VLC Media Player Vulnerabilities Allow Remote Code Execution

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

VideoLAN, the organization behind the popular VLC Media Player, has disclosed multiple critical vulnerabilities that could allow attackers to execute arbitrary code remotely. These vulnerabilities affect both the desktop and …

ComfyUI Users Targeted by Malicious Code Designed to Steal Login Credentials

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The research team has recently reported a concerning incident involving the popular Stable Diffusion user interface, ComfyUI. This event has sent shockwaves through the AI community, highlighting the potential dangers …

Critical Microsoft Outlook Zero-Click RCE Flaw Executes as Email is Opened

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical zero-click remote code execution (RCE) vulnerability has been discovered in Microsoft Outlook. This vulnerability, designated as CVE-2024-30103, enables attackers to run arbitrary code by sending a specially designed …

Popular Biometric Terminal Vulnerable To QR Code SQL Injection

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A popular hybrid biometric terminal manufactured by ZKTeco has been found to have several critical vulnerabilities, including a significant flaw that allows for SQL injection via QR codes. This discovery …

APT Hackers Abusing Google & OneDrive To Host Malicious Scripts

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Threat actors are leveraging cloud storage services like Google Drive, OneDrive, and Dropbox to distribute malware and steal user information by uploading malicious files such as scripts, RAT (Remote Access …

UNC5537 Hackers Hijacking Snowflake Customer Instances

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Threat actors penetrate the networks with the aim of obtaining unauthorized access to personal and corporate details, bank accounts, and organizational resources for purposes of identity theft, fraud, and data …