Critical QNAP Vulnerability Let Attackers Execute Remote Code

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Multiple vulnerabilities have been identified in QNAP’s QuRouter, specifically affecting version 2.4.x. The vulnerabilities are tracked as CVE-2024-48860 and CVE-2024-48861, which pose a serious risk as they allow remote attackers to execute arbitrary commands through command injection. The vulnerabilities were …

Explore MITRE ATT&CK Techniques in Real-World Samples With ANY.RUN TI Lookup Tool

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

In a major update aimed at revolutionizing the way cybersecurity professionals tackle threats, ANY.RUN has unveiled its redesigned Threat Intelligence (TI) Lookup platform. The latest update introduces an enhanced home screen that integrates the powerful MITRE ATT&CK matrix, complete with …

New DocuSign Attacks Targeting Organizations Working With Government Agencies

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A new wave of sophisticated phishing attacks exploiting DocuSign has emerged, specifically targeting businesses that regularly interact with state, municipal, and licensing authorities. Cybersecurity researchers have reported a staggering 98% increase in DocuSign phishing URLs between November 8 and 14, …

Bing.com XSS Vulnerability Let Attackers Send Crafted Malicious Requests

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A recent discovery of a cross-site scripting (XSS) vulnerability on Bing.com has raised significant security concerns, potentially allowing attackers to send crafted malicious requests across Microsoft’s interconnected applications. This vulnerability, identified on the main domain of Bing, underscores the risks …

Detecting & Classifying DDoS Attacks Using Machine Learning, New Research

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A new research has unveiled promising developments in the detection and classification of Distributed Denial of Service (DDoS) attacks through the application of advanced machine learning techniques. This breakthrough comes at a critical time as cybersecurity threats continue to evolve …

Meta Taken Down 2 Million Account Linked To Cyber Crime Activities

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Meta has announced the removal of over 2 million accounts linked to cyber crime activities, particularly focusing on schemes like ‘pig butchering.’ This initiative is part of Meta’s broader strategy to combat cross-border criminal organizations exploiting forced labor in scam …

Multiple Vulnerabilities In Veritas Enterprise Vault Let Attackers Execute Remote Code

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Multiple critical vulnerabilities were identified by the Veritas Technologies in its Enterprise Vault software that allows attackers to execute remote code on affected servers. These vulnerabilities, disclosed on November 15, 2024, are due to the deserialization of untrusted data and …

North Korean IT Workers Mimic as US Organizations for Job Offers

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

North Korea has established a global network of highly skilled IT workers who pose as professionals from other countries to secure remote jobs and freelance contracts with businesses worldwide. These workers, operating both individually and through front companies, specialize in …

Hackers Abuse URL Rewriting In Sophisticated Phishing Attack

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cybercriminals have found a new way to exploit email security measures, turning them into tools for their malicious activities. Since mid-June 2024, threat actors have been increasingly abusing URL rewriting features, which are designed to protect users from phishing threats, …

Critical 7-Zip Vulnerability Let Attackers Execute Arbitrary Code

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A severe security vulnerability has been discovered in 7-Zip, the popular file compression utility, allowing remote attackers to execute malicious code through specially crafted archives. The vulnerability tracked as CVE-2024-11477 has received a high CVSS score of 7.8, indicating significant …