PoC Exploit Released For Windows Kernel-Mode Drivers Privilege Escalation Flaw

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical vulnerability in Windows Kernel-Mode Drivers has been exposed with the release of a Proof-of-Concept (PoC) exploit, allowing attackers to escalate privileges to SYSTEM level. The vulnerability, identified as …

Nation-State Actors Exploiting Ivanti CSA 0-days To Compromise Victims’ Networks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Researchers have uncovered a sophisticated attack campaign targeting Ivanti Cloud Services Appliance (CSA) users. Nation-state actors are exploiting multiple zero-day vulnerabilities in the CSA to gain unauthorized access to victims’ …

Critical Jetpack Vulnerability Impacts 27 Million Sites

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Jetpack, a popular WordPress plugin, has released a critical security update. Version 13.9.1 was launched earlier today to address a vulnerability that could potentially expose sensitive visitor information. The flaw, …

Netgear WiFi Extender Vulnerability Let Attackers Inject Malicious Commands

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Security researchers have uncovered critical vulnerabilities in several popular Netgear WiFi extender models that could allow attackers to execute malicious commands on affected devices. The flaws, tracked as CVE-2024-35518 and …

Next.js Image Optimization Vulnerability Let Attackers Exhaust CPU Resources

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical security vulnerability has been discovered in the popular React framework Next.js, potentially allowing attackers to exhaust CPU resources through its image optimization feature. The flaw, identified on October …

Multiple Splunk Enterprise Vulnerabilities Let Attackers Execute Remote Code

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Splunk has released patches for several high-severity vulnerabilities in its Enterprise product that could allow attackers to execute remote code on affected systems. The vulnerabilities impact multiple versions of Splunk …

New Supply Chain Attack Leveraging Entry Points in PyPI, npm, Ruby Gems & NuGet

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated supply chain attack has been identified, leveraging entry points in popular open-source package repositories, including PyPI (Python), npm (JavaScript), Ruby Gems, and NuGet (.NET). This attack vector poses …

CoreWarrior Malware Attacking Windows Machines With Self-replication Capabilities

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Malware targeting Windows machines continues to be a significant threat. While these threats could be in various forms like viruses, worms, and ransomware. These malicious programs can infiltrate systems via …

OilRig Hackers Exploiting Microsoft Exchange Servers To Steal Login Details

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

OilRig hackers (aka Earth Simnavaz, APT34, OilRig) is a cyber espionage group that was linked to “Iranian” interests. This APT group primarily targets energy, governmental, and critical infrastructure sectors. Cybersecurity …