Hackers Exploit PHP Vulnerability in Windows To Execute Arbitrary Code Remotely

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cybersecurity researchers at Symantec recently identified a new malware that exploits a PHP vulnerability(CVE-2024-4577) in the CGI argument injection flaw. This vulnerability affects all versions of PHP installed on the Windows operating system and eventually executes arbitrary code remotely. A …

Hackers Exploited AWS ENV Files to Attack 110,000 Domains & Steal Credentials

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated extortion campaign targeted 110,000 domains by exploiting exposed .env files on unsecured web applications. The attackers obtained AWS IAM access keys from these files, which allowed them to create new IAM roles and policies with unlimited access.  This …

Microsoft Launches Unified Teams App for Personal & Work Environments

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Microsoft has unveiled a significant update to its popular collaboration platform, Microsoft Teams, by launching a unified app that brings together personal, work, and education accounts in a single interface. This new unified Teams app is now available on Windows …

Atlassian Bamboo Data Center & Server Flaw Let Attackers Execute Arbitrary Code

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Atlassian has issued a security advisory for a newly discovered high-severity vulnerability affecting its Bamboo Data Center and Server products. The vulnerability, identified as CVE-2024-21689, has a CVSS score of 7.6, indicating a high severity level. This flaw allows attackers to …

New UULoader Attacking Users Via Weaponized PDF Documents

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Malicious .msi installers disguised as legitimate software actively target Korean and Chinese speakers by dubbing UULoader, contain a loader likely developed by a Chinese speaker, and evade detection by most security solutions.  The malware employs DLL side-loading to execute obfuscated …

Outlook Zero-click RCE Vulnerability Technical Details Released

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Researchers at Morphisec have uncovered critical technical details about the recently discovered zero-click remote code execution (RCE) vulnerability in Microsoft Outlook, identified as CVE-2024-38021. This vulnerability poses a significant security risk, allowing potential attackers to execute arbitrary code without user …

10 Best Cloud VPN Providers – 2024

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A cloud VPN (Virtual Private Network) provider is a company that offers VPN services through cloud technology. This can save time and resources and reduce the risk of security breaches.  These services allow users to connect to the internet securely …

Android & iOS Users Targeted with New Phishing Attack Using PWAs & WebAPKs

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A novel type of phishing attack has been discovered, targeting both Android and iOS users. This attack combines traditional social engineering techniques with the use of Progressive Web Applications (PWAs) and WebAPKs, making it a significant threat to mobile users. …

Apache DolphinScheduler Vulnerability Let Hackers Execute Remote Code

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical vulnerability has been identified in Apache DolphinScheduler, a popular open-source workflow orchestration platform. This security flaw, designated as CVE-2024-43202, allows hackers to execute remote code, posing a significant threat to affected systems. CVE-2024-43202: Remote Code Execution Vulnerability The …

Multiple F5 Flaws Let Attackers Login With User Session & Cause DoS Attack

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Two vulnerabilities have been discovered in BIG-IP, which are associated with Insufficient Session Fixation and Expired Pointer Dereference. These vulnerabilities have been assigned to CVE-2024-39809 and CVE-2024-39792, and the severity was given as 7.5 (High). Moreover, these vulnerabilities were affecting …