Cipla Allegedly Hacked, Akira Ransomware Claims 70GB Data Stolen

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cipla, the Indian pharmaceutical giant, has reportedly fallen victim to a cyberattack orchestrated by the Akira ransomware group. The hackers claim to have exfiltrated a staggering 70GB of sensitive data from the multinational company, which operates 47 manufacturing facilities globally …

OpenWrt Supply Chain Attack Via SHA-256 Collision & Command Injection

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical vulnerability in OpenWrt’s firmware upgrade system has been recently unveieled by the security researcher RyotaK from Flatt Security Inc.. The exploit, which combines a truncated SHA-256 collision with a command injection technique, could have potentially compromised the entire …

Hackers Attacking Global Sporting Championships Via Fake Domains To Steal Logins

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cybercriminals leverage high-profile events, such as global sporting championships, by registering fake domains to launch phishing and scam attacks. Researchers uncover suspicious domain registration campaigns, especially when event-specific terms or phrases are used in recently registered domains.  Event-related abuse focuses …

Microsoft Challenged AI Hackers To Break LLM Email Service, Rewards Up To $10,000

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Microsoft has launched an innovative cybersecurity challenge that puts artificial intelligence (AI) to the test. As Microsoft is inviting hackers and security researchers to attempt to break its simulated LLM-integrated email client, dubbed the LLMail service, with rewards of up …

Synology Router Vulnerabilities Let Attackers Inject Arbitrary Web Script

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Synology, a leading provider of network-attached storage and networking solutions, has recently patched multiple vulnerabilities in its Router Manager (SRM) software. These security flaws, classified as moderate in severity, could allow attackers to inject arbitrary web scripts or HTML into …

Researcher Demonstrated On How Attacker Can Gain Full Admin Access With XSS

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A cybersecurity researcher has unveiled an unexpected discovery that demonstrates how a simple Cross-Site Scripting (XSS) vulnerability can be leveraged to gain full administrative access to a web application, even in the presence of robust security measures. The researcher, identified …

Google’s New Open-Source Patch Validation Tools Vanir Unveiled

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Google has officially launched Vanir, a groundbreaking open-source security patch validation tool designed to enhance the efficiency and accuracy of patch management. Announced during the Android Bootcamp in April, Vanir is now available for public use, offering developers a powerful …

Qlik Sense Enterprise For Windows Vulnerability Let Attackers Execute Remote Code

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical security vulnerability has been discovered in Qlik Sense Enterprise for Windows, potentially allowing attackers to execute remote code on affected systems. The issue, identified during internal security testing by Qlik, affects all versions of the software prior to …

Raspberry Pi 500 All-in-One Compact Computer Launched With New Features

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Just in time for the holiday season, Raspberry Pi has unveiled two highly anticipated products that are expected to be popular among both tech enthusiasts and educators. The company has announced the release of the Raspberry Pi 500 all-in-one compact …

Critical Windows Zero-Day Vulnerability Exploited in the Wild – PoC Released

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Microsoft has patched a critical zero-day vulnerability (CVE-2024-38193) that the notorious North Korean hacker group Lazarus APT actively exploited. Gen Threat Labs discovered and reported the flaw, which posed a severe threat to Windows users worldwide. The vulnerability, identified in …