Cisco ATA 190 Telephone Adapter Flaw Expose Devices To Remote Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cisco has issued a critical security advisory concerning multiple vulnerabilities in its ATA 190 Series Analog Telephone Adapters. These vulnerabilities could potentially allow remote attackers to execute arbitrary code, posing significant risks to affected devices. The vulnerabilities impact both on-premises …

PoC Exploit Released for BIG-IP Privilege Escalation Vulnerability

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical vulnerability in F5 BIG-IP, a popular network traffic management and security solution tracked as CVE-2024-45844, allows authenticated attackers to bypass access control restrictions and potentially compromise the system. According to the security advisory issued by F5, the vulnerability …

New macOS Vulnerability Allows Attackers to Bypass Security Controls

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A recently discovered vulnerability in macOS, dubbed “HM Surf,” allows attackers to bypass the operating system’s Transparency, Consent, and Control (TCC) technology, gaining unauthorized access to a user’s protected data. This vulnerability, identified as CVE-2024-44133, was uncovered by Microsoft Threat Intelligence and has since been addressed by Apple in the latest security updates for macOS Sequoia, …

Hacking Laptop With a BBQ Lighter to Gain Root Access

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A simple BBQ lighter has been used to exploit vulnerabilities in laptops, gaining root access through an innovative method known as electromagnetic fault injection (EMFI). David Buchanan, a professional hardware researcher, demonstrated this unconventional approach and showcased how a piezo-electric …

macOS Gatekeeper Security Feature Bypassed to Execute Malicious Code

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Security researchers at Palo Alto Networks’ Unit 42 have uncovered significant vulnerabilities in macOS’s Gatekeeper security mechanism. This discovery reveals how certain third-party applications and even some of Apple’s native command-line tools can inadvertently bypass Gatekeeper, potentially allowing malicious code …

What is Lumma Stealer: Technical Details and Recent Fake CAPTCHA Attack

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Lumma Stealer, also known as LummaC2, is a widely known malware that first surfaced in 2022. Since then, it has steadily evolved, improving its techniques for stealing sensitive information. Lumma Stealer targets a wide range of credentials, including browser-stored passwords, …

SAP NetWeaver Code Injection Vulnerability Let Attackers Upload Malicious Files

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical security flaw in SAP NetWeaver AS Java has been uncovered, potentially allowing attackers to upload malicious files and execute unauthorized commands. The vulnerability, identified as CVE-2024-22127, affects the Administrator Log Viewer plug-in and has been assigned a CVSS …

ANY.RUN’s Upgraded Linux Sandbox for Fast and Secure Malware Analysis

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

ANY.RUN upgraded its Linux sandbox with features to enhance malware analysis. It now uses a stable Chrome browser for smoother interaction with suspicious websites, while lag in the process tree view is eliminated, allowing for faster exploration of running processes.  Users can …

Authorities take down Gang Behind ATM Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Dutch, French, and German police forces arrested three members of a notorious criminal network responsible for a series of violent attacks on ATMs across Europe. The coordinated operation occurred in the early hours of October 16, 2024, marking a pivotal …

Multihomed Linux Devices Flaw Allows Spoof of Internal Communication

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical vulnerability has been discovered in multihomed Linux devices. It allows attackers to spoof and inject packets into internal communication streams via an external or public interface. Security researchers uncovered the flaw during several assessments, and it has been …