Cisco Duo Device Health App Flaw Allows Directory Traversal Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The CryptoService function in the Cisco Duo Device Health Application for Windows has a vulnerability tracked as (CVE-2023-20229). This might allow a low-privileged attacker to carry out directory traversal attacks …

Ivanti Avalanche Flaw Let Attackers Execute Remote Code

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Ivanti Avalanche has been reported with several vulnerabilities ranging between Medium to High severity. Vulnerabilities include Arbitrary file upload remote code execution, Authentication bypass, Buffer Overflow, and Directory Traversal remote …

Discord.io Hack Was Due to a Flaw in the Website’s Code

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Discord.io experienced a significant data breach on the 14th of August 2023 that risks the privacy of about 760K consumers’ data.  The platform revealed the massive data breach on August 15th, claiming …

IBM Security Guardium Flaw Let Attacker to execute arbitrary commands

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A Command Injection vulnerability was recently discovered on IBM Security Guardium which allows threat actors to execute arbitrary commands on the affected system remotely. This vulnerability was due to improper …

New Phishing Attack Exploits Cloudflare R2 Hosting Service to Steal Cloud Passwords

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The Cloudflare R2 hosting service like the following platforms, which provides a cost-effective large-scale data storage platform to developers with no exit bandwidth charges:- Amazon S3 Google GCS Azure Blob …

New Citrix ADC Zero-Day Scanner Tool Released With IOCs

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Citrix was previously discovered with a Zero-Day vulnerability on their Citrix NetScaler Application Delivery Controller (ADC) that allowed threat actors to perform remote code execution. The Zero-Day was found to …

2000+ Citrix NetScalers Hacked to Deploy Webshell

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

It has been discovered that an attacker installed web shells on susceptible Citrix NetScalers, exploiting the CVE-2023-3519 flaw to acquire persistent access.  This critical zero-day vulnerability poses a significant risk …

Cyber Criminals Turned Mac Systems into Proxy Exit Nodes

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Besides Windows OS, now threat actors are also actively targeting Mac systems to accomplish their illicit goals. Cybersecurity analysts at AT&T Alien Labs recently observed that threat actors are actively …

Threat Actors Using ChatGPT Lure to Target iPhone and Android Users

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The “CryptoRom” scam uses ChatGPT to trick victims into downloading fake crypto-trading mobile applications. Android and iPhone users have reported increased instances of similar fraud utilizing apps from official app stores. …