MediaTek Smartphone Chipsets Vulnerabilities Let Attackers Escalate Privileges

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Recent security bulletins have disclosed high-severity vulnerabilities in MediaTek smartphone chipsets, which could enable attackers to escalate privileges and gain unauthorized access to the affected devices. These vulnerabilities, identified in various MediaTek components, pose significant risks to Android smartphones running …

SYS01 InfoStealer Malware Attacking Meta Business Page To Steal Logins

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Infostealer malware is a type of malicious software designed to infiltrate computer systems and extract sensitive information. Once the data is collected, it is sent to remote servers controlled by threat actors and often resold on “dark web markets.” Cybersecurity …

280+ Typosquat Malicious Packages Attacking npm Developers

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Over 280 malicious typosquat packages have been unearthed in an ongoing campaign targeting JavaScript developers using the popular npm (Node Package Manager) ecosystem. The attack, which began in late October 2024, is specifically aimed at developers who rely on widely used libraries such as Puppeteer, Bignum.js, …

Threat Actors Planted ‘Pygmy Goat’ Backdoor On Hacked Sophos XG Firewall

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

NCSC researchers have uncovered a sophisticated backdoor dubbed “Pygmy Goat” that was deployed on compromised Sophos XG firewall devices. The malware, discovered by the National Cyber Security Centre (NCSC), provides attackers with persistent access and powerful capabilities to maintain a …

Opera Browser 0-Day Flaw Allows Malicious Extensions to Takeover Browser

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical vulnerability in the Opera web browser has been discovered that could allow malicious extensions to gain unauthorized access to private APIs, potentially leading to account hijacking and other severe security breaches. Researchers at Guardio Labs dubbed the flaw …

Weekly Cybersecurity Newsletter: Data Breaches, Vulnerabilities, Cyber Attacks, & Other Updates

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Welcome to this week’s Cybersecurity Newsletter, where you will find the latest updates and insights from the cybersecurity world. Stay informed and protected with our top stories. Stay updated on the latest threats and advancements in the ever-changing digital landscape. …

LastPass Warns of Hackers Misusing Reviews for Fake Support Numbers

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

LastPass, the popular password management service, has issued an urgent warning to its users about an ongoing social engineering campaign targeting customers through fake reviews on the Chrome Web Store. The company has discovered that threat actors post fraudulent 5-star …

Okta AD/LDAP Authentication Vulnerability Allows Unauthorized Access

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Okta, a leading company in identity and access management, has recently addressed a critical vulnerability in its AD/LDAP Delegated Authentication system. Okta’s security team internally discovered and promptly addressed the flaw, which could potentially allow unauthorized access to user accounts. …

DDoS Attacks Service Provider Websites Seized by Authorities

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

In a coordinated international effort, authorities have conducted a significant crackdown on cybercrime, arresting two suspects, seizing online platforms used for narcotics trafficking, and executing DDoS attacks. Two individuals, aged 19 and 28, from Darmstadt and the Rhein-Lahn district, were …

Azure Virtual Desktop May Experience 30 mins Black Screen During Logon

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Microsoft has warned Azure Virtual Desktop (AVD) users about potential black screen issues lasting up to 30 minutes when logging in after installing the July 2024 non-security preview update (KB5040525) or subsequent updates. This problem primarily affects enterprise users in …