SAP NetWeaver Vulnerabilities Let Attackers Upload Malicious PDF Files

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

SAP has issued a crucial security update addressing multiple high-severity vulnerabilities in its NetWeaver Application Server for Java, specifically within the Adobe Document Services component. The patch, released on December 10, 2024, as part of SAP’s monthly Security Patch Day, …

WhatsApp View Once Vulnerability Let Attackers Bypass The Privacy Feature

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Meta’s WhatsApp recently faced scrutiny after a significant vulnerability in its “View Once” feature was discovered, allowing attackers to bypass its privacy protections. This feature, designed to let users send media that can only be viewed once, was found to …

New Meeten Malware Targets macOS and Windows Users to Steal Login Credentials

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A new scam effort has been observed targeting Web3 leveraging fake video conferencing applications to deliver an information stealer dubbed Realst. Realst crypto stealer has been active for almost four months and targets both macOS and Windows users. Operating under …

Radiant Hacked – $50 Million USD Worth Crypto Stolen by North Korean Hackers

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Radiant Capital, a prominent decentralized finance (DeFi) protocol, has fallen victim to a major security breach, resulting in the loss of approximately $50 million USD. The attack, which exploited vulnerabilities in the devices of long-standing, trusted developers, has been described …

CISA listed Over 270 Critical Vulnerabilities That Were Fixed Last Week – What’s New!

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The Cybersecurity and Infrastructure Security Agency (CISA) has published its latest vulnerability bulletin, detailing over 270 security vulnerabilities identified in the past week across a wide range of software and hardware. These vulnerabilities affect popular applications, operating systems, IoT devices, …

Critical Vulnerability in Python Affected MacOS or Linux Leads to Exploiting The Memory

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A high-severity vulnerability (CVE-2024-12254) impacting CPython has been publicly disclosed, affecting Python versions 3.12.0 and later. The flaw, identified in the asyncio module, specifically lies in the _SelectorSocketTransport.writelines() method, potentially leading to memory exhaustion under certain conditions. Leveraging 2024 MITRE …

Uncovering Attacker’s Infrastructre & Tactics Via Passive DNS

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

In the ever-evolving landscape of cybersecurity, understanding how attackers establish and maintain their attack infrastructure is crucial for building robust defenses. A recent study by Juniper Threat Labs sheds light on the sophisticated methods attackers use to set up their …

Let’s Encrypt to End Support for Online Certificate Status Protocol (OCSP)

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Let’s Encrypt, a leading provider of free SSL/TLS certificates, has officially announced its timeline for discontinuing support for the Online Certificate Status Protocol (OCSP) in favor of Certificate Revocation Lists (CRLs). This decision, driven by privacy and efficiency concerns, marks …

Romania’s Leading Energy Provider Electrica Group Hit by Ransomware Attack

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Electrica Group, one of Romania’s most prominent energy service providers, has confirmed it is grappling with a ransomware attack. The cyber incident has prompted the company to activate its emergency response protocols and collaborate closely with national cybersecurity authorities to …

Mauri Ransomware Exploiting Apache ActiveMQ Vulnerability

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The Apache ActiveMQ Vulnerability, identified as CVE-2023-46604, was exploited by Mauri Ransomware threat actors to install CoinMiners. Threat actors were detected continuously launching attacks on unpatched, vulnerable Apache ActiveMQ services. Once the compromised machine has been infected, threat actors can …