Users Can Be Just As Dangerous As Hackers

Blog WriterThe Hacker News - Original news source is thehackernews.com

Among the problems stemming from our systemic failure with cybersecurity, which ranges from decades-old software-development practices to Chinese and Russian cyber-attacks, one problem gets far less attention than it should—the …

Pulse Secure VPNs Get New Urgent Update for Poorly Patched Critical Flaw

Blog WriterThe Hacker News - Original news source is thehackernews.com

Pulse Secure has shipped a fix for a critical post-authentication remote code execution (RCE) vulnerability in its Connect Secure virtual private network (VPN) appliances to address an incomplete patch for …

New Amazon Kindle Bug Could’ve Let Attackers Hijack Your eBook Reader

Blog WriterThe Hacker News - Original news source is thehackernews.com

Amazon earlier this April addressed a critical vulnerability in its Kindle e-book reader platform that could have been potentially exploited to take full control over a user’s device, resulting in …

India’s Koo, a Twitter-like Service, Found Vulnerable to Critical Worm Attacks

Blog WriterThe Hacker News - Original news source is thehackernews.com

Koo, India’s homegrown Twitter clone, recently patched a serious security vulnerability that could have been exploited to execute arbitrary JavaScript code against hundreds of thousands of its users, spreading the …

VMware Issues Patches to Fix Critical Bugs Affecting Multiple Products

Blog WriterThe Hacker News - Original news source is thehackernews.com

VMware has released security updates for multiple products to address a critical vulnerability that could be exploited to gain access to confidential information. Tracked as CVE-2021-22002 (CVSS score: 8.6) and CVE-2021-22003 (CVSS score: 3.7), …

Salesforce Release Updates — A Cautionary Tale for Security Teams

Blog WriterThe Hacker News - Original news source is thehackernews.com

On the surface, Salesforce seems like a classic Software-as-a-Service (SaaS) platform. Someone might even argue that Salesforce invented the SaaS market. However, the more people work with the full offering …

A Wide Range of Cyber Attacks Leveraging Prometheus TDS Malware Service

Blog WriterThe Hacker News - Original news source is thehackernews.com

Multiple cybercriminal groups are leveraging a malware-as-a-service (MaaS) solution to distribute a wide range of malicious software distribution campaigns that result in the deployment of payloads such as Campo Loader, Hancitor, IcedID, QBot, Buer Loader, …

Unpatched Security Flaws Expose Mitsubishi Safety PLCs to Remote Attacks

Blog WriterThe Hacker News - Original news source is thehackernews.com

Multiple unpatched security vulnerabilities have been disclosed in Mitsubishi safety programmable logic controllers (PLCs) that could be exploited by an adversary to acquire legitimate user names registered in the module …