Apache HTTP Server Flaw Let Attackers Inject Malicious Headers Amd HTTP/2 DoS

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Apache released updates to address several vulnerabilities impacting the Apache HTTP server that let attackers launch HTTP/2 DoS attacks and insert malicious headers. Server operations are being adversely affected by these …

Cyber Attack Hits World’s Second Largest Lens-maker

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

HOYA CORPORATION, the world’s second-largest lens manufacturer, has reported an IT system incident that has disrupted its operations. The Tokyo-based company, known for its advanced optics technology and a broad …

Google Pixel Phone Zero-days Exploited by Forensic Firms in the Wild : Patch Now

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The Pixel Update Bulletin details security vulnerabilities and functional improvements for supported devices. Updating to the April 2024 security patch level (2024-04-05 or later) addresses all these issues and those …

VMware SD-WAN Vulnerabilities Let Attackers Execute Arbitrary Commands

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Multiple security flaws affecting VMware SD-WAN have been addressed, allowing arbitrary commands to be executed on the intended system. If these vulnerabilities are successfully exploited, enterprises that use VMware SD-WAN …

Chrome Zero-Day Vulnerability Exploited At Pwn2Own : Patch Now

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Google fixed three vulnerabilities in the Chrome browser on Tuesday, along with another zero-day exploit that was exploited during the Pwn2Own Vancouver 2024 hacking contest. Google recently fixed two more zero-day vulnerabilities …

D-Link NAS Command Injection Flaw : 92,000 Devices Affected

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A new command injection vulnerability and a backdoor account have been discovered in D-Link Network Attached Storage devices, which affects D-Link NAS devices, including DNS-340L, DNS-320L, DNS-327L, and DNS-325, among …

HTTP/2 Continuation Flood Attack : Single Machine Can Bring Down Server

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Security researcher Bartek Nowotarski disclosed a new class of vulnerabilities within the HTTP/2 protocol, known as the HTTP/2 CONTINUATION Flood. This attack vector is proving to be a significant threat, …

Center Identity Launches Patented Passwordless Authentication for Businesses

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Center Identity, a pioneering cybersecurity company, is excited to unveil its patented secret location authentication, reshaping how businesses manage workforce digital identity. This proprietary technology enables users to authenticate their …