Chinese Hacker Charged for Hacking 81,000+ Firewalls Worldwide

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The cybersecurity firm Sichuan Silence and one of its employees, Guan Tianfeng, have been sanctioned by the Department of the Treasury’s Office of Foreign Assets Control (OFAC) for their involvement in the April 2020 hack of tens of thousands of …

Microsoft Office & Excel Vulnerabilities Expose Systems To RCE & Privilege Escalation

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Microsoft disclosed two significant vulnerabilities affecting its Office and Excel products as part of its December Patch Tuesday updates. These vulnerabilities tracked as CVE-2024-49059 and CVE-2024-49069, pose serious security risks by enabling attackers to execute remote code or escalate privileges …

Hackers Exploiting HTML Functions to Bypass Email Security Filters

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cybercriminals increasingly leverage sophisticated HTML techniques to circumvent email security filters, putting users and organizations at greater risk of falling victim to phishing attacks. These attacks, often disguised as legitimate documents such as invoices or HR policies, exploit various HTML …

Critical Vulnerabilities in Ivanti CSA Let Attackers Bypass Admin Web Console Remotely

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Ivanti has released crucial security updates to address multiple vulnerabilities in its Cloud Services Application (CSA) software, including critical flaws that could allow attackers to bypass authentication and execute remote code. Organizations are urged to update their software immediately to …

Chrome Security Update, Patch for 3 High-severity Vulnerabilities

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Google has released a critical security update for its Chrome browser, addressing three high-severity vulnerabilities that could potentially expose users to significant risks. The latest update, version 131.0.6778.139/.140 for Windows and Mac and 131.0.6778.139 for Linux, is being rolled out …

Windows Common Log File System Zero-day (CVE-2024-49138) Exploited in the Wild

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A new high-severity security vulnerability, CVE-2024-49138, has been identified in the Windows Common Log File System (CLFS) Driver as a zero-day that was exploited in the wild. Microsoft confirmed that this vulnerability is categorized as an Elevation of Privilege issue …

Microsoft December 2024 Patch Tuesday – 71 Vulnerabilities Fixed, Including 1 Zero-day & 30 RCEs

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Microsoft released a security as part of the December Patch Tuesday that addressed 72 vulnerabilities, including 30 classified as critical Remote Code Execution (RCE) vulnerabilities. These fixes are crucial for securing Windows operating systems and related software against potential exploitation. …

Microsoft 365 Down: Web Apps and Admin Center are Affected

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Microsoft is investigating a widespread outage that disrupted access to Microsoft 365 web applications and the Microsoft 365 admin center earlier today. The issue affected users attempting to connect to services like Outlook, OneDrive, and other Office 365 applications through …

Cleo Zero-Day RCE Vulnerability Actively Exploited in the Wild

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical zero-day vulnerability (CVE-2024-50623) in Cleo’s file transfer products Harmony, VLTrader, and LexiComis being actively exploited by threat actors, cybersecurity researchers have warned. The flaw, stemming from an unrestricted file upload and download vulnerability, allows unauthenticated remote code execution …

Chinese Hackers Using Visual Studio Code Tunnels & RDP To Gain Remote Access

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

In a sophisticated cyber-espionage campaign dubbed ‘Operation Digital Eye,’ suspected Chinese state-backed hackers targeted major business-to-business IT service providers across Southern Europe between late June and mid-July 2024. The attackers employed a clever technique, exploiting Visual Studio Code Tunnels and …