Windows Zero-day Flaw Let Hackers Downgrade Fully Updated Systems to Old Vulnerabilities

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Every software and operating system vendor has been implementing security measures to protect their products. This is because threat actors require a lot of time to find a zero-day but …

Hackers Leveraging OneDrive & Google Drive To Hide Malicious Traffic

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Attackers, including nation-state actors, increasingly leverage legitimate cloud services for espionage operations, exploiting their low-profile and cost-effective nature.  The services, such as Microsoft OneDrive and Google Drive, evade detection by …

1Password Vulnerability Let Attackers Exfiltrate Vault Items

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical vulnerability, designated as CVE-2024-42219, has been identified in 1Password 8 for Mac. This flaw allows malicious actors to exfiltrate vault items by bypassing the app’s platform security protections. …

RHADAMANTHYS Stealer Weaponizing RAR Archive To Steal Login Credentials

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A newly surfaced cybercampaign targeting Israeli users has thrust the sophisticated RHADAMANTHYS information stealer into the spotlight. Originating from Russian-speaking cybercriminals and offered as a Malware-as-a-Service, RHADAMANTHYS excels at data …

Apache Cloudstack Vulnerability Exposes API & Secret Keys to Admin Accounts

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The Apache CloudStack project has announced the release of long-term support (LTS) security updates, versions 4.18.2.3 and 4.19.1.1, which address two critical vulnerabilities, CVE-2024-42062 and CVE-2024-42222. These vulnerabilities pose significant …

Firefox Patches Multiple High Severity Vulnerabilities

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Mozilla has released Firefox 129, addressing multiple high-severity vulnerabilities. These patches are critical for enhancing the browser’s security and protecting users from potential exploits. Detailed Vulnerability Table The latest Firefox …

Critical Kibana Vulnerability Let Attackers Execute Arbitrary Code

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Kibana, a popular open-source data visualization and exploration tool, has identified a critical security flaw that could allow attackers to execute arbitrary code. This vulnerability, tracked as CVE-2024-37287, has a …