VMware vCenter Server RCE Vulnerability Actively Exploited in Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Broadcom has issued an urgent warning that two critical vulnerabilities in VMware vCenter Server are now being actively exploited in the wild. The more severe of the two flaws is a remote code execution (RCE) vulnerability tracked as CVE-2024-38812, which …

Google Announces Shielded Email Feature To Hide Your Main Email Address

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Google has unveiled a groundbreaking new feature called “Shielded Email” that aims to revolutionize email privacy and combat spam. This innovative tool allows Gmail users to create temporary email aliases, effectively masking their primary email address when signing up for …

Apache HertzBeat Vulnerability Let Attackers Exfiltrate Sensitive Data

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A recently discovered vulnerability in Apache HertzBeat, an open-source real-time monitoring tool, has raised concerns about potential data exfiltration. The security flaw, identified as CVE-2024-45791, affects versions of Apache HertzBeat prior to 1.6.1 and could allow unauthorized actors to access …

Zohocorp ManageEngine ADAudit Plus Vulnerable To SQL Injection Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Zohocorp’s ManageEngine has disclosed a critical vulnerability in its ADAudit Plus software during a significant cybersecurity development. It’s a popular tool used for Active Directory auditing and reporting. The vulnerability, identified as CVE-2024-49574, exposes versions of ADAudit Plus prior to …

Team Software Breach, Hackers Gain Unauthorized Access To Network Infrastructure

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

TEAM Software, a Nebraska-based company specializing in workforce management solutions, has fallen victim to a data breach affecting approximately 99,525 individuals. This security event was reported via ‘Data Breach Notifications’ by the Office of the Maine Attorney General. The unauthorized …

Citrix Virtual Apps & Desktops Vulnerability Actively Exploited in Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A recently discovered vulnerability in Citrix Virtual Apps and Desktops is being actively exploited in the wild. The flaw, which allows for unauthenticated remote code execution (RCE), poses a significant threat to organizations using the popular remote access solution. Last …

PostgreSQL Security Update, Patch For Multiple Vulnerabilities

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The PostgreSQL Global Development Group has released a critical security update for all supported versions of PostgreSQL. All the supported versions of PostgreSQL includes 17.1, 16.5, 15.9, 14.14, 13.17, and 12.21. While this security update addresses four security vulnerabilities and …

Sonatype Nexus Repository Manager Hit By RCE & XSS Vulnerability

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Sonatype has disclosed two significant vulnerabilities in a critical security update released on November 13, 2024, affecting their Nexus Repository Manager 2.x versions. The two vulnerabilities pose serious risks to organizations using the affected software versions. While these two vulnerabilities …

Samba AD Vulnerability Let Attackers Escalate Privilege

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical vulnerability in Samba Active Directory (AD) implementations has been discovered that could allow attackers to escalate privileges and potentially take over entire domains. The flaw, tracked as CVE-2023-3961, affects Samba versions 4.13.0 and later when configured as an …

BrazenBamboo APT Exploiting FortiClient Zero-Day to Steal User Credentials

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated cyber espionage campaign conducted by a threat actor known as BrazenBamboo. The group is exploiting an unpatched vulnerability in Fortinet’s FortiClient VPN software for Windows to steal user credentials, as part of a broader attack using a modular …