Japan Airlines System Hit by Cyber Attack, Flight Operations Affected

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Japan Airlines (JAL), the nation’s second-largest airline, reported a significant cyberattack on its systems early Thursday morning, causing disruptions to both domestic and international flight operations. The attack, which began at 7:24 AM local time (2224 GMT), targeted the airline’s …

New Sophisticated Attack Weaponizes Windows Defender to Bypass EDR

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated attack technique that weaponizes Windows Defender Application Control (WDAC) to disable Endpoint Detection and Response (EDR) sensors on Windows machines. WDAC, a technology introduced with Windows 10 and Windows Server 2016, was designed to give organizations fine-grained control …

Apache Traffic Control Vulnerability Let Attackers Inject Malicious SQL Commands

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical SQL injection vulnerability, identified as CVE-2024-45387, has been discovered in Apache Traffic Control, a widely used open-source platform for managing large-scale content delivery networks (CDNs). This vulnerability affects versions 8.0.0 through 8.0.1 of the software and has been …

Postman Data Leak – 30,000 Publicly Accessible Workspaces Could Lead Massive Hack

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Researchers uncovered a widespread and alarming trend involving data leaks from Postman, a widely used cloud-based API development and testing platform. The investigation reveals that improper management of Postman workspaces has resulted in over 30,000 publicly accessible collections exposing sensitive …

Apache HugeGraph-Server Vulnerability Lets Attackers Bypass Authentication

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A new security vulnerability, CVE-2024-43441, has been identified in Apache HugeGraph-Server, a widely used open-source graph database system. This flaw, classified as an Authentication Bypass by Assumed-Immutable Data vulnerability, affects versions 1.0 to 1.3 of the software prior to the …

OilRig Hackers Exploiting Windows Kernel 0-day to Attack Organizations

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The Iranian state-sponsored hacking group OilRig, also known as APT34, has intensified its cyber espionage activities, targeting critical infrastructure and government entities in the United Arab Emirates and the broader Gulf region. Security researchers from Picus Labs have uncovered a …

Two New Malicious PyPI Packages Attacking Users to Steal Login Details

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Two malicious Python Package Index (PyPI) packages: Zebo-0.1.0 and Cometlogger-0.1, have been identified, posing a significant threat to user security. These packages, uploaded in November 2024, exploit unsuspecting developers and users, aiming to steal sensitive data such as login credentials, browsing history, …

Adobe ColdFusion Vulnerability Let Attackers Read arbitrary files – PoC Released

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Adobe has issued updates to address a vulnerability in its ColdFusion software that could allow attackers to read arbitrary files from affected systems. The flaw, identified as CVE-2024-53961, has a proof-of-concept (PoC) exploit publicly available, heightening the urgency for system administrators …

Node.js “systeminformation” Vulnerability Exposes Millions of Systems to RCE Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical security vulnerability has been discovered in the widely-used Node.js package “systeminformation,” potentially exposing millions of systems to remote code execution (RCE) attacks. The flaw, identified as CVE-2024-56334, affects versions up to and including 5.23.6 of the package, which …

Brazilian Hacker Charged for Selling Data Stolen From Hacked Computers

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Junior Barros De Oliveira, a 29-year-old resident of Curitiba, Brazil, has been indicted in the United States for orchestrating an extortion scheme involving data stolen from the computer systems of a Brazilian subsidiary of a New Jersey-based company. U.S. Attorney …