Google Chrome Enhances Security to Block Malicious Downloads

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Google has recently unveiled significant updates to Chrome’s download protection features, aiming to provide users with enhanced security against potentially harmful files. These changes come as part of Google’s ongoing efforts to combat the rising tide of online threats and …

6600+ Vulnerable GeoServer instances Exposed to the Internet

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Security analysts have identified 6,635 GeoServer instances exposed to the Internet, which makes them vulnerable to critical remote code execution (RCE) attacks. A recent tweet from the Shadowserver Foundation stated that the vulnerability, tracked as CVE-2024-36401, affects GeoServer versions before …

Microsoft’s Windows Hello for Business Flaw Let Attackers Bypass Authentication

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A recently discovered vulnerability in Microsoft’s Windows Hello for Business (WHfB) authentication system allowed attackers to bypass the supposedly phishing-resistant login method, raising concerns about the security of this widely adopted passwordless solution. This flaw allows attackers to bypass the …

DDoS Attack Lasted for 6 Days, Record created for the duration of the Cyberattack

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A financial institution in the Middle East endured a record-breaking Distributed Denial of Service (DDoS) attack for six days. The attack, orchestrated by the hacktivist group SN_BLACKMETA, set a new benchmark for the duration and intensity of such cyberattacks. The …

Progress Telerik Report Server Flaw Let Attackers Execute Remote Code

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical security vulnerability has been discovered in the Progress® Telerik® Report Server, potentially allowing attackers to execute remote code on affected systems. The flaw, identified as CVE-2024-6327, has been assigned a CVSS score of 9.9 out of 10, indicating …

GitLab Patch XSS Vulnerability that Lets Attackers to Execute Arbitrary Code

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

GitLab has released new Community Edition (CE) and Enterprise Edition (EE) versions to address multiple vulnerabilities. Among these, a high-severity cross-site scripting (XSS) vulnerability has garnered particular attention due to its potential to allow attackers to execute arbitrary code. Summary …

BIND DNS Vulnerability Lets Attackers Flood Server With DNS Messages

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The Internet Systems Consortium (ISC) has released critical security advisories addressing multiple vulnerabilities in the Berkeley Internet Name Domain (BIND) 9 software, a cornerstone of the Domain Name System (DNS) infrastructure. These vulnerabilities, identified as CVE-2024-0760, CVE-2024-1737, CVE-2024-1975, and CVE-2024-4076, …

Darkgate Autoit Converter Bypasses Windows Defender & Most Antiviruses

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A new tool known as the Darkgate Autoit Converter Crypter has emerged on the dark web. This sophisticated malware is designed to bypass Windows Defender and most other antivirus programs, posing a significant threat to computer systems worldwide. A New …

Beware of New Krampus Loader That Getting Popular in Dark Web

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A new malware loader named “Krampus” has surfaced on the dark web, gaining rapid popularity among threat actors. The loader was announced on a dark web forum by a threat actor, as reported by MonThreat on their social media platform, …

Russian Malware Cuts Off Heaters In 600 Apartments During Zero Temperatures

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

FrostyGoop represents a significant advancement in industrial control systems (ICS) malware, being the ninth ICS-specific threat and the first to leverage Modbus TCP communications for directly impacting Operational Technology (OT).  When FrostyGoop uses Modbus for enumeration, unlike PIPEDREAM, which was …