Poisoned Google Ads Targeting Infra Teams with Weaponized IP Scanners

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Security researchers uncovered a sophisticated malvertising campaign targeting IT professionals, particularly those in security and network administration roles. The threat actor behind this attack has been leveraging Google Ads to distribute trojanized versions of popular IP scanning and IT management …

Xiid SealedTunnel: Unfazed by Yet Another Critical Firewall Vulnerability (CVE-2024-3400)

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

In the wake of the recent disclosure of a critical vulnerability (CVE-2024-3400) affecting a leading firewall solution, Xiid Corporation reminds organizations that Xiid SealedTunnel customers remain secure. This latest vulnerability, currently unpatched and rated 10/10 on the CVSS (Common Vulnerability …

5 Sandbox Tools for Phishing Analysis in 2024

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

There is a wide variety of solutions one can use to investigate phishing attacks. Yet, in most cases, analysts can do with just one, a malware analysis sandbox. Thanks to its combination of static and dynamic capabilities, a sandbox is …

Tor Browser 13.0 Released: What’s New

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Tor Browser 13.0.14 has been released, bringing essential security updates to the popular privacy-focused web browser. This latest version includes updates to the underlying Firefox browser and several bug fixes and improvements. Critical Updates in Tor Browser 13.0.14 Updated Tor …

“Mobile NotPetya”!! Surge in Zero-click Vulnerabilities, Conditions Favour

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The cybersecurity community is sounding the alarm about the growing risk of a “mobile NotPetya” event – a self-propagating mobile malware outbreak that could have devastating consequences. Over the past year, the alarming increase in the discovery and exploitation of …

Hackers Attempted To Takeover JavaScript Project From OpenJS Foundation

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Attackers tried to take over the JavaScript project from OpenJS Foundation, which is home to JavaScript projects utilized by billions of websites globally.  This is similar to the incident that was recently disclosed and targeted at the open-source XZ Utils tracked …

Data Center Ransomware Attacks on Rise: Microsoft SQL Server Prime Target

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Ransomware threats are increasingly targeting data center servers and workloads as the initial step in the attack chain. These systems may not be up-to-date with recommended patches, often run legacy applications without vendor security updates, or may not be scheduled …

Alert! Oracle Releases Critical Patch Update 2024 – 372 Vulnerabilities are Fixed

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Oracle has released its Critical Patch Update (CPU) for April 2024, addressing 372 vulnerabilities across multiple products. The Critical Patch Update provides fixes for security flaws in widely-used Oracle products including Database Server, Fusion Middleware, Enterprise Manager, E-Business Suite, Supply …

Hackers Exploiting TP-Link Archer Command Injection Vulnerability in the Wild

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cybersecurity researchers have uncovered widespread exploitation of a critical vulnerability in TP-Link Archer routers, which has led to the proliferation of botnet threats. The vulnerability, CVE-2023-1389, allows attackers to execute arbitrary commands on affected devices, potentially granting them access to …

Critical PHP Vulnerabilities Let Attackers Inject Commands : Patch Now

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Multiple vulnerabilities have been identified in PHP that are associated with Command Injection, Cookie Bypass, Account takeover, and Denial of Service. The CVEs for these vulnerabilities have been given as CVE-2024-1874, CVE-2024-2756, CVE-2024-3096, and CVE-2024-2757. The severity of these vulnerabilities …