VLC Media Player Vulnerabilities Allow Remote Code Execution

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

VideoLAN, the organization behind the popular VLC Media Player, has disclosed multiple critical vulnerabilities that could allow attackers to execute arbitrary code remotely. These vulnerabilities affect both the desktop and iOS versions of the software. The security advisories, identified as …

ComfyUI Users Targeted by Malicious Code Designed to Steal Login Credentials

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The research team has recently reported a concerning incident involving the popular Stable Diffusion user interface, ComfyUI. This event has sent shockwaves through the AI community, highlighting the potential dangers lurking behind seemingly innocuous tools. While ComfyUI itself remains secure, …

Chinese Hackers Compromised 20K FortiGate Systems worldwide

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

At the beginning of 2024, there were reports of Chinese threat actors targeting FortiGate systems with COATHANGER malware. However, it has been discovered that the Chinese cyber espionage campaign had much more extensive capabilities than before.  The Military Intelligence and …

Critical Microsoft Outlook Zero-Click RCE Flaw Executes as Email is Opened

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical zero-click remote code execution (RCE) vulnerability has been discovered in Microsoft Outlook. This vulnerability, designated as CVE-2024-30103, enables attackers to run arbitrary code by sending a specially designed email. When the recipient opens the email, the exploit is …

Researchers Detailed ValleyRAT Password Stealing Techniques

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Hackers use RATs to get unauthorized access and full control of the victim’s computer and all its functionalities and enable other malicious abilities. They allow the threat actors to control the system and obtain useful information for their goals. Zscaler …

Canada & U.K. To Launch Investigation over 23andMe Hack

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Privacy regulators in Canada and the United Kingdom have initiated a collaborative inquiry into the genetic testing firm 23andMe in response to a major data breach, marking a significant step toward addressing the issue. The sensitive personal information of almost …

Popular Biometric Terminal Vulnerable To QR Code SQL Injection

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A popular hybrid biometric terminal manufactured by ZKTeco has been found to have several critical vulnerabilities, including a significant flaw that allows for SQL injection via QR codes. This discovery raises serious concerns about the security of biometric access control …

APT Hackers Abusing Google & OneDrive To Host Malicious Scripts

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Threat actors are leveraging cloud storage services like Google Drive, OneDrive, and Dropbox to distribute malware and steal user information by uploading malicious files such as scripts, RAT (Remote Access Trojan) malware, and decoy documents, which can download additional malware …

UNC5537 Hackers Hijacking Snowflake Customer Instances

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Threat actors penetrate the networks with the aim of obtaining unauthorized access to personal and corporate details, bank accounts, and organizational resources for purposes of identity theft, fraud, and data theft. They can masquerade as legit users to gain access …

Hackers Using OTP bots To Bypass Two-Factor Authentication

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Two-factor authentication (2FA) is a security method that requires two verification steps for user access and is commonly implemented with one-time passwords (OTPs) delivered via various channels.  To bypass 2FA, attackers leverage social engineering to trick users into revealing OTPs …