Hackers Use Windows XSS Flaw To Execute Arbitrary Command In MMC Console

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The shift in attack vectors includes JavaScript, MSI files, LNK objects, and ISOs, as Microsoft has disabled Office macros in documents downloaded from the Internet. Some sophisticated attackers are now using other undisclosed methods to go unnoticed. The Elastic team …

PoC Released for D-LINK Information Disclosure that Leaks Passwords

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A Proof of Concept (PoC) has been released for a critical information disclosure vulnerability in D-LINK routers. This flaw, which has been identified as a major security risk, allows unauthorized access to sensitive information, including passwords. The vulnerability was highlighted …

New Zip Slip vulnerability Let Attackers Execute Arbitrary Code Via Path Traversal

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A Zip Slip vulnerability was discovered in Artifactory, the leading software repository manager, allowing attackers to execute arbitrary code through path traversal attacks. JFrog’s Artifactory is a software repository manager that leads the market. It offers a unified solution for …

Julian Assange Freed: WikiLeaks Founder Released in Stunning Deal with U.S.

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

London, June 25, 2024—In a dramatic and unexpected turn of events, WikiLeaks founder Julian Assange has been released from prison after reaching a deal with the U.S. government. The agreement, announced early today, ends the long-standing legal battle between Assange …

LockBit Claims Massive Breach of the United States Federal Reserve System

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The notorious ransomware group LockBit has claimed to have breached the United States Federal Reserve systems, allegedly exfiltrating 33 terabytes of sensitive banking data. The group announced this purported attack on their dark web leak site on June 23, 2024, …

Google Claims That Only 1% of Installs From Chrome Store Has Malware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

In 2024, Google reported that less than 1% of Chrome Web Store installations contained malware.  Extensions are small software programs that enhance your browser experience. They let users customize the behavior and functionality of Chrome to suit their own requirements …

Levi’s Data Breach: 72,000+ Customers’ Data Exposed

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Levi Strauss & Co., a renowned American clothing company, has disclosed a significant data breach affecting over 72,000 customers. The breach occurred on June 13, 2024, and was discovered on the same day. The compromised data includes personal identifiers such …

Apple Vision Pro Flaw Let Attackers Fill Your Room with Hundreds of Spiders

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cybersecurity experts have discovered a critical flaw in Apple’s latest augmented reality (AR) headset, the Apple Vision Pro. This vulnerability allows malicious actors to exploit the device and project hundreds of virtual spiders into the user’s environment, causing panic and …

New Android Rafel RAT Takes Complete Control Of Your Android Device

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Android has many features and access to apps but is prone to security risks due to its open-source nature. Android malware, viruses, Trojans, ransomware, spyware, and adware programs threaten the data privacy and integrity of users. These threats exploit different …

ESET Security Products for Windows Vulnerable to Privilege Escalation

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

ESET, a leading cybersecurity company, recently addressed a local privilege escalation vulnerability in its Windows security products. The Zero Day Initiative (ZDI) reported the vulnerability to ESET. It could have allowed attackers to misuse ESET’s file operations during a restore …