YubiKeys cryptographic Flaw Let Attackers Clone Devices by Extracting Private Key

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Security researchers have uncovered a significant vulnerability in YubiKeys, specifically targeting the YubiKey 5 Series. This vulnerability, identified as a side-channel attack, allows attackers to clone these devices by extracting the secret keys stored within them. The attack exploits a …

D-Link Declines to Patch RCE Vulnerabilities That Affected End-of-Life Routers

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A significant security vulnerability has been reported in the DAP-2310, specifically affecting Hardware Revision A with Firmware version 1.16RC028. Hahna Latonick of Dark Wolf Solutions identified the vulnerability, which has been named “BouncyPufferfish.” It exploits a stack-based buffer overflow in …

North Korean Hackers Actively Exploiting Chromium RCE Zero-Day In The Wild

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Chromium is the foundation for many popular web browsers including Google Chrome and Microsoft Edge, and this is the most lucrative thing that attracts the hackers most. Cybersecurity analysts at Microsoft recently discovered that North Korean hackers have been actively …

Bonjour Network Service Vulnerable to Privilege Escalation Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical vulnerability has been identified in the Bonjour service, specifically in the mDNSResponder.exe process, which is used for network discovery across local area networks. This vulnerability affects both macOS and Windows systems, potentially allowing attackers to escalate privileges within …

Website Operators Arrested for Running an MFA Bypass Site

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Three men have pleaded guilty to operating a website that enabled criminals to bypass banking anti-fraud checks, leading to significant financial losses for unsuspecting victims. The website, www.OTP.Agency, was run by Callum Picari, 22, from Hornchurch, Essex; Vijayasidhurshan Vijayanathan, 21, from …

Arbitrary Code Execution Vulnerabilities Affecting WPS Office – Technical Analysis

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

WPS Office, a popular office suite with over 500 million active users worldwide, has recently found critical vulnerabilities that allow arbitrary code execution. These vulnerabilities, identified as CVE-2024-7262 and CVE-2024-7263, were discovered by ESET researchers during an investigation into the …

What is Access Management?

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Access management is an essential aspect of an organization’s security infrastructure, designed to protect and manage access to information and resources. Its primary objective is to ensure that only authorized individuals can access specific data, applications, or systems. This article …

Hacking Poisoning GlobalProtect VPN To Deliver WikiLoader Malware On Windows

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Hackers often target VPNs for several illicit purposes like injecting malicious code, stealing sensitive data, and many more. Besides this, compromising a VPN enables hackers to gain unauthorized access to private networks and monitor user activity without getting detected. Cybersecurity …

Google Chrome Vulnerability Allow Attackers To Execute Arbitrary Code Remotely

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Google has released updates for the Chrome Stable and Extended Stable channels. The new version, 128.0.6613, is now available for Windows, Mac, and Linux users, with a staggered rollout planned over the coming days and weeks. This update addresses four …

VMware Fusion Vulnerability Let Attackers Execute Malicious Code

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

VMware has issued a security advisory to address a significant vulnerability in its VMware Fusion product that could allow attackers to execute malicious code. This vulnerability, identified as CVE-2024-38811, stems from the application’s use of an insecure environment variable. With …