Critical MailCleaner Vulnerabilities Let Attackers Execute arbitrary command

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Critical vulnerabilities in MailCleaner versions before 2023.03.14 allow remote attackers to take complete control of the appliance through malicious emails, administrator interaction with attacker sites or links, and exploitation of …

Dropbox Sign Hacked: Attackers Stolen API Keys, MFA, & Hashed Passwords

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Dropbox disclosed a significant security breach affecting its electronic signature service, Dropbox Sign (formerly known as HelloSign). The incident, which came to light on April 24, involved unauthorized access to …

Hackers Infiltrated 9-days Within UnitedHealth Network Before Ransomware Attack

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Andrew Witty, CEO of UnitedHealth Group, detailed a sophisticated ransomware attack on Change Healthcare, a key component of the UnitedHealth network. The cybercriminals, identifying themselves as ALPHV or BlackCat, infiltrated …

Malware Cuckoo – Previously Unknown Infosteler Spyware Steals Data From MacOS

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Security researchers have uncovered a previously undetected malware threat for macOS that exhibits characteristics of both an infostealer and spyware. Dubbed “Cuckoo” after the brood parasitic bird, this malicious code …

Postman API Testing Platform Flaw Exposes Sensitive Credentials

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Truffle Security Co. has recently discovered a major vulnerability in Postman, the widely used API testing platform. This flaw exposed over 4,000 active credentials, creating serious security concerns for the …

Millions of Docker Hub Repositories Found Pushing Malware for Over 5 Years

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

It has been found that almost one-fifth of the repositories on Docker Hub, a popular platform for developers to store and share containerized applications, have been exploited to spread malicious …

Investigating Two TeamCity Authentication Bypass Vulnerabilities

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Vulnerability exploits are the third most common way that cybercriminals gain access to target organizations, surpassed only by credential stealing and phishing in 2023. Once illicit access is achieved, intruders …

Threat Actors Claiming of 0-Day Vulnerability in Zyxel VPN Device

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Threat actors have claimed to have discovered a 0-day vulnerability in Zyxel VPN devices. This revelation was made public through a tweet by the cybersecurity monitoring group MonThreat, which has …

Muddling Meerkat Using DNS As A Powerful Weapon For Sophistication

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Hackers exploit DNS vulnerabilities to redirect users to malicious websites, launch distributed denial-of-service (DDoS) attacks by overwhelming DNS servers, and manipulate domain resolutions to intercept traffic for surveillance or data …