CISA, NSA, & FBI Release List of 15 Most Exploited Vulnerabilities in 2023

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The Cybersecurity and Infrastructure Security Agency (CISA), National Security Agency (NSA), and Federal Bureau of Investigation (FBI) have jointly released a critical cybersecurity advisory detailing the 15 most routinely exploited vulnerabilities in 2023. This collaborative effort, which also involved cybersecurity …

Microsoft November Patch Tuesday: 4 Zero-Days & 89 Vulnerabilities Patched

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Microsoft released its latest Patch Tuesday update, addressing 89 security vulnerabilities across its software portfolio. Four of these are classified as zero-day vulnerabilities, with two actively exploited in the wild. This patch release underscores the critical importance of timely updates …

Citrix Virtual Apps & Desktops RCE Vulnerability, PoC Exploitation Underway

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Security researchers have disclosed critical vulnerabilities in Citrix Virtual Apps and Desktops that could allow remote code execution (RCE) attacks. Proof-of-concept (PoC) exploitation attempts have already been observed in the wild, highlighting the urgency for organizations to patch affected systems. …

SAP Security Update: Patch For High Severity Vulnerabilities

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

SAP has released its July 2024 security patch update, addressing 18 product vulnerabilities. The update includes fixes for two high-severity flaws that could potentially allow attackers to gain unauthorized access to sensitive data and systems. The most critical vulnerability, CVE-2024-39592, …

New Android Malware SpyAgent Taking Screenshots Of Users’ Devices

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Android malware has evolved significantly since its inception, transitioning from simple threats like SMS Trojans to complex ransomware and banking Trojans. The evolution of Android malware reflects a broader trend of increasing sophistication in mobile malware driven by the Android …

SelectBlinds Data Breach, 200,000+ Customers Card Details Skimmed in Cyberattack

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

SelectBlinds, a well-known online retailer specializing in custom blinds and shades, has confirmed a data breach that exposed the sensitive information of 206,238 customers. The breach, attributed to a sophisticated cyberattack, allowed hackers to embed malicious software on the company’s …

Hackers Leveraging Microsoft Visio Files & SharePoint For Two-Step Phishing Attack

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A new sophisticated phishing technique utilizes Microsoft Visio files and SharePoint in a two-step phishing attack. This two-step attack method represents a significant evolution in phishing tactics. It exploits users’ trust in familiar Microsoft tools to bypass security measures and …

VMware Workstation & Fusion Now Free For All Users

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

VMware, a leading virtualization software provider, has significantly changed its licensing model for its popular desktop hypervisor products, VMware Fusion and VMware Workstation. Both products are now free for all users, including commercial, educational, and personal users, effective November 11, …

Dell Enterprise SONiC Vulnerabilities Let Attackers Compromise The System

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Dell Technologies has disclosed three critical security vulnerabilities affecting its Enterprise SONiC (Software for Open Networking in the Cloud) operating system. These vulnerabilities could allow attackers to compromise affected systems. The vulnerabilities, identified as CVE-2024-45763, CVE-2024-45764, and CVE-2024-45765, impact Dell …

PAN-OS Access Management RCE Vulnerability, 11k+ Interface IPs Exposed

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Palo Alto Networks has issued a critical security advisory regarding a potential remote code execution (RCE) vulnerability affecting the PAN-OS management interface of their next-generation firewalls. The advisory, released on November 8, 2024, warns customers to restrict access to their …