Apache NiFi RCE Vulnerability Let Attackers Exfiltrate Sensitive Data

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The widely used data integration tool Apache NiFi has been discovered to be susceptible to a critical security flaw tracked as CVE-2023-34468 that might allow remote code execution. Additionally, this significant issue might allow attackers …

BunnyLoader: New Malware-as-a-Service (MaaS) Under Rapid Development

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A new malware-as-a-service (MaaS) loader under the name “BunnyLoader” has been discovered to be sold in multiple hacking forums. This malware has multiple functionalities which include second-stage payload downloading and …

Windows Server Running SMB over QUIC Let Attacker Launch DoS Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

QUIC, created by Google, is a modern transport layer protocol aimed at enhancing connection reliability and security while addressing latency and packet loss issues utilizing UDP. Microsoft’s QUIC implementation is …

Malicious npm and PyPi Packages Exfiltrate SSH Keys From Server

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

JavaScript and Python both have their own package repositories called npm (Node Package Manager) and PyPi (Python Package Index), respectively. They act as key centers for publishing and exchanging reusable …

$20M Offered By Russian Zero-Day Seller To Hack Android And iPhone Devices

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The Russian company Operation Zero is currently offering researchers $20 million in exchange for hacking tools that would enable its customers to take control of Android and iPhone devices. “By …

New Ransomware Trend – Threat Actors Deploy Two Ransomware on Victims’ Networks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The FBI alerts on rising ransomware trends and urges organizations to follow mitigation recommendations for minimizing ransomware risks and consequences. In July 2023, the FBI observed two ransomware trends, and …