Cisco Systems Manager for Windows Vulnerability Let Attackers Escalate Privilege

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cisco Systems has issued a critical security advisory for a vulnerability in the Cisco Meraki Systems Manager (SM) Agent for Windows. The flaw, identified as CVE-2024-20430, allows authenticated local attackers to execute arbitrary code with elevated privileges. With a CVSS …

Tor Browser 13.5.3 Released, What’s New?

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The Tor Project has officially released Tor Browser 13.5.3, bringing many updates and improvements to enhance security and usability. This latest version is available from the Tor Browser download page and the distribution directory. The release includes critical security updates …

Critical Cisco Smart Licensing Vulnerabilities Let Attackers Take Over System

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cisco has recently disclosed multiple critical vulnerabilities in its Smart Licensing Utility (CSLU), which could allow unauthenticated, remote attackers to gain administrative access or collect sensitive information from affected systems. These vulnerabilities, identified as CVE-2024-20439 and CVE-2024-20440, are present in …

Palo Alto Networks Acquires IBM’s QRadar in $500 Million Deal

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Palo Alto Networks, the global cybersecurity leader, has announced the completion of its acquisition of IBM’s QRadar Software as a Service (SaaS) assets. This strategic move, revealed on September 4, 2024, marks a significant milestone in the company’s mission to …

Criminal IP Secures PCI DSS v4.0 Certification, Enhancing Payment Security with Top-Level Compliance

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

AI SPERA, a leading Cyber Threat Intelligence (CTI) company, has achieved PCI DSS v4.0 certification for its flagship search engine solution, Criminal IP. This accomplishment builds on last year’s attainment of PCI DSS v3.2.1 (Payment Card Industry Data Security Standard) …

What is an Access Matrix?

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Access control is fundamental to operating system (OS) security. It ensures that only authorized processes can perform specific actions on system resources. One key tool used to manage access control is the access matrix. This article explores an access matrix, how …

New Emansrepo Malware Weaponizing HTML Files To Attack Windows Users

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Emansrepo is a Python infostealer that was discovered by the FortiGuard Labs in August 2024 and has been disseminated through phishing emails containing fake purchase orders and invoices. It started its operation in November 2023, where Emansrepo retrieves exfiltrated data …

RomCom Group Exploiting Microsoft Office 0-day To Deploy Ransomware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The Russian group RomCom, dubbed Storm-0978, distributes underground ransomware by leveraging the Microsoft Office and Windows HTML RCE zero-day vulnerability identified as CVE-2023-36884. This ransomware encrypts files on victims’ Windows computers, similar to typical ransomware, and then drops ransom notes …

Researchers Unpacked ViperSoftX Malware’s Evasion Tactics And Techniques

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Sophisticated threat actors, like those behind the ViperSoftX malware from 2020, often make use of existing tools to save time and resources.  ViperSoftX uses AutoIt, the CLR, and pre-made hacking scripts. This helps them to develop malware faster and avoid …

Threat Actor Allegedly Claims Leak of BMW Customer Database

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A well-known threat actor identified as “888” has claimed responsibility for leaking sensitive customer data belonging to BMW Hong Kong. According to the Breachforums post, “888” has allegedly leaked sensitive data from BMW Hong Kong, affecting approximately 14,057 customer records. …