Cisco NX-OS Zero-Day Command Injection Flaw Under Active Attack

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical vulnerability in the Command Line Interface (CLI) of Cisco NX-OS Software is currently under active exploitation, allowing attackers to execute arbitrary commands as root on affected devices. This zero-day flaw, identified as CVE-2024-20399, poses a significant threat to …

Openssh Critical Flaw Exposes Millions of Linux Servers to Arbitrary Code Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical vulnerability has been discovered in OpenSSH, a widely used implementation of the SSH protocol, which could potentially expose millions of Linux systems to arbitrary code execution attacks. The flaw, identified in the sshd(8) component of OpenSSH, affects versions …

Man Charged for Creating ‘evil twin’ Free Wi-Fi Networks on a Flight

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A 42-year-old West Australian man is set to appear in Perth Magistrates Court today, facing nine charges for alleged cybercrime offences. The Australian Federal Police (AFP) has accused the man of establishing fake free WiFi access points, mimicking legitimate networks …

Toshiba Multi-Function Printers Impacted by 40+ Vulnerabilities

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Home Cyber Security News Toshiba Multi-Function Printers Impacted by 40+ Vulnerabilities Toshiba Multi-Function Printers Impacted by 40+ Vulnerabilities By Eswar – July 1, 2024 Several new vulnerabilities have been discovered in Toshiba e-STUDIO Multi-Function Printers (MFPs) that are used by …

New Skimmer Malware Attacking E-commerce WebSites To Steal Credit Card Data

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Researchers identified a new variant of credit card skimming attack, the Caesar Cipher Skimmer, targeting multiple content management systems (CMS), including WordPress, Magento, and OpenCart.  The skimmer specifically targets the checkout process, injecting malicious code into the checkout PHP file, …

30 Best Cyber Security Search Engines In 2024

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

In the 21st century, it has become crucial for every user, including IT security professionals, to access search engines, as they have become essential tools.  Currently, Google and Bing are among the most used search engines. Users can use these …

PoC Exploit Published for Linux Kernel Privilege Escalation Flaw

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical use-after-free vulnerability has been discovered in the Linux kernel’s netfilter subsystem. This vulnerability could potentially allow local, unprivileged users with CAP_NET_ADMIN capability to escalate their privileges. The flaw, identified in the upstream commit 5f68718b34a5 (“netfilter: nf_tables: GC transaction …

Water Sigbin Hackers Exploit Oracle WebLogic Vulnerabilities

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cybersecurity researchers uncovered a sophisticated attack campaign by the Water Sigbin (aka 8220 Gang) threat actor that exploited vulnerabilities in the Oracle WebLogic Server, notably CVE-2017-3506 and CVE-2023-21839, to deploy the XMRig cryptocurrency miner on compromised systems. The attack begins …

Google Chrome to Block Entrust SSL Certificates Starting November 2024

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Google has announced that its Chrome browser will stop trusting TLS server authentication certificates issued by Entrust and AffirmTrust starting November 1, 2024. This decision follows Entrust’s series of compliance failures and unmet improvement commitments, which have eroded Google’s confidence …

Hackers Created 250 npm Packages, Mimicking Popular AWS And Microsoft Projects

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Hackers target and abuse npm packages to inject malicious code into widely used software libraries, reaching many developers and applications. Sonatype security researchers recently identified more than 250 npm packages that mimic popular AWS, Microsoft, and other open-source projects. A …