Multiple Django Vulnerabilities Enables SQL Injection and Denial-of-Service Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The development team has officially released essential security updates to address two significant vulnerabilities found in the popular web framework. These issues range from high to moderate severity. They could allow attackers to compromise database integrity or crash servers through …

Chrome 143 Released With Fix for 13 Vulnerabilities that Enables Arbitrary Code Execution

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Google has officially promoted Chrome 143 to the Stable channel, rolling out version 143.0.7499.40 for Linux and 143.0.7499.40/41 for Windows and Mac. This significant update addresses 13 security vulnerabilities, including several high-severity flaws that could allow attackers to execute arbitrary …

ChatGPT Down – Users Report Outage Worldwide, Conversations Disappeared for Users

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Millions of users worldwide faced a significant disruption to their workflows early Wednesday morning as ChatGPT suffered a major service outage. The incident, which began shortly before 6:30 AM, rendered the popular AI chatbot inaccessible for many and caused alarming …

Hackers can Hijack Your Dash Cams in Seconds and Weaponize it for Future Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Dashcams have become essential devices for drivers worldwide, serving as reliable witnesses in case of accidents or roadside disputes. However, a team of Singaporean cybersecurity researchers has uncovered a disturbing reality: these seemingly harmless devices can be hijacked within seconds …

Nisos Details Earlier Signs of Insider Detection via Authentication and Access Controls

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Insider threats remain one of the most challenging security problems that organizations face today. These threats typically do not show obvious warning signs at first. Instead, they reveal themselves through small, unusual activities that often blend into normal daily operations. …

Ukraine Hackers Attacking Russian Aerospace Companies and Other Defence-Related Sectors

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Ukraine-linked hackers are stepping up cyberattacks against Russian aerospace and wider defence-related companies, using new custom malware to steal designs, schedules, and internal emails. The campaign targets both prime contractors and smaller suppliers, aiming to map production chains and expose …

Hackers Leverage Evilginx to Undermine MFA Security Mimicking Legitimate SSO Sites

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Hackers are turning to Evilginx, a powerful adversary-in-the-middle tool, to get around multi-factor authentication and take over cloud accounts. The framework acts as a reverse proxy between the victim and real single sign-on pages, so the login screen looks and …

Salty2FA and Tycoon2FA Phishing Kits Attacking Enterprise Users to Steal Login Credentials

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A new type of phishing attack that combines two different phishing kits: Salty2FA and Tycoon2FA. This marks a significant change in the Phishing-as-a-Service (PhaaS) landscape. While phishing kits typically maintain unique signatures in their code and delivery mechanisms, recent campaigns …

Water Saci Hackers Leveraging AI Tools to Attack WhatsApp Web Users

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cybercriminals targeting Brazilian users have aggressively escalated their tactics, launching a highly sophisticated campaign dubbed “Water Saci.” This new wave of attacks weaponizes WhatsApp Web, a platform implicitly trusted by millions, to deliver banking trojans and steal sensitive financial data. …

Researchers Expose Lazarus Recruitment Pipeline Live on Camera Through Honeypot Operation

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A collaborative investigation by Mauro Eldritch of BCA LTD, ANYRUN, and NorthScan has provided unprecedented visibility into how North Korean threat actors from the Lazarus Group recruit and operate against Western companies. Researchers documented the complete attack cycle in real-time, …