Hackers Exploiting FortiClient EMS Vulnerability (CVE-2023-48788) in the Wild

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cybersecurity researchers have uncovered active exploitation of a critical vulnerability in Fortinet’s FortiClient Enterprise Management Server (EMS), tracked as CVE-2023-48788. This flaw, stemming from improper filtering of SQL commands, allows …

Hackers Exploiting Azure Key Vault Access Policies To Read Sensitive Data

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical security configuration in Azure Key Vault has been discovered, potentially allowing users with the Key Vault Contributor role to access sensitive data contrary to Microsoft’s documented intentions. This …

Europol Reveals How Cyber Criminals Boost Economy By Hacking Legal Businesses

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Europol has unveiled its latest report, “Leveraging legitimacy: How the EU’s most threatening criminal networks abuse legal business structures,” shedding light on the alarming extent to which cybercriminals are infiltrating …

Hikvision Camera Driver Vulnerability Records Login details in Log files

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A newly disclosed security vulnerability, tracked under CVE-2024-12569, has been identified in Hikvision camera drivers integrated with Milestone’s XProtect® Device Pack. This vulnerability has raised concerns as it could log …

Next.js Authorization Bypass Vulnerability Exposes Root-Level Pages

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical security vulnerability tracked as CVE-2024-51479 has been identified in Next.js, a widely used React framework for building web applications. The flaw allowed unauthorized access to certain pages directly …

New Phishing Attack Exploiting HubSpot Tools To Steal Microsoft Azure Logins

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated phishing campaign targeting European companies. The attack, which peaked in June 2024, aims to harvest Microsoft Azure cloud credentials and compromise victims’ cloud infrastructure. The campaign primarily targets …

CISA Warns of 4 New Vulnerabilities Exploited in the Wild

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

 The Cybersecurity and Infrastructure Security Agency (CISA) has added four new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, highlighting significant security risks for various devices used worldwide. These vulnerabilities, …

CISA Released National Cyber Incident Response Plan (NCIRP) – 2024

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The Cybersecurity and Infrastructure Security Agency (CISA) has unveiled an updated version of the National Cyber Incident Response Plan (NCIRP), a strategic framework for coordinating how federal, state, local, tribal, …

Fortinet Vulnerabilities Let Attackers Execute Arbitrary Code Remotely

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Fortinet, a leading cybersecurity solutions provider, has issued urgent advisories regarding two critical vulnerabilities affecting its FortiWLM and FortiManager products. These flaws could enable attackers to execute unauthorized code or …

GitHub Launches “Copilot Free” Access to 150 Million Developers

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

In a significant step towards empowering the global developer community, GitHub has announced the launch of GitHub Copilot Free an offering designed to enhance the productivity of developers, free of …