PoC Exploit Ivanti Endpoint Manager Remote Code Execution Vulnerability

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Ivanti Endpoint Manager, a widely used IT management software, has discovered a critical security vulnerability. CVE-2024-29847 vulnerability allows for remote code execution by deserializing untrusted data. This flaw poses a significant risk to organizations relying on Ivanti’s endpoint management and …

Critical Zero-Click Vulnerability in macOS Calendar Let Attackers Execute Malicious Code

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical zero-click vulnerability has been discovered in macOS Calendar, allowing attackers to add or delete arbitrary files within the Calendar sandbox environment and execute malicious code without any user interaction. The vulnerability, found by security researcher Mikko Kenttala in …

Google Cloud Platform RCE Flaw Let Attackers Execute Code on Millions of Google Servers

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Security researchers revealed this week that a critical remote code execution (RCE) vulnerability in Google Cloud Platform (GCP) could have allowed attackers to run malicious code on millions of Google’s servers. The flaw, dubbed “CloudImposer” by Tenable Research, has since …

Beware Of Weaponized Excel Document That Delivers Fileless Remcos RAT

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Remcos is a Remote Access Trojan (RAT) that allows attackers to gain unauthorized control over infected computers. This RAT has been weaponized and commonly used in cybercriminal activities since its introduction in 2016. Trellix researchers recently warned of weaponized Excel …

New Android Malware Ajina Attacks Users To Steal Banking Login Details

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Recent developments in Android malware have revealed a concerning trend where malicious applications are increasingly capable of stealing banking login details and intercepting two-factor authentication (2FA) messages.  This significant rise in sophisticated attacks poses great risks to the financial security …

Critical Vulnerabilities Impact Millions Of D-Link Routers: Patch Now!

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

In a significant security alert, millions of D-Link routers are at risk due to critical vulnerabilities that have been discovered in several models, including the DIR-X5460 and DIR-X4860. These vulnerabilities could allow remote attackers to execute arbitrary code, potentially compromising …

Windows MSHTML Zero-Day Vulnerability Exploited In The Wild

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The Windows MSHTML platform spoofing vulnerability, CVE-2024-43461, which affects all supported Windows versions, has been exploited in the wild. CVE-2024-43461 was used in attacks by the Void Banshee APT hacking group. Research from Trend Micro claims that Void Banshee lures …

Creating An AI Honeypot To Engage With Attackers Sophisticatedly

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

In cybersecurity, a honeypot is a bait system specifically designed to attract and analyze cyber-attacks, functioning as a trap for potential intruders.  By mimicking legitimate targets, honeypots divert threat actors from real assets while gathering intelligence on their methods and …

What is Security Auditing?

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

With the global cost of cybercrime reaching nearly $9.4 million in 2024, organizations are under immense pressure to protect their data and systems from potential breaches. Security auditing is one of the most effective ways to ensure the security of …

Threat Actor 888 Allegedly Claims Leak of SAP Employees Data

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A Twitter account known as DarkWebInformer has claimed that a notorious hacker, identified only by the alias “888,” has allegedly leaked sensitive data belonging to SAP employees. A member of BreachForums has claimed responsibility for leaking an employee database purportedly …