Hackers Exploiting ProjectSend Authentication Vulnerability In The Wild

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Hackers are actively exploiting a critical authentication vulnerability in ProjectSend, a popular open-source file-sharing web application. The vulnerability, now identified as CVE-2024-11680, allows remote, unauthenticated attackers to bypass authentication and modify the application’s configuration, potentially leading to unauthorized account creation, …

Hackers Launch Zero-Day Attacks to Exploits Corrupted Files to Evade Security Tools

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cybersecurity experts at ANY.RUN have uncovered an active zero-day attack campaign that leverages corrupted files to bypass antivirus software, sandbox environments, and even email spam filters. The attack, first identified by the ANY.RUN team, poses a significant threat by enabling …

Firefox 133 Released With Fix For Multiple Security Vulnerabilities

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Mozilla has officially launched Firefox 133.0, introducing a host of new features, performance improvements, and critical security fixes. The release, first offered to the Release channel on November 26, 2024, brings significant advancements in privacy protection, developer tools, and overall …

Bootkitty, The First UEFI Bootkit Targeting Linux Servers

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Researchers have uncovered the first UEFI bootkit designed specifically for Linux systems, named Bootkitty. This discovery marks a pivotal moment in the evolution of UEFI threats, which have traditionally targeted Windows systems exclusively. The UEFI threat landscape has seen considerable …

NVIDIA UFM Vulnerability Let Attackers Escalate Privileges

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A high-severity vulnerability has been disclosed recently on November 26, 2024 by NVIDIA affecting its UFM Enterprise, UFM Appliance, and UFM CyberAI products. The flaw, identified as CVE-2024-0130, could allow attackers to escalate privileges, tamper with data, cause denial of …

IBM Engineering Systems Flaw Let Attackers Bypass Security Restrictions

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical security vulnerability has been discovered in IBM Engineering Systems Design Rhapsody – Model Manager (RMM), potentially allowing remote attackers to bypass security restrictions and execute code. The flaw, identified as CVE-2024-41779, affects versions 7.0.2 and 7.0.3 of the …

Junior School Student Charges For Infecting Computers With ‘Test of Skill’ Virus

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A 15-year-old junior high school student from Saitama Prefecture has been charged with creating and distributing a computer virus. The Fukui Police Station and the Cyber Crime Division of the Fukui Prefectural Police forwarded the case to the prosecutor’s office …

20 Years Old macOS Vulnerability Allow Attackers To Gain Root Access Remotely

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A security researcher, Gergely Kalman, uncovered a severe macOS vulnerability privilege escalation in Apple’s MallocStackLogging framework, which had remained undetected for approximately 20 years. The bug, tracked as CVE-2023-32428, was discovered in March 2023 and subsequently patched by Apple in …

VMware Aria Operations Vulnerabilities Allow Privilege Escalation & XSS Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

VMware, a leading cloud computing and virtualization software provider, has disclosed multiple critical vulnerabilities in its Aria Operations product. The most severe flaws could allow attackers to escalate privileges to the root user on affected systems. The advisory, identified as …

Interpol Arrested 1,000+ Cybercriminals and Dismantled 130,000+ Malicious Networks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A joint operation by INTERPOL and AFRIPOL has led to the arrest of 1,006 suspects and the dismantling of 134,089 malicious infrastructures across 19 African countries. The operation, codenamed Operation Serengeti, targeted cybercriminals involved in ransomware, business email compromise (BEC), …