North Korean Hackers Exploit Zero-Day Flaw In Internet Explorer

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A joint report by AhnLab Security Emergency response Center (ASEC) and the National Cyber Security Center (NCSC) has revealed a new zero-day vulnerability (CVE-2024-38178) in Microsoft Internet Explorer (IE) being actively exploited by North Korean hackers. The campaign, dubbed “Operation …

Linux System ‘noexec’ Mount Flag Flaw Allows Malicious Code Execution

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A recent discovery in the Linux ecosystem has unveiled a method to bypass the ‘noexec’ mount flag, enabling malicious code execution on systems that were previously thought to be secure. This vulnerability exploits a combination of Linux system calls and …

Critical Oracle Security Update, 334 Vulnerabilities Patched

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Oracle has released its October 2024 Critical Patch Update (CPU), addressing a staggering 334 security vulnerabilities across its vast product portfolio. This quarterly update, the fourth and final of 2024, underscores the ongoing importance of cybersecurity vigilance for organizations relying …

90+ 0-Days, 40+ N-Days Exploited In The Wild

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Hackers exploit security vulnerabilities in the wild primarily to gain ‘unauthorized access to systems,’ ‘steal sensitive data,’ and ‘disrupt services.’ These vulnerabilities often arise from “software bugs,” “misconfiguration,” and “outdated systems” that have not been patched. Cybersecurity researchers at Mandiant …

Authorities Takendown Sipulitie Dark Web Marketplace

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Finnish Customs, in collaboration with the Swedish Police, has successfully shut down the Sipulitie dark web marketplace. This site, operating on the encrypted Tor network since February 2023, was notorious for facilitating the anonymous sale of narcotics. The takedown marks …

Kubernetes Image Builder Flaw Let Attackers Gain Root Access to VMs

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The Kubernetes Security Response Committee has disclosed two critical vulnerabilities in the Kubernetes Image Builder that could allow attackers to gain root access to virtual machines (VMs). The flaws, identified as CVE-2024-9486 and CVE-2024-9594, stem from the use of default …

CISA Warns of Three Vulnerabilities Actively Exploited in the Wild

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent alert regarding three critical vulnerabilities currently exploited in the wild. These vulnerabilities affect widely used software products from Microsoft, Mozilla, and SolarWinds, posing significant security risks to organizations and …

Microsoft Dataverse Authentication Flaw Let Attackers Escalate Privileges

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical security vulnerability in Microsoft Dataverse has been discovered, allowing authorized attackers to elevate their privileges over a network. The flaw, identified as CVE-2024-38139, has a high severity rating with a CVSS base score of 8.7, indicating its potential …

Chrome 130 Released with Fix for 17 Security Flaws

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Google has released Chrome 130, addressing 17 security vulnerabilities in the popular web browser. This latest update, version 130.0.6723.58/.59 for Windows and Mac and 130.0.6723.58 for Linux is being rolled out gradually to users over the coming days and weeks. …

Why Traditional Correlation Rules Aren’t Enough for Your SIEM – SOC Guide

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

If you’re managing an SIEM (Security Information and Event Management) system, you know how vital centralized threat detection is. SIEM collects and analyzes data from multiple sources—your firewalls, applications, servers—and looks for patterns that could be a security threat. But …