SonicWall Warns of Access Control Vulnerability Exploited in the Wild

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

SonicWall has issued an urgent security advisory regarding a critical vulnerability (CVE-2024-40766) affecting its firewall products. The company warns that this improper access control flaw is potentially being exploited in the wild, prompting immediate action from users. The vulnerability, with …

Linux Pluggable Authentication Modules Abused to Create Backdoors

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The Group-IB Digital Forensics and Incident Response (DFIR) team has uncovered a novel technique that exploits Linux’s Pluggable Authentication Modules (PAM) to create persistent backdoors on compromised systems. This technique not yet included in the MITRE ATT&CK framework, involves the …

Critical Progress LoadMaster Vulnerability Let Attackers Execute Arbitrary Code

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical vulnerability has been identified in the LoadMaster product line, including all LoadMaster releases and the LoadMaster Multi-Tenant (MT) hypervisor. This vulnerability, which is cataloged as CVE-2024-7591, could allow unauthenticated, remote attackers to execute arbitrary code on affected systems. …

Researcher Details Exploitation of Exchange PowerShell via MultiValuedProperty

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

OffensiveCon 2024 devised multiple methods to exploit Microsoft Exchange. One method was using the MultiValuedProperty, through which a researcher was able to exploit Exchange PowerShell. Moreover, this exploit bypasses Microsoft’s patch for one of the vulnerabilities. Two vulnerabilities (CVE-2022-41040 and …

6 Hackers Charged for Hacking Ukrainian Government Networks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A grand jury in Maryland has charged six Russian nationals with conspiracy to engage in computer intrusion and wire fraud. The indictment, unsealed today, accuses these individuals of orchestrating a series of cyberattacks targeting Ukrainian government networks, exacerbating tensions amid …

PoC Exploit Released for Linux Kernel Vulnerability that Allows Root Access

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Google Released a Proof-of-Concept (PoC) for a critical security vulnerability, identified as CVE-2024-26581, which has been discovered in the Linux kernel and poses significant risks to systems worldwide. This vulnerability, reported by Google’s kCTF team, affects the netfilter component, specifically …

Electric vehicle (EV) Owners beware of Quishing Attacks via EV Chargers

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Electric vehicle (EV) owners, beware: quishing attack targeting charging stations is on the rise. This cyber threat combines QR codes with phishing tactics to deceive unsuspecting EV drivers and potentially steal their money or install malware on their devices. The …

How Modern Malware Exploits Discord and Telegram for Malicious Activities

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Although Discord and Telegram are some of the most popular communication channels today, they aren’t just used for chatting and messaging. It’s becoming increasingly common for cyber attackers to exploit these platforms as part of their malicious activities. These services, …

RAMBO Attack Steals Data From Air-gapped Systems

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Researchers explore the vulnerability of air-gapped networks to malicious attacks. Despite their physical isolation, these networks can be compromised through covert channels, such as electromagnetic emissions.  The attack model involves malware manipulating RAM to generate radio signals that can be …

What is Account Harvesting?

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

In today’s digital world, online security is a primary concern for individuals and businesses. One of the most significant threats is account harvesting, also known as credential or password harvesting. This illegal practice involves collecting sensitive information from unsuspecting victims, …