Critical Vulnerability In OpenBMCs For Servers, Leads To Full Compromise

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

BMCs are specialized microcontrollers embedded in servers and other devices, responsible for monitoring and managing hardware health, including temperature, voltage, and system logs. Cybersecurity researchers at Tetrel Sec recently discovered …

Hackers Exploit PHP Vulnerability in Windows To Execute Arbitrary Code Remotely

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cybersecurity researchers at Symantec recently identified a new malware that exploits a PHP vulnerability(CVE-2024-4577) in the CGI argument injection flaw. This vulnerability affects all versions of PHP installed on the …

Hackers Exploited AWS ENV Files to Attack 110,000 Domains & Steal Credentials

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated extortion campaign targeted 110,000 domains by exploiting exposed .env files on unsecured web applications. The attackers obtained AWS IAM access keys from these files, which allowed them to …

Microsoft Launches Unified Teams App for Personal & Work Environments

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Microsoft has unveiled a significant update to its popular collaboration platform, Microsoft Teams, by launching a unified app that brings together personal, work, and education accounts in a single interface. …

Atlassian Bamboo Data Center & Server Flaw Let Attackers Execute Arbitrary Code

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Atlassian has issued a security advisory for a newly discovered high-severity vulnerability affecting its Bamboo Data Center and Server products. The vulnerability, identified as CVE-2024-21689, has a CVSS score of 7.6, …

New UULoader Attacking Users Via Weaponized PDF Documents

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Malicious .msi installers disguised as legitimate software actively target Korean and Chinese speakers by dubbing UULoader, contain a loader likely developed by a Chinese speaker, and evade detection by most …

Outlook Zero-click RCE Vulnerability Technical Details Released

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Researchers at Morphisec have uncovered critical technical details about the recently discovered zero-click remote code execution (RCE) vulnerability in Microsoft Outlook, identified as CVE-2024-38021. This vulnerability poses a significant security …

Android & iOS Users Targeted with New Phishing Attack Using PWAs & WebAPKs

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A novel type of phishing attack has been discovered, targeting both Android and iOS users. This attack combines traditional social engineering techniques with the use of Progressive Web Applications (PWAs) …

Apache DolphinScheduler Vulnerability Let Hackers Execute Remote Code

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical vulnerability has been identified in Apache DolphinScheduler, a popular open-source workflow orchestration platform. This security flaw, designated as CVE-2024-43202, allows hackers to execute remote code, posing a significant …