WordPress Plugin Flaw Let Attackers Seize Administrative Control

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical vulnerability has been discovered in the popular Profile Builder and Profile Builder Pro plugins, with over 50,000 active installations. The flaw, identified during a routine audit of various …

CISA Warns of GeoServer RCE Vulnerability Under Active Exploitation

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent alert regarding a critical Remote Code Execution (RCE) vulnerability in GeoServer, identified as CVE-2024-36401. This vulnerability is currently under …

Pinterest Data Leak: Hackers Claiming Access to 60 Million Rows of Data

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Pinterest, the popular image-sharing platform with over 518 million monthly active users, faces a potential data leak that could affect millions of users. A hacker known as “Tchao1337” has allegedly …

Threat Actors Claims Breach of 1.1TB of Disney’s Internal Slack Chats

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Threat actors have claimed responsibility for a massive data breach involving 1.1TB of Disney’s internal Slack chats. The breach, first reported on July 12 by a hacktivist named NullBulge on …

BianLian Ransomware Leveraging RDP Credentials To Gain Initial Access

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

BianLian emerged in 2022, and after its emergence rapidly, it became one of the three most active ransomware groups.  They started their operations by exploiting RDP, ProxyShell, and SonicWall VPN …

CRYSTALRAY Hackers Exploiting Popular pentesting Tools To Evade Detections

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The threat actor Crystalray, previously observed using SSH-Snake, has significantly expanded operations, targeting over 1,500 victims.  Employing mass scanning, exploiting multiple vulnerabilities, and utilizing tools like zmap, asn, httpx, nuclei, …