Apple Safari Zero-Day Flaw Exploited At Pwn2Own : Patch Now

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Apple has released security updates to address a zero-day vulnerability in its Safari web browser that was exploited during this year’s Pwn2Own Vancouver hacking competition.  This issue, identified as CVE-2024-27834, was fixed by enhanced checks on macOS Monterey and macOS …

Authorities Seized Notorious Data Leak Site BreachForums

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The notorious data leak site BreachForums has been taken over by the police. Cybercrime and data leaks are still being fought, but this is a big win. A Brief History of BreachForums As a replacement for the notorious RaidForums, BreachForums …

LogRhythm and Exabeam to Merge to Boost SIEM & SOAR

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

LogRhythm and Exabeam, two leading cybersecurity companies, announced today their intent to merge in a transformative deal that will create a powerful force in the security operations and analytics market. LogRhythm is a world-class cybersecurity company that delivers comprehensive security …

Critical SAP NetWeaver & CX Commerce Flaw Leads To Complete Takeover

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Three vulnerabilities associated with CSS injection, file upload, and remote code execution have been discovered in the SAP Customer Experience (CX) commerce cloud and SAP Netweaver Application. These two vulnerabilities have been assigned with CVE-2019-17495 and CVE-2022-36364.  The severity of …

Wireshark 4.2.5 Released: What’s New!

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The Wireshark team has announced the release of Wireshark 4.2.5, a maintenance update to the popular network protocol analyzer. This new version brings important security fixes and improvements to the widely-used tool. Wireshark is a well-known open-source network protocol analyzer …

Google Chrome Zero-day Vulnerability (CVE-2024-4947) Actively Exploited in The Wild

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Google has released an emergency security update for its Chrome web browser to patch a high-severity vulnerability that is being actively exploited by attackers in the wild. The zero-day flaw, tracked as CVE-2024-4947, is a type confusion bug in the …

5 Common Phishing Vectors and Examples – 2024

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Phishing attacks can be executed through various means, such as SMS and phone calls, but the most prevalent method involves sending victims emails containing malicious attachments. These may come in various forms, but they most often belong to one of …

New Wi-Fi ‘SSID Confusion’ Attack Let Attackers connecting To Malicious Network

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A design flaw in the IEEE 802.11 standard allows for SSID spoofing in WPA2 and WPA3 networks. While authentication protocols prevent unauthorized access points, they don’t guarantee that the SSID displayed on the client device matches the actual network’s SSID.  …

Turla APT Group Attacking European Ministry of Foreign Affairs

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The well-known advanced persistent threat (APT) group Turla, based in Russia, is said to be going after the European Ministry of Foreign Affairs. This new cyber espionage attempt shows how innovative and persistent Turla is. The group has been active …

Hackers Abusing to GitHub to Host Malicious Infrastructure

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cybersecurity experts from Recorded Future’s Insikt Group have uncovered a sophisticated cybercriminal campaign orchestrated by Russian-speaking threat actors from the Commonwealth of Independent States (CIS). These cybercriminals have been exploiting GitHub, a platform widely trusted by developers, to host malicious …