China-Nexus Hackers Hijack Websites to Deliver Cobalt Strike Malware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Chinese state-sponsored hackers recently compromised two prominent Tibetan websites in a sophisticated cyber-espionage campaign to distribute the notorious Cobalt Strike malware. The attack, attributed to the threat group TAG-112, highlights the ongoing digital threats faced by ethnic and religious minorities …

Zoom App Vulnerability Let Attackers Execute Remote Code

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Zoom recently disclosed multiple vulnerabilities affecting its suite of applications, including a critical flaw that could allow attackers to execute remote code. The Zoom app vulnerabilities, identified by CVE numbers, range from medium to high severity and impact various Zoom …

Critical Fortinet Product Flaws That Let Hackers Take Control of The System

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Fortinet has released critical security updates to address multiple product vulnerabilities, including FortiOS, FortiAnalyzer, FortiManager, and FortiClient Windows. If left unpatched, these flaws could allow attackers to take control of affected systems. One of the most severe vulnerabilities, tracked as …

Apache CloudStack Released Fix for Critical KVM Infrastructure Vulnerabilities

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The Apache CloudStack project has announced the release of critical security updates to address severe vulnerabilities in its KVM-based infrastructure. The latest LTS security releases, versions 4.18.2.5 and 4.19.1.3, patch a significant flaw that could potentially allow attackers to compromise …

CISA Warns of Microsoft Zero-day Exploited in Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The Cybersecurity and Infrastructure Security Agency (CISA) has issued a warning regarding two newly disclosed vulnerabilities in Microsoft Windows, urging organizations and users to apply mitigations promptly to prevent potential exploitation in the wild. These flaws, CVE-2024-49039 and CVE-2024-43451, could allow attackers …

Chrome 131 Released With Fix for 12 Security Vulnerabilities

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Google has released Chrome 131 to the stable channel for Windows, Mac, and Linux, addressing 12 security vulnerabilities, including several high and medium-severity flaws. This update, which will roll out over the coming days and weeks, brings important security fixes …

Microsoft Active Directory Certificate Services Vulnerability (CVE-2024-49019) Discovered

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Microsoft has recently disclosed a new security vulnerability, CVE-2024-49019, in Microsoft Patch Tuesday updates, affecting Active Directory Certificate Services (AD CS). This vulnerability, classified as an Elevation of Privilege (EoP) issue, poses a significant risk to enterprises relying on AD …

Microsoft Released Patch for Exchange Server Email Spoofing Vulnerability – Update Now!

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Microsoft has unveiled crucial Security Updates (SUs) for its Exchange Server platforms. The November 2024 update addresses several vulnerabilities in Exchange Server 2019 and 2016, specifically targeting versions Exchange Server 2019 CU13 and CU14, as well as Exchange Server 2016 …

How to Build an Effective Incident Response Plan: A Practical Guide

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Creating a robust Incident Response Plan (IRP) is essential for businesses navigating today’s cyber-threat terrain. This guide will walk you through how to build an IRP that not only responds to incidents but also protects your company from future threats.  …

What is the CIA Triad (Confidentiality, Integrity, Availability)?

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The CIA Triad stands as one of the fundamental models used to guide policies and strategies for protecting information. The “CIA” in the triad stands for Confidentiality, Integrity, and Availability—three primary objectives that organizations must ensure to safeguard their data, communications, and infrastructure …