WhatsApp View Once Privacy Flaw Exploited by Attackers in the Wild

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

WhatsApp’s “View Once” feature, designed to enhance privacy by allowing users to send photos and videos that disappear after being opened once, has been found to have a critical flaw that attackers are actively exploiting. The Zengo X Research Team …

Hackers Exploiting GeoServer RCE Vulnerability to Deploy Malware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

GeoServer is an open-source server for sharing geospatial data, and this open-source software server is written in Java.  It publishes data from any major spatial data source using open standards. GeoServer is designed for teamwork and allows users to share, …

Hackers Stolen 300,000 Users Personal Data in Cyber Attack at Car Rental Firm

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Avis Car Rental disclosed that hackers had stolen personal data from approximately 300,000 customers. The breach, which occurred between August 3 and August 6, 2024, was detected on August 5 when Avis identified unauthorized access to one of its business …

Understand How Threat Intelligence Benefits for a Business

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

As a business owner, you’ve likely invested in various security tools such as SIEMs, antivirus software, and IDS/IPS systems. You may also have a dedicated cybersecurity team, like a SOC (Security Operations Center) or a DFIR (Digital Forensics and Incident …

Beware Of Malicious Chrome Extension That Delivers Weaponized ZIP Archive

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Malicious Chrome extensions pose significant risks to users, as they can compromise personal information, inject unwanted promotions, and even manipulate web traffic as well. There are several malicious extensions that remain undetected for extended periods, and this primarily happens due …

Bitcoin ATMs Now Become as a Playground for Scammers

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Bitcoin ATMs (BTMs) have emerged as a convenient tool for cryptocurrency transactions, but they have also become a hotbed for scams. With their increasing presence in convenience stores, gas stations, and other high-traffic areas, BTMs are now a favored method …

Fog Ransomware Group Attacking Employees of Financial Services Sector

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The Fog, a ransomware variant belonging to the STOP/DJVU family that was formerly targeting educational and recreational SECTORS, has turned its attention towards profitable targets in the finance industry. In early August 2024, threat actors used compromised VPN credentials to …

Kibana Vulnerabilities Let Attackers Execute Arbitrary Code

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Elastic has disclosed two critical vulnerabilities affecting Kibana, the popular data visualization and exploration tool used with Elasticsearch. These vulnerabilities, CVE-2024-37288 and CVE-2024-37285, allow attackers to execute arbitrary code through YAML deserialization issues. The flaws have been assigned high severity …

Russian Military Hackers Attacking Attacking U.S. and Global Critical Infrastructure

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The NSA, FBI, CISA, and allies have assessed the cyber actors associated with the Russian General Staff Main Intelligence Directorate (GRU), Unit 29155, who are responsible for conducting computer network operations against global targets with the intent of espionage, sabotage, …

Critical IBM webMethods Vulnerabilites Let Attackers Execute Arbitrary Commands

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

IBM has disclosed multiple critical vulnerabilities in its webMethods Integration Server, potentially allowing attackers to execute arbitrary commands on affected systems. These vulnerabilities, identified in version 10.15 of the software, pose a severe risk to organizations using this platform for …