PoC Exploit Released for VMware vCenter Server RCE Vulnerability

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A proof-of-concept (PoC) exploit has been released for a critical vulnerability in the VMware vCenter Server, potentially allowing authenticated remote code execution. The vulnerability, identified as CVE-2024-22274, affects the vCenter Server’s API components and has been assigned a CVSSv3 base …

New OpenSSH Vulnerability CVE-2024-6409 Exposes Systems to RCE Attack

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Security researchers have discovered a new vulnerability in OpenSSH, identified as CVE-2024-6409, which could potentially allow remote code execution attacks on affected systems. This vulnerability, which affects OpenSSH versions 8.7 and 8.8, allows for potential remote code execution (RCE) due to a race condition …

Microsoft Bans Android Devices for China Employees, Mandates iPhones

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Microsoft employees in China will be required to use iPhones, as the company plans to block Android devices from accessing its corporate resources. This decision, as outlined in an internal memo obtained by Bloomberg News, is part of a broader …

Researchers Decrypted DoNex Ransomware And It’s Rebranded Versions

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Researchers discovered a flaw in the DoNex ransomware’s encryption scheme, allowing them to create a decryptor for DoNex and its predecessors (Muse, fake LockBit 3.0, DarkRace).  The decryptor has been secretly provided to victims since March 2024 in collaboration with …

1.4 GB of NSA Data Leaked – Phone Numbers, Email Addresss & More Classified Data Exposed Online

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Researchers from Cyber Press, who reported a massive Twitter data leak today, found another data leak online. This time, cybercriminals exposed a file with 1.4 GB of leaked data from the National Security Agency (NSA). The data, which includes sensitive and classified …

Kimsuky Hackers Attacking Organizations Using Weaponized EXE & DOCX Files

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Hackers often use EXE and DOCX file formats is due to they are among the most commonly used types of files that can be easily disguised as legitimate. EXE files can be used to deliver various forms of malware, such …

Information Stealing Malware Distributed as AT tools & Chrome Extensions

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The first half of 2024 has seen a significant rise in information-stealing malware disguised as AI tools and Chrome extensions. This trend highlights cyber criminals’ increasing sophistication and adaptability as they exploit emerging technologies and popular platforms to target unsuspecting …

Massive 9.4GB Twitter Data Leaked Online – 200 Million Records Exposed

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Researchers at Cyber Press discovered a 9.4GB leaked Twitter user data containing nearly 200 million user data records. This leak, sourced from a Twitter database or scrape, represents one of the largest exposures of user data in recent times. The …

Beware of Fake regreSSHion Exploit Attacking Security Researchers

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

An alarming new threat has emerged targeting cybersecurity researchers. An archive containing malicious code is being distributed on the social network X, masquerading as an exploit for the recently discovered CVE-2024-6387 vulnerability, also known as regreSSHion. This exploit, which affects …

Critical MongoDB Compass Code Injection Flaw Exposes Systems to Hacking

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical security vulnerability in MongoDB Compass, identified as CVE-2024-6376, has been discovered, potentially exposing systems to code injection attacks. The flaw, which affects versions of MongoDB Compass prior to 1.42.2, stems from insufficient sandbox protection settings in the ejson …