PoC Exploit Released for High Severity Apache HugeGraph RCE flaw

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A proof-of-concept (PoC) exploit has been released for a high-severity Remote Code Execution (RCE) vulnerability in the Apache HugeGraph Server. This vulnerability, identified as CVE-2024-27348, affects versions of HugeGraph Server before 1.3.0 and has been assigned a CVSS score of …

Microsoft to Disable NTLM, Transition to Kerberos Authentication

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Microsoft has made an announcement regarding the gradual phasing out of all versions of NTLM (NT LAN Manager). This decision is part of Microsoft’s ongoing efforts to harden Windows against various security threats and vulnerabilities. The announcement for deprecated features …

Cisco Finesse Vulnerabilities Let Attackers Perform Stored XSS Attack

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cisco has issued a security advisory detailing multiple vulnerabilities in Cisco Finesse’s web-based management interface. These vulnerabilities, identified as CVE-2024-20404 and CVE-2024-20405, could allow unauthenticated, remote attackers to perform a stored cross-site scripting (XSS) attack. The vulnerabilities in question involve …

Chrome Introduced Shared Memory Versioning to Enhance Browser Performance

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Google Chrome recently implemented Shared Memory Versioning, improving its speed through more effective cookie handling. This upgrade improves Chrome and other Chromium-powered browsers like Microsoft Edge and Vivaldi. Resource contention arises as more people rely on the Internet to do …

50 World’s Best Cyber Security Companies – 2024

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cybersecurity has become a critical issue for individuals and organizations alike as the world increasingly relies on digital technologies to conduct business and store sensitive information Cyber threats are constantly evolving, and as a result, there is a need for …

Top 10 Best Governance, Risk & Compliance (GRC) Tools in 2024

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Governance, Risk, and Compliance (GRC) tools are essential software solutions designed to help organizations manage their governance, risk management, and compliance processes in an integrated and systematic manner. These tools provide a framework that allows businesses to align their strategies, …

Commando Cat Attacking Docker remote API servers to Deploy Crypto Miners

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A campaign dubbed “Commando Cat” has been observed exploiting exposed Docker remote API servers to deploy cryptocurrency miners. This campaign, active since the beginning of 2024, initiates its attacks using the publicly available Commando project. The attackers use the cmd.cat/chattr …

Kiosk Mode Bypass Flaw On Hotel Check-in Terminal Leaks Guests Personal Data

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A new vulnerability has been discovered in Ariane Allegro  Scenario Player in a Kiosk mode that could allow threat actors to bypass the Kiosk mode and access the underlying Windows Desktop. The CVE for this vulnerability is yet to be …

RansomHub Raas Emerges As The Most Largest Ransomware Group Operating

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The lucrative business model and the simplicity of running Ransomware-as-a-Service (RaaS) are driving rapid evolution and adoption. Threat actors go for RaaS as it eliminates technical barriers to entry, instead serving up ready-made ransomware tools and infrastructure. This has brought …

Hackers Exploiting MS-SQL Servers To Attack Windows Server

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

MS-SQL Servers contain a multitude of sensitive information, which is why hackers often target them, enabling them to access critically important systems. Exploiting these servers’ vulnerabilities allows threat actors to gain unauthorized access. These actors can execute unauthorized commands and …