User ID Verification Service for TikTok, Uber, X Exposes Admin Credentials

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

AU10TIX, an Israel-based identity verification company that works with major tech platforms like TikTok, Uber, and X (formerly Twitter), inadvertently exposed a set of administrative credentials online for more than …

Hackers Leveraging CHM Files To Attack Users With Password-Protected Zip Files

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

⁤Hackers abuse CHM files because they can embed malicious scripts or code within them. Windows systems often trust and execute these files without many security checks. ⁤ When the CHM …

Polyfill JS Library Injected Malware Into 100K+ Websites

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Polyfill.js is a JavaScript library that gives modern functionality on older browsers without native support for some web features. Polyfills ensure compatibility across a wide range of browsers, enabling developers …

Researchers Released PoC For Windows Bluetooth Service RCE Vulnerability

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Microsoft addressed a Remote code execution vulnerability on their Bluetooth service on March 2023 Patch Tuesday. This vulnerability could allow an unauthorized threat actor to run a certain function on …

FireTail Unveils Free Access for All to Cutting-Edge API Security Platform

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

FireTail announces a free version of its enterprise-level API security tools, making them accessible to developers and organizations of all sizes. FireTail’s unique combination of open-source code libraries, inline API …

HC3 Unveils Qilin Ransomware Attacking Global Healthcare Organizations

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The Health Sector Cybersecurity Coordination Center (HC3) has issued a critical alert regarding a new ransomware strain, Qilin, which is targeting healthcare organizations worldwide. This revelation underscores the escalating cyber …

VMware ESXi Vulnerability Allows Attackers to Bypass Authentication

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

VMware has disclosed three critical vulnerabilities in its ESXi hypervisor that allow attackers to bypass authentication mechanisms. These vulnerabilities, identified as CVE-2024-37085, CVE-2024-37086, and CVE-2024-37087, pose significant risks to organizations …

Neiman Marcus Hacked: 64,000 customers Data Exposed

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A Luxury retailer, Neiman Marcus, has disclosed a data breach affecting approximately 64,000 customers. The incident, which came to light after an investigation, exposed sensitive customer information, including names, contact …

P2Pinfect Malware Deploy Ransomware and Cryptominer in Windows Via SSH

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cybersecurity researchers have discovered a significant evolution in the previously dormant P2Pinfect malware strain. The updated version can now deploy ransomware and a cryptominer, posing a serious threat to organizations …