Researchers Detail Attacks on Air-Gapped Computers to Steal Data

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Security researchers have unveiled new techniques that allow attackers to exfiltrate sensitive data from air-gapped computers, which are systems physically isolated from unsecured networks. Despite air gaps being a strong …

Hackers Exploiting GeoServer RCE Vulnerability to Deploy Malware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

GeoServer is an open-source server for sharing geospatial data, and this open-source software server is written in Java.  It publishes data from any major spatial data source using open standards. …

Hackers Stolen 300,000 Users Personal Data in Cyber Attack at Car Rental Firm

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Avis Car Rental disclosed that hackers had stolen personal data from approximately 300,000 customers. The breach, which occurred between August 3 and August 6, 2024, was detected on August 5 …

Beware Of Malicious Chrome Extension That Delivers Weaponized ZIP Archive

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Malicious Chrome extensions pose significant risks to users, as they can compromise personal information, inject unwanted promotions, and even manipulate web traffic as well. There are several malicious extensions that …

Fog Ransomware Group Attacking Employees of Financial Services Sector

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The Fog, a ransomware variant belonging to the STOP/DJVU family that was formerly targeting educational and recreational SECTORS, has turned its attention towards profitable targets in the finance industry. In …

Kibana Vulnerabilities Let Attackers Execute Arbitrary Code

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Elastic has disclosed two critical vulnerabilities affecting Kibana, the popular data visualization and exploration tool used with Elasticsearch. These vulnerabilities, CVE-2024-37288 and CVE-2024-37285, allow attackers to execute arbitrary code through …