GitLab Security Update – Patch For Multiple Vulnerabilities That Enables DoS Attack

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

GitLab has released important security updates. The new versions are 18.4.2, 18.3.4, and 18.2.8 for both Community Edition (CE) and Enterprise Edition (EE). These updates fix several vulnerabilities that could …

IRGC-Linked APT35 Structure, Tools, and Espionage Operations Disclosed

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Since emerging in the mid-2010s as a persistent threat actor, the IRGC-linked APT35 collective has continually adapted its tactics to target government entities, energy firms, and diplomatic missions across the …

Hackers Abuse CSS Properties With Messages to Inject Malicious Codes in Hidden Text Salting Attack

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated technique known as hidden text salting has emerged as a significant threat to email security systems, allowing cybercriminals to bypass detection mechanisms through the strategic abuse of cascading …

Microsoft 365 Outage Blocks Access to Teams, Exchange Online, and Admin Center – Updated

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A significant Microsoft 365 outage blocked user access to several critical services, including Microsoft Teams, Exchange Online, and the Microsoft 365 admin center. The incident began late on Wednesday, October …

Discord Data Breach – 1.5 TB of Data and 2 Million Government ID Photos Extorted

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The popular communication platform Discord is facing an extortion attempt following a significant data breach at one of its third-party customer service providers, Zendesk. Threat actors claim to have stolen …

CrowdStrike Falcon Windows Sensor Vulnerability Enables Code Execution and File Deletion

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

CrowdStrike has disclosed and released patches for two medium-severity vulnerabilities in its Falcon sensor for Windows that could allow an attacker to delete arbitrary files. The security vulnerabilities, designated as …

FreePBX SQL Injection Vulnerability Exploited to Modify The Database

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical SQL injection vulnerability in FreePBX has emerged as a significant threat to VoIP infrastructure worldwide, enabling attackers to manipulate database contents and achieve arbitrary code execution. FreePBX, a …

Crimson Collective Leverages AWS Services to Exfiltrate Sensitive Data

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A new threat group calling itself Crimson Collective has emerged as a significant cybersecurity concern, targeting Amazon Web Services (AWS) cloud environments with sophisticated data exfiltration and extortion campaigns. The …

Hackers Actively Compromising Databases Using Legitimate Commands

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated new breed of ransomware attacks is leveraging legitimate database commands to compromise organizations worldwide, bypassing traditional security measures through “malware-less” operations. Unlike conventional ransomware that encrypts files using …

Scattered Lapsus$ Hunters Launched a New Leak Site to Release Data Stolen from Salesforce Instances

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The notorious cybercriminal collective known as Scattered Lapsus$ Hunters has escalated their extortion campaign by launching a dedicated leak site to threaten organizations with the exposure of stolen Salesforce data. …