PoC Exploit Released For Windows Kernel-Mode Drivers Privilege Escalation Flaw

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical vulnerability in Windows Kernel-Mode Drivers has been exposed with the release of a Proof-of-Concept (PoC) exploit, allowing attackers to escalate privileges to SYSTEM level. The vulnerability, identified as CVE-2024-35250, affects various versions of Windows, including Windows 11 and …

Nation-State Actors Exploiting Ivanti CSA 0-days To Compromise Victims’ Networks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Researchers have uncovered a sophisticated attack campaign targeting Ivanti Cloud Services Appliance (CSA) users. Nation-state actors are exploiting multiple zero-day vulnerabilities in the CSA to gain unauthorized access to victims’ networks and establish a foothold for further malicious activities. FortiGuard …

Critical Jetpack Vulnerability Impacts 27 Million Sites

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Jetpack, a popular WordPress plugin, has released a critical security update. Version 13.9.1 was launched earlier today to address a vulnerability that could potentially expose sensitive visitor information. The flaw, identified during an internal security audit, affects the Contact Form …

Netgear WiFi Extender Vulnerability Let Attackers Inject Malicious Commands

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Security researchers have uncovered critical vulnerabilities in several popular Netgear WiFi extender models that could allow attackers to execute malicious commands on affected devices. The flaws, tracked as CVE-2024-35518 and CVE-2024-35519, impact the Netgear EX6120, EX6100, and EX3700 extenders running …

What is Broadcast? Types, Examples & How it Works!

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Broadcasting, in the context of computer networks, refers to a method of communication where a message is sent from one node to all other nodes within a network. This concept is pivotal in networking and extends to other fields, such …

Next.js Image Optimization Vulnerability Let Attackers Exhaust CPU Resources

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical security vulnerability has been discovered in the popular React framework Next.js, potentially allowing attackers to exhaust CPU resources through its image optimization feature. The flaw, identified on October 14, 2024, affects versions up to 14.2.6 and could lead …

Multiple Splunk Enterprise Vulnerabilities Let Attackers Execute Remote Code

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Splunk has released patches for several high-severity vulnerabilities in its Enterprise product that could allow attackers to execute remote code on affected systems. The vulnerabilities impact multiple versions of Splunk Enterprise and Splunk Cloud Platform. One of the most critical …

New Supply Chain Attack Leveraging Entry Points in PyPI, npm, Ruby Gems & NuGet

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated supply chain attack has been identified, leveraging entry points in popular open-source package repositories, including PyPI (Python), npm (JavaScript), Ruby Gems, and NuGet (.NET). This attack vector poses significant risks to both individual developers and enterprises, highlighting the …

CoreWarrior Malware Attacking Windows Machines With Self-replication Capabilities

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Malware targeting Windows machines continues to be a significant threat. While these threats could be in various forms like viruses, worms, and ransomware. These malicious programs can infiltrate systems via illicit methods like “phishing emails,” “infected downloads,” and “vulnerabilities.” Cybersecurity …

OilRig Hackers Exploiting Microsoft Exchange Servers To Steal Login Details

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

OilRig hackers (aka Earth Simnavaz, APT34, OilRig) is a cyber espionage group that was linked to “Iranian” interests. This APT group primarily targets energy, governmental, and critical infrastructure sectors. Cybersecurity researchers at Trend Micro recently discovered that OilRig hackers have …