IBM Cognos Analytics Vulnerability Allows Malicious File Upload & Injection Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

IBM has released a critical security update for its Cognos Analytics software, addressing two severe vulnerabilities: CVE-2023-42017 and CVE-2024-51466. These vulnerabilities could allow attackers to upload malicious files or execute Expression Language (EL) …

PHP-based Craft CMS Vulnerability Let Attackers Execute Remote Code

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical vulnerability in the popular PHP-based Craft CMS has been discovered, allowing unauthenticated attackers to execute remote code on affected systems. The security flaw, identified as CVE-2024-56145, affects default …

U.S Intelligence Agencies Launched Cyber Attack on Chinese Tech Companies

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The Chinese National Internet Emergency Center has discovered and resolved two significant cases of cyber espionage targeting Chinese technology companies and research institutions. The attacks, suspected to have been orchestrated …

Critical SHARP Routers Vulnerabilities Lets Attacker Trigger RCE to Gain Root Access

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

SHARP has issued an urgent security advisory regarding multiple vulnerabilities discovered in several of its router products. Customers using the affected devices are strongly urged to update their firmware immediately …

Weekly Cybersecurity Newsletter: Cyber Attack News, Vulnerabilities & Data Breaches

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Welcome to this week’s Cyber Security Newsletter, where we explore the latest advancements and important updates in the field of cybersecurity. Your engagement in this swiftly changing digital landscape is …

New PaaS Platform “FlowerStorm” Attacking Microsoft 365 Users

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A new phishing-as-a-service (PaaS) platform called “FlowerStorm” has emerged, targeting Microsoft 365 users. This platform has quickly gained traction following the unexpected disruption of its predecessor, Rockstar2FA, in November 2024. …

Ascension Health Hacked – Ransomware Attack Compromised 5.6 Million Patients Data

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Ascension Health, one of the largest health systems in the United States, has reported a significant data security breach that could potentially affect around 5.6 million patient records, including patients …

Mastercard Completes Acquisition of Cybersecurity Firm Recorded Future for $2.6 Billion

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Mastercard (NYSE: MA) has officially finalized the acquisition of Recorded Future, a leading provider of AI-driven threat intelligence. Mastercard Operating in over 200 countries and territories worldwide, Mastercard is a …

Critical PHP Zero-Day Vulnerability in Craft CMS Lets Hackers Gain Remote Access

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A significant security vulnerability in Craft CMS, one of the most widely used PHP-based content management systems, has been uncovered, allowing unauthenticated remote code execution (RCE) under default configurations. The …

Researchers Exploit Reflected Input with HTTP Range Header To Bypass Browser Restriction

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Security researchers have uncovered a technique that takes previously unexploitable reflected input vulnerabilities and turns them into fully functional attacks through clever use of HTTP Range headers. The findings highlight …