PoC Exploit Released for Microsoft Office 0-day Flaw – CVE-2024-38200

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Security researchers have released a proof-of-concept (PoC) exploit for the recently disclosed Microsoft Office vulnerability CVE-2024-38200, which could allow attackers to capture users’ NTLMv2 hashes. This high-severity flaw affects multiple versions of Microsoft Office, including Office 2016, Office 2019, Office …

14 DrayTek Routers Vulnerabilities Let Hackers Hijack 700K Devices Remotely

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Researchers have identified fourteen new vulnerabilities in DrayTek Vigor routers, including a critical remote code execution flaw rated 10 out of 10 on the CVSS severity scale. DrayTek, a Taiwanese networking equipment maker, offers advanced routers with VPN, firewalls, and …

Ivanti Endpoint Manager Vulnerability Public Exploit is Now Used in Cyber Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The Cybersecurity and Infrastructure Security Agency (CISA) has announced the addition of a new vulnerability to its Known Exploited Vulnerabilities Catalog. Cybercriminals have used public exploits in recent attacks targeting Ivanti endpoints. Ivanti is a U.S.-based IT software company that …

Cisco Small Business Routers Vulnerabilities Allow Attacker Exploits It Remotely

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

In a recent security advisory, Cisco has disclosed multiple vulnerabilities affecting its Small Business RV340, RV340W, RV345, and RV345P Dual WAN Gigabit VPN Routers. Additionally, Cisco has issued a security advisory regarding a critical vulnerability in its Nexus Dashboard Fabric …

Cisco Nexus Vulnerability Let Attackers Launch Command Injection Attack

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cisco has issued a security advisory regarding a critical vulnerability in its Nexus Dashboard Fabric Controller (NDFC). This flaw could allow an authenticated, low-privileged, remote attacker to perform a command injection attack on affected devices. The vulnerability arises from improper …

Tor Browser 13.5.6 Released – What’s New!

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The Tor Browser 13.5.6 has been released with crucial security updates for Firefox and several enhancements and bug fixes across all platforms. Notably, NoScript has been updated to version 11.4.40, and issues such as download spam prevention affecting browser extensions …

Red Barrels IT Systems Breached by Nitrogen Ransomware Group

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Montreal-based video game developer Red Barrels, known for its critically acclaimed Outlast series, has recently experienced a significant cybersecurity breach. The attack, attributed to the Nitrogen Ransomware Group, has reportedly compromised 1.8 terabytes of sensitive data, including game source codes …

Mario Duarte, Former Snowflake Cybersecurity Leader, Joins Aembit as CISO to Tackle Non-Human Identities

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Aembit, the non-human IAM company, today announced the appointment of Mario Duarte as chief information security officer (CISO). Duarte, formerly head of security at Snowflake, joins Aembit with a deep commitment to address pressing gaps in non-human identity security. Duarte’s …

Zimbra Remote Command Execution Vulnerability (CVE-2024-45519) – Exploit POC Released

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Zimbra, a popular email and collaboration platform, has issued a crucial security update to patch a severe vulnerability in its postjournal service. Identified as CVE-2024-45519, this flaw allows unauthenticated attackers to execute arbitrary commands on affected Zimbra installations. The vulnerability …

Evil Corp Cyber Criminals Group Identity Exposed Along with Lockbit Affiliate

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Authorities in the UK, US, and Australia have sanctioned sixteen individuals linked to Evil Corp, a group once considered the pinnacle of global cyber threats. This move exposes their connections to the Russian state and other infamous ransomware groups, including …