Google Chrome Now Prevent Users From Cookie Steal Malware on Windows

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Google has introduced several measures to address this threat, including Safe Browsing download protection in Chrome, Device Bound Session Credentials, and account-based threat detection systems that alert users to the …

20,275 VMware ESXi Vulnerable Instances Exposed, Microsoft Warns of Massive Exploitation

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Microsoft has issued a significant security alert regarding a vulnerability in VMware ESXi hypervisors, which ransomware operators have actively exploited. According to the Shadowserver Foundation, the vulnerability, identified as CVE-2024-37085, …

Hackers Actively Exploiting GeoServer RCE Flaw, 6635 Servers Vulnerable

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical vulnerability in GeoServer, an open-source Java-based software server, has put thousands of servers at risk. The flaw, CVE-2024-36401, allows unauthenticated users to execute remote code, posing a significant …

Beware of Malicious Crypto Management App that Drains Your Wallet

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cryptocurrency scams are becoming increasingly sophisticated. This article delves into the intricacies of these scams, providing insights into how they operate and offering tips on how to protect your cryptocurrency …

Multiple SMTP Servers Vulnerable to Spoofing Attacks, Let Hackers Bypass Authentication

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A recent discovery has unveiled vulnerabilities in multiple hosted, outbound SMTP servers, allowing authenticated users and certain trusted networks to send emails with spoofed sender information. These vulnerabilities, CVE-2024-7208 and …

Beware! Tycoon 2FA Phish-kit Exploits Amazon SES to Steal User Credentials

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated phishing campaign with Tycoon 2FA Phish-kit has been identified, leveraging Amazon Simple Email Service (SES) and a series of high-profile redirects to steal user credentials. The attack chain, …

Critical OAuth Vulnerability Exposes 1 Million Sites to XSS Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Security researchers have uncovered a critical vulnerability affecting over one million websites. The vulnerability combines OAuth implementation flaws with cross-site scripting (XSS) attacks. The vulnerability stems from the interaction between …