Exim SMTP Service Zero-day Flaw Let Attackers Execute Remote Code

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Six new zero-day vulnerabilities in Exim Message Transfer Agent have been reported as part of the Zero-Day initiative. These vulnerabilities were discovered in June 2022 but were not disclosed until …

New Android Banking Malware Pose as Government App to Target Users

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cybercriminals continue making malware for profit, with a recent report uncovering ASMCrypt in underground forums related to the DoubleFinger loader. In the cybercrime landscape, researchers at Securelist have also reported …

Apache NiFi RCE Vulnerability Let Attackers Exfiltrate Sensitive Data

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The widely used data integration tool Apache NiFi has been discovered to be susceptible to a critical security flaw tracked as CVE-2023-34468 that might allow remote code execution. Additionally, this significant issue might allow attackers …

BunnyLoader: New Malware-as-a-Service (MaaS) Under Rapid Development

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A new malware-as-a-service (MaaS) loader under the name “BunnyLoader” has been discovered to be sold in multiple hacking forums. This malware has multiple functionalities which include second-stage payload downloading and …

Windows Server Running SMB over QUIC Let Attacker Launch DoS Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

QUIC, created by Google, is a modern transport layer protocol aimed at enhancing connection reliability and security while addressing latency and packet loss issues utilizing UDP. Microsoft’s QUIC implementation is …

Malicious npm and PyPi Packages Exfiltrate SSH Keys From Server

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

JavaScript and Python both have their own package repositories called npm (Node Package Manager) and PyPi (Python Package Index), respectively. They act as key centers for publishing and exchanging reusable …