Microsoft Copilot Studio Vulnerability Exploited to Access Sensitive Information

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Microsoft has patched a critical vulnerability in its Copilot Studio tool that allowed researchers to access sensitive internal cloud data and services. The flaw tracked as CVE-2024-38206, was discovered by cybersecurity firm Tenable and has been described as a server-side …

Man Sentenced for Altering Registry Systems to Fake His Death

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Jesse Kipf, a 39-year-old resident of Somerset, Kentucky, has been sentenced to 81 months in federal prison. U.S. District Judge Robert Wier handed down the sentence, citing Kipf’s involvement in computer fraud and aggravated identity theft. This unusual case has …

SolarWinds Web Help Desk RCE Vulnerability Allows Remote Exploitation – Hotfix Released

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

SolarWinds has released a critical hotfix addressing multiple vulnerabilities in its Web Help Desk (WHD) software. This update is crucial for all users to ensure the security and functionality of their systems. SolarWinds has issued a patch for a recently …

New iOS Bug Could Crash Your iPhone by Typing Four Characters

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A security researcher discovered a bug in iOS on Wednesday that can cause iPhones and iPads to briefly crash when a specific sequence of four characters is typed into certain search bars. The bug affects the Apple mobile user interface …

Halliburton Hit by Cyberattack, Operations Disrupted

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Halliburton, a leading oilfield services company, is currently grappling with a significant cyberattack that has disrupted operations at its Houston campus and affected some of its global networks. A person familiar with the situation first reported the incident to Reuters, …

Chrome Zero-day Vulnerability (CVE-2024-7971) Actively Exploited in The Wild

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Google has recently addressed a high-severity zero-day vulnerability in its Chrome browser, identified as CVE-2024-7971. This vulnerability involves a type of confusion issue within the V8 JavaScript engine, which can be exploited to execute arbitrary code. The flaw was reported …

Tycoon 2FA Phishing Kit: What You Need to Know about the Highly Active Threat

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

If your company is using Microsoft products, you are at risk of falling victim to a Tycoon 2FA phishing attack. The adoption of this phishing kit in attacks is steadily increasing with new campaigns emerging almost every week. Let’s learn …

Xeon Sender Abusing Nine SaaS providers For Massive SMS Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Xeon Sender, a Python script, is a tool that enables threat actors to send spam messages through nine different SaaS providers. Initially observed in 2022, various threat actors have reused and rebranded this tool in the cloud hacktool scene.  By …

Chipmaker Microchip Hit by Cyber Attack, Operations Impacted

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Microchip Technology Incorporated, a leading semiconductor manufacturer, has been hit by a significant cyber attack that has disrupted its operations. The company, which supplies chips to the U.S. defense industry, detected suspicious activity on its information technology systems on August …

AWS Configuration Vulnerability Exposes Thousands of Web Apps to Attack

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A recent discovery by Miggo Research has unveiled a critical configuration vulnerability in Amazon Web Services (AWS) that exposes thousands of web applications to potential attacks. This vulnerability, dubbed “ALBeast,” affects applications using AWS’s Application Load Balancer (ALB) authentication feature, …