Critical zero-click RCE Vulnerability Impacts Microsoft Outlook Applications

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Morphisec researchers have discovered a critical zero-click remote code execution (RCE) vulnerability in Microsoft Outlook, designated CVE-2024-38021. Unlike the previously disclosed CVE-2024-30103, this vulnerability does not require authentication, making it particularly dangerous. This zero-click remote code execution (RCE) vulnerability poses …

PoC Exploit Released For Splunk Enterprise Local File Inclusion Vulnerability

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A proof-of-concept (PoC) exploit has been released for a critical local file inclusion vulnerability in Splunk Enterprise, identified as CVE-2024-36991. This vulnerability affects Splunk Enterprise versions below 9.2.2, 9.1.5, and 9.0.10, specifically on Windows systems. The vulnerability arises from a …

Fujitsu Cyber Attack: Customers’ Personal Information Exposed

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Fujitsu Limited has disclosed the results of an investigation into a cyberattack that potentially exposed customers’ personal information. The breach, first announced on March 15, 2024, was caused by sophisticated malware that infiltrated the company’s internal network in Japan. Fujitsu …

Exclusive! Analysis of 3 Ransomware Threats Active Right Now 

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Ransomware continues to loom large over the cybersecurity landscape, causing significant damage to individuals and organizations alike. With the difficulty of recovering encrypted files and the potential exposure of stolen data, it is essential to keep track of active ransomware …

Researcher Exploits Browser Rendering Process to Alter PDF Invoice Pricing

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A cybersecurity researcher, Zakhar Fedotkin, demonstrated how differences in PDF rendering across various browsers and operating systems can be exploited to manipulate the displayed pricing on PDF invoices. This vulnerability could significantly impact businesses relying on digital invoices for transactions. …

Massive Truecaller Data Leak Exposes 273 Million Indian Users’ Information

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A massive data leak involving Truecaller, the popular caller ID and spam-blocking app, has reportedly exposed the personal information of 273 million Indian users. The leak, which stems from a breach in February 2019, has recently resurfaced, raising significant privacy …

Windows Notepad Text Editor Gets Spell Check After 41 Years

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Microsoft has finally introduced spell check and autocorrect features to its venerable Notepad text editor, a staple of the Windows operating system for over four decades. This update significantly enhances the minimalist text editor, which has remained largely unchanged since …

WordPress Calendar Plugin RCE Flaw Exposes 150,000 Sites for Hacking

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A security flaw was discovered in the Modern Events Calendar, a widely used WordPress plugin with over 150,000 active installations. The vulnerability, identified as an Arbitrary File Upload flaw, allows authenticated users, such as subscribers, to upload arbitrary files to …

New CloudSorcerer APT Group Exploits Cloud Services And GitHub For C2 Servers

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The hackers take advantage of Cloud services and GitHub since they are highly popular and can give access to massive amounts of data. Since they contain intellectual property, sensitive information, and credentials that lucrates the hackers. Besides this, misconfigurations in …

Threat Actors Claiming Breach of Nokia Database

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Threat actors have claimed responsibility for a breach of Nokia’s database. The announcement was made via a tweet from the notorious hacker group H4ckManac, known for their previous cyber exploits. The tweet, 2024, reads: “We have successfully breached Nokia’s database. …