Critical PHP Zero-Day Vulnerability in Craft CMS Lets Hackers Gain Remote Access

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A significant security vulnerability in Craft CMS, one of the most widely used PHP-based content management systems, has been uncovered, allowing unauthenticated remote code execution (RCE) under default configurations. The …

Researchers Exploit Reflected Input with HTTP Range Header To Bypass Browser Restriction

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Security researchers have uncovered a technique that takes previously unexploitable reflected input vulnerabilities and turns them into fully functional attacks through clever use of HTTP Range headers. The findings highlight …

WhatsApp Wins NSO Pegasus Spyware Hacking Case After 5-Year Legal Battle

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

After five years of contentious litigation, Meta Platforms Inc., the parent company of WhatsApp, emerged victorious in its lawsuit against NSO Group, the controversial Israeli firm behind the Pegasus spyware. …

McDonald’s Delivery App Vulnerability Let Anyone Place an Order for Just $0.01

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical vulnerability was found in McDonald’s McDelivery, one of India’s top food delivery apps, allowing unlimited orders for just $0.01. The flaws were identified by a researcher who conducted …

Authorities Arrested LockBit Ransomware Developer & Team Core Member

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

U.S. authorities have unveiled charges against Rostislav Panev, a dual Russian-Israeli national, for his alleged role as a key developer of the notorious LockBit ransomware group. Panev, 51, was arrested …

Malicious Apps On Amazon Appstore Records Screen & Intercept OTP’s

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Recently, researchers have discovered a relatively harmless app called “BMI CalculationVsn” on the Amazon App Store, masquerading as a normal health tool to steal data. This application performs malicious actions …

NetWalker Ransomware Operator Sentenced For Hacking Hundreds Of Organizations

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A Romanian man, Daniel Christian Hulea, 30, was sentenced to 20 years in prison for his role in the NetWalker ransomware attacks, a sophisticated cybercrime operation that targeted hundreds of …

Hackers Selling Cracked Version of Acunetix Tool as Araneida Scanner

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Threat actors reportedly sell a cracked version of Acunetix, a powerful commercial web application vulnerability scanner, for malicious purposes. The cracked software, known as the “Araneida Scanner,” is being marketed …

 Session Smart Routers With Default Passwords Hacked By Mirai Malware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Juniper Networks has issued an urgent advisory following reports of Mirai malware infections targeting Session Smart Routers (SSRs) left with default passwords. The campaign, first detected on December 11, exploited …

Siemens UMC Vulnerability Let Remote Attacker Execute Arbitrary Code

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical security flaw has been discovered in Siemens’ User Management Component (UMC), potentially exposing numerous industrial control systems to remote attacks. The vulnerability, identified as CVE-2024-49775, allows unauthenticated, remote …