Threat Actors Allegedly Selling Microsoft Office 0-Day RCE Vulnerability on Hacking Forums

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A threat actor known as Zeroplayer has reportedly listed a zero-day remote code execution (RCE) vulnerability, combined with a sandbox escape, targeting Microsoft Office and Windows systems for sale on …

Threat Actors Pioneering a New Operational Model That Combines Digital and Physical Threats

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Nation-state actors are fundamentally changing how they conduct military operations. The boundary between digital attacks and physical warfare is disappearing rapidly. Instead of treating cybersecurity and military operations as separate …

Critical N-able N-central Vulnerabilities Allow attacker to interact with legacy APIs and read sensitive files

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

N-able’s N-central remote management and monitoring (RMM) platform faces critical security risks following the discovery of multiple vulnerabilities. According to Horizon3.ai, it allows unauthenticated attackers to bypass authentication, access legacy …

Critical Twonky Server Vulnerabilities Let Attackers Bypass Authentication

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Twonky Server version 8.5.2 contains two critical authentication bypass vulnerabilities that allow unauthenticated attackers to gain full administrative access to the media server software. Rapid7 discovered that the vulnerabilities can …

Researchers Disclosed Analysis of Rhadamanthys Loader’s Anti-Sandboxing and Anti-AV Emulation Features

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Rhadamanthys has emerged as one of the most dangerous stealer malware programs since its first appearance in 2022. This advanced threat continues to challenge security teams with its ability to …

NSA Issues Guidance for ISPs and Network Defenders to Combat Malicious Activity

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The National Security Agency (NSA), in collaboration with the Cybersecurity and Infrastructure Security Agency (CISA), the FBI, and multiple international partners, has released a comprehensive cybersecurity information sheet titled “Bulletproof …

Ollama Vulnerabilities Let Attackers Execute Arbitrary Code by Parsing of Malicious Model Files

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A severe vulnerability in Ollama, one of GitHub’s most popular open-source projects, with over 155,000 stars. The flaw enables attackers to execute arbitrary code on systems running vulnerable versions of …

China-Nexus APT Group Leverages DLL Sideloading Technique to Attack Government and Media Sectors

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A targeted cyber espionage campaign has emerged across Southeast Asia, specifically affecting government and media organizations in countries surrounding the South China Sea. The campaign, which has been actively monitored …

Hackers Can Exploit Default ServiceNow AI Assistants Configurations to Launch Prompt Injection Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A dangerous vulnerability in ServiceNow’s Now Assist AI platform allows attackers to execute second-order prompt injection attacks via default agent configuration settings. The flaw enables unauthorized actions, including data theft, …

Cline AI Coding Agent Vulnerabilities Enables Prompt Injection, Code Execution, and Data Leakage

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cline is an open-source AI coding agent with 3.8 million installs and over 52,000 GitHub stars. Contains four critical security vulnerabilities that enable attackers to execute arbitrary code and exfiltrate …