Tag-100 Hacker Group Exploiting Citrix NetScaler & F5 BIG-IP Vulnerabilities

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A new threat actor, TAG-100, has emerged and is actively targeting government and private sector organizations worldwide and initiates its attacks by exploiting vulnerabilities in internet-facing devices, such as Citrix NetScaler and F5 BIG-IP, to gain initial access to victim …

Critical Docker Vulnerability Lets Hacker Bypass Authentication

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical security vulnerability in Docker Engine has been discovered, potentially allowing attackers to bypass authentication and gain unauthorized access to systems. The vulnerability, identified as CVE-2024-41110, affects multiple versions of Docker Engine and has been assigned a CVSS score …

ERP Provider Exposes 769 Million Records, Including API Keys And Email Addresses

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A massive data breach involving ClickBalance, one of Mexico’s largest Enterprise Resource Planning (ERP) technology providers, has been uncovered by cybersecurity researcher Jeremiah Fowler. The breach exposed a staggering 769,333,246 records, totaling 395 GB of data, in a non-password-protected database. …

Stargazers Ghost: Network of GitHub Accounts Used to Deliver Malware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cybersecurity researchers at Check Point have uncovered a sophisticated network of GitHub accounts, dubbed the Stargazers Ghost Network, that has been distributing malware and phishing links since at least June 2023. This network, operated by a threat actor known as …

Google Chrome 127 Released With Fix for Vulnerabilities that Lead to Browser Crash

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Google has announced the release of Chrome 127, which is now available on the Stable channel for Windows, Mac, and Linux. The new version, 127.0.6533.72/73 for Windows and Mac and 127.0.6533.72 for Linux, will be rolled out over the coming …

New Windows False File Immutability Vulnerability Let Attackers Execute Arbitrary Code

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A new unnamed vulnerability class has been detected in the Windows 11 Kernel that could allow a threat actor to execute arbitrary code with Kernel privileges.  This vulnerability, named “File Immutability,” exists due to incorrect assumptions in the design of …

CrowdStrike Details Incident Affected Millions of Windows Systems Worldwide

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

In a recent preliminary Post-Incident Review (PIR), cybersecurity firm CrowdStrike provided a detailed account of the events that led to a massive global IT outage on July 19, 2024. The incident affected millions of Windows systems worldwide and was traced …

LiteSpeed Cache Plugin Flaw Let Attackers Inject Malicious Code, 5M+ Sites Impacted

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The popular LiteSpeed Cache plugin for WordPress has been found vulnerable to a Cross-Site Request Forgery (CSRF) attack, which could potentially impact over 5 million websites. The flaw, identified as CVE-2024-3246, was publicly disclosed on July 23, 2024, and has …

KnowBe4 Hired Fake North Korean IT Worker, Catches While Installing Malware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Security awareness and training provider KnowBe4 recently disclosed that it inadvertently hired a fake North Korean IT worker who attempted to install malware on a company-issued computer. The incident highlights the growing sophistication of cybercriminals and the challenges organizations face …

Pentagon IT Service Provider Hacked: U.S. Government Secrets Exposed

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Leidos Holdings Inc., one of the largest IT services providers to the U.S. government, experienced a significant cybersecurity breach. Hackers leaked internal documents, raising concerns about the security of sensitive government data managed by third-party contractors. Leidos, known for its …