0.0.0.0 Day – 18 Yr Old Vulnerability Let Attackers Bypass All Browser Security

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Researchers at Oligo Security have discovered an 18-year-old critical vulnerability, dubbed “0.0.0.0 Day,” that affects all major web browsers, including Chromium, Firefox, and Safari. This vulnerability allows malicious websites to bypass browser security and interact with services running on an …

Cisco Small Business IP Phones Vulnerabilities: Attackers Can Execute Arbitrary Commands

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cisco has disclosed multiple critical vulnerabilities affecting its Small Business SPA300 and SPA500 Series IP Phones, potentially allowing attackers to execute arbitrary commands with root privileges or cause denial of service conditions. The flaws, which have been assigned CVE identifiers …

Vulnerabilities in Jenkins Let Hackers Execute Arbitrary Code Remotely

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A pair of security vulnerabilities have been discovered in Jenkins, a popular open-source automation server, that could allow attackers to read arbitrary files from the Jenkins controller file system and potentially lead to remote code execution (RCE). Jenkins is a …

GhostWrite Vulnerability Let Hackers Read & Write Any Part of The Computer’s Memory

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A group of cybersecurity researchers at CISPA Helmholtz Center for Information Security recently identified three major security vulnerabilities in five commercial RISC-V CPUs, including GhostWrite, which allows an attacker to write arbitrary data from unprivileged states into any physical memory …

Windows Zero-day Flaw Let Hackers Downgrade Fully Updated Systems to Old Vulnerabilities

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Every software and operating system vendor has been implementing security measures to protect their products. This is because threat actors require a lot of time to find a zero-day but less time to find a readily available exploit for vulnerable …

National Public Data Hacked: 2.9 Billion Users Personal Data Stolen

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

In one of the largest data breaches in history, the personal information of nearly 3 billion individuals has been stolen from National Public Data, a background check and fraud prevention service provider. The breach, which came to light through a …

Hackers Leveraging OneDrive & Google Drive To Hide Malicious Traffic

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Attackers, including nation-state actors, increasingly leverage legitimate cloud services for espionage operations, exploiting their low-profile and cost-effective nature.  The services, such as Microsoft OneDrive and Google Drive, evade detection by masquerading as trusted entities, thereby enabling covert data exfiltration and …

1Password Vulnerability Let Attackers Exfiltrate Vault Items

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical vulnerability, designated as CVE-2024-42219, has been identified in 1Password 8 for Mac. This flaw allows malicious actors to exfiltrate vault items by bypassing the app’s platform security protections. Robinhood’s Red Team responsibly disclosed the issue following an independent …

RHADAMANTHYS Stealer Weaponizing RAR Archive To Steal Login Credentials

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A newly surfaced cybercampaign targeting Israeli users has thrust the sophisticated RHADAMANTHYS information stealer into the spotlight. Originating from Russian-speaking cybercriminals and offered as a Malware-as-a-Service, RHADAMANTHYS excels at data exfiltration.  Recent samples and in-depth analysis reveal a complex infection …

Apache Cloudstack Vulnerability Exposes API & Secret Keys to Admin Accounts

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The Apache CloudStack project has announced the release of long-term support (LTS) security updates, versions 4.18.2.3 and 4.19.1.1, which address two critical vulnerabilities, CVE-2024-42062 and CVE-2024-42222. These vulnerabilities pose significant risks to the integrity, confidentiality, and availability of CloudStack-managed infrastructure. …