Technical Details Released for ‘SynLapse’ RCE Vulnerability Reported in Microsoft Azure

Blog WriterThe Hacker News - Original news source is thehackernews.com

Microsoft has incorporated additional improvements to address the recently disclosed SynLapse security vulnerability in order to meet comprehensive tenant isolation requirements in Azure Data Factory and Azure Synapse Pipelines. The …

Patch Tuesday: Microsoft Issues Fix for Actively Exploited ‘Follina’ Vulnerability

Blog WriterThe Hacker News - Original news source is thehackernews.com

Microsoft officially released fixes to address an actively exploited Windows zero-day vulnerability known as Follina as part of its Patch Tuesday updates. Also addressed by the tech giant are 55 …

Unpatched Travis CI API Bug Exposes Thousands of Secret User Access Tokens

Blog WriterThe Hacker News - Original news source is thehackernews.com

June 14, 2022Ravie Lakshmanan An unpatched security issue in the Travis CI API has left tens of thousands of developers’ user tokens exposed to potential attacks, effectively allowing threat actors …

New Zimbra Email Vulnerability Could Let Attackers Steal Your Login Credentials

Blog WriterThe Hacker News - Original news source is thehackernews.com

June 14, 2022Ravie Lakshmanan A new high-severity vulnerability has been disclosed in the Zimbra email suite that, if successfully exploited, enables an unauthenticated attacker to steal cleartext passwords of users …

Researchers Disclose Rooting Backdoor in Mitel IP Phones for Businesses

Blog WriterThe Hacker News - Original news source is thehackernews.com

Cybersecurity researchers have disclosed details of two medium-security flaws in Mitel 6800/6900 desk phones that, if successfully exploited, could allow an attacker to gain root privileges on the devices. Tracked …

Chinese Hackers Distribute Backdoored Web3 Wallets for iOS and Android Users

Blog WriterThe Hacker News - Original news source is thehackernews.com

A technically sophisticated threat actor known as SeaFlower has been targeting Android and iOS users as part of an extensive campaign that mimics official cryptocurrency wallet websites intending to distribute …

Chinese ‘Gallium’ Hackers Using New PingPull Malware in Cyberespionage Attacks

Blog WriterThe Hacker News - Original news source is thehackernews.com

June 13, 2022Ravie Lakshmanan A Chinese advanced persistent threat (APT) known as Gallium has been observed using a previously undocumented remote access trojan in its espionage attacks targeting companies operating …

HelloXD Ransomware Installing Backdoor on Targeted Windows and Linux Systems

Blog WriterThe Hacker News - Original news source is thehackernews.com

June 13, 2022Ravie Lakshmanan Windows and Linux systems are being targeted by a ransomware variant called HelloXD, with the infections also involving the deployment of a backdoor to facilitate persistent …