Vulnerabilities Let Attackers Trigger Remote Code Execution

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Veeam Software, a leading backup, recovery, and data management solutions provider, has announced the discovery and remedy of several critical and high-severity vulnerabilities across multiple products. These vulnerabilities were identified during internal testing and through external reports, highlighting potential risks …

What is ACK Piggybacking?-Definition, Attack Types & Prevention

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Piggybacking is a term relevant to computer networking and cybersecurity. It describes techniques that aim to optimize data transmission and, conversely, unauthorized access to networks. This article delves into the concept of piggybacking, exploring its application in data communication, its …

SonicWall Warns of Access Control Vulnerability Exploited in the Wild

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

SonicWall has issued an urgent security advisory regarding a critical vulnerability (CVE-2024-40766) affecting its firewall products. The company warns that this improper access control flaw is potentially being exploited in the wild, prompting immediate action from users. The vulnerability, with …

Linux Pluggable Authentication Modules Abused to Create Backdoors

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The Group-IB Digital Forensics and Incident Response (DFIR) team has uncovered a novel technique that exploits Linux’s Pluggable Authentication Modules (PAM) to create persistent backdoors on compromised systems. This technique not yet included in the MITRE ATT&CK framework, involves the …

Critical Progress LoadMaster Vulnerability Let Attackers Execute Arbitrary Code

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical vulnerability has been identified in the LoadMaster product line, including all LoadMaster releases and the LoadMaster Multi-Tenant (MT) hypervisor. This vulnerability, which is cataloged as CVE-2024-7591, could allow unauthenticated, remote attackers to execute arbitrary code on affected systems. …

Researcher Details Exploitation of Exchange PowerShell via MultiValuedProperty

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

OffensiveCon 2024 devised multiple methods to exploit Microsoft Exchange. One method was using the MultiValuedProperty, through which a researcher was able to exploit Exchange PowerShell. Moreover, this exploit bypasses Microsoft’s patch for one of the vulnerabilities. Two vulnerabilities (CVE-2022-41040 and …

6 Hackers Charged for Hacking Ukrainian Government Networks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A grand jury in Maryland has charged six Russian nationals with conspiracy to engage in computer intrusion and wire fraud. The indictment, unsealed today, accuses these individuals of orchestrating a series of cyberattacks targeting Ukrainian government networks, exacerbating tensions amid …

PoC Exploit Released for Linux Kernel Vulnerability that Allows Root Access

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Google Released a Proof-of-Concept (PoC) for a critical security vulnerability, identified as CVE-2024-26581, which has been discovered in the Linux kernel and poses significant risks to systems worldwide. This vulnerability, reported by Google’s kCTF team, affects the netfilter component, specifically …