AWS Execution Roles Enable Subtle Privilege Escalation in SageMaker and EC2

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A persistent privilege escalation technique in AWS that allows attackers with limited permissions to execute code under higher-privileged execution roles on EC2 instances and SageMaker notebook instances. First documented by Grzelak in 2016 for EC2, the method exploits modifiable boot-time …

Russian Hackers Spoof European Events in Targeted Phishing Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Russian threat actors are running a new wave of phishing campaigns that spoof major European security events to quietly steal cloud credentials. Invitations that look legitimate, often tied to conferences such as the Belgrade Security Conference or the Brussels Indo-Pacific …

Critical Apache Tika Core Vulnerability Exploited by Uploading Malicious PDF

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical security vulnerability in Apache Tika has been discovered that allows attackers to compromise systems by uploading specially crafted PDF files. Organizations worldwide are urged to patch immediately. Apache Tika is a popular open-source toolkit used by thousands of …

NCSC New Proactive Notifications Service Reports Vulnerabilities to System Owners

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The National Cyber Security Centre (NCSC) has unveiled a new pilot program designed to help organizations identify and fix security weaknesses before malicious actors can exploit them. Known as the Proactive Notifications Service, this initiative responsibly reports vulnerabilities directly to system …

Hackers Exploiting Microsoft Teams Notifications to Deliver CallBack Phishing Attack

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cybersecurity researchers have identified a sophisticated phishing campaign that exploits Microsoft Teams notifications to deceive users into calling fraudulent support numbers. The attack demonstrates how legitimate communication platforms can be weaponized to bypass security defenses and email filters. According to …

Russian Calisto Hackers Target NATO Research Sectors with ClickFix Malicious Code

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Russian-backed threat actors continue their sophisticated cyber espionage operations against Western institutions through advanced phishing tactics. Calisto, a Russia-nexus intrusion set attributed to the Russian FSB’s Center 18 for Information Security (military unit 64829), has emerged as a persistent threat …

China-Nexus Hackers Exploiting VMware vCenter Environments to Deploy Web Shells and Malware Implants

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A new sophisticated threat actor has emerged in the cybersecurity landscape, targeting critical infrastructure across the United States. The adversary, operating under the name WARP PANDA, has demonstrated remarkable technical capabilities in infiltrating VMware vCenter environments at legal, technology, and …

NVIDIA Triton Vulnerability Let Attackers Trigger DoS Attack Using Malicious Payload

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Critical security updates have been released to fix two high-severity flaws in the Triton Inference Server that let attackers crash systems remotely from NVIDIA. Both flaws received a CVSS score of 7.5, indicating they are high-priority threats requiring immediate patching. …

Hackers Actively Exploiting ArrayOS AG VPN Vulnerability to Deploy Webshells

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Attackers are actively exploiting a serious vulnerability in Array Networks’ ArrayOS AG series to gain unauthorized access to enterprise networks. The flaw exists in the DesktopDirect function, a feature designed to provide remote desktop access to administrators. Security researchers have …

Cloudflare Outage Hits Internet with 500 Internal Server Error

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A major disruption swept across the internet today as Cloudflare, a critical backbone for millions of websites, reported widespread issues with its Dashboard and APIs, triggering 500 Internal Server Errors for users globally. The outage, confirmed by Cloudflare’s status page, …