Github Paid $4,000,000 In Rewards For Bug Bounty Program

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

GitHub, the world’s leading software development platform, is celebrating a milestone: the 10th anniversary of its Security Bug Bounty program. Over the past decade, the program has not only enhanced the security of GitHub’s services but also rewarded security researchers …

Kulicke & Soffa Data Breach – 12 Million Files Leaked

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Kulicke and Soffa Industries, Inc. (K&S), a leading semiconductor packaging and electronic assembly solutions provider, has disclosed a data breach that has compromised approximately 12 million files. Initially detected on May 12, 2024, the breach raised concerns about the security …

Threat Actor Claiming of Israel’s Government API Database

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A threat actor has claimed responsibility for breaching Israel’s government API database. The announcement was made via a post on social media X by the darkwebinformer. The post, which has since garnered significant attention, alleges that sensitive data from the …

FortiOS Vulnerability Let Attackers to Execute Unauthorized Commands

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Fortinet has disclosed multiple stack-based buffer overflow vulnerabilities (CVE-2024-23110) in FortiOS’s command line interpreter. These vulnerabilities could allow authenticated attackers to execute unauthorized code or commands. Gwendal Guégniaud of the Fortinet Product Security team discovered and reported these vulnerabilities. Affected …

Authorities Arrest Encryption Specialist Behind Conti & LockBit Ransomware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Ukrainian cyber police have arrested a 28-year-old man from Kyiv, identified as a key figure in the development of cryptors used by the notorious Conti and LockBit ransomware groups. Authorities Arrested The arrest is part of an international law enforcement …

Tools for Conducting Malware Traffic Analysis in a Sandbox

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A malware sandbox is a versatile solution that offers a variety of tools for studying malicious behavior, including threats’ network traffic. A quick sandbox analysis can reveal tons of useful information, such as the malware’s communication with its command-and-control server …

Microsoft Security Update : RCE, Privilege Escalation Flaws Patched

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The June 2024 Patch Tuesday update from Microsoft addressed almost 49 vulnerabilities in its products and 9 vulnerabilities in non-Microsoft products.  The update includes a critical vulnerability in Microsoft Message Queuing (MSMQ) that allows remote code execution to be tracked …

Black Basta Actors Exploited Windows Zero-day Privilege Escalation Vulnerability

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The Cardinal cybercrime group (aka Storm-1811, UNC4393), which operates the Black Basta ransomware, may have been exploiting a recently patched Windows privilege escalation vulnerability as a zero-day. CVE-2024-26169: The Vulnerability The vulnerability (CVE-2024-26169) occurs in the Windows Error Reporting Service. …

Chrome 126 Released With Patch For 21 Security Flaws

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The Chrome team has released Chrome 126 to the Windows, Mac, and Linux stable channels. This update, which will roll out over the coming days and weeks, includes many fixes and improvements, focusing on security. Key Security Fixes Chrome 126 …

CISA Urges Administrators To Review Newly Released Six ICS Advisories

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The Cybersecurity and Infrastructure Security Agency (CISA) has issued a call to action for administrators and security professionals to review six newly released Industrial Control Systems (ICS) advisories. These advisories, released on June 11, 2024, provide critical information on current …