WordPress Plugin Flaw Exposes 200,000 WordPress Sites To Hacking

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical vulnerability was discovered on October 30th, 2024 in the Anti-Spam by CleanTalk WordPress plugin, potentially affecting over 200,000 active installations. This flaw allows unauthenticated attackers to install and …

CISA Details Red Team’s Activity Including TTPs & Network Defense

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A comprehensive Red Team Assessment (RTA) was conducted recently by the Cybersecurity and Infrastructure Security Agency (CISA) on a critical infrastructure organization in the United States. This assessment, which spanned …

7 New Flaws In Android & Google Pixel Devices Let Attackers Elevate Privileges

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Seven critical vulnerabilities affecting Android and Google Pixel devices were recently uncovered during a recent analysis of mobile applications. These security flaws, discovered through the Oversecured Mobile Application Vulnerability Scanner, …

Starbucks Hit by Ransomware Attack Via Third-party Software Supplier

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A ransomware attack on Blue Yonder, a critical supply chain management software provider, has forced Starbucks to revert to manual processes for managing employee schedules and payroll systems. The incident, …

Hackers Abuse Avast Anti-Rootkit driver To Evade Detection

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A malicious campaign has been discovered in which the malware employs a more nefarious tactic, dropping the legitimate Avast Anti-Rootkit driver (aswArPot.sys) to evade detection. The malware takes advantage of …

Critical QNAP Vulnerability Let Attackers Execute Remote Code

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Multiple vulnerabilities have been identified in QNAP’s QuRouter, specifically affecting version 2.4.x. The vulnerabilities are tracked as CVE-2024-48860 and CVE-2024-48861, which pose a serious risk as they allow remote attackers …

Explore MITRE ATT&CK Techniques in Real-World Samples With ANY.RUN TI Lookup Tool

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

In a major update aimed at revolutionizing the way cybersecurity professionals tackle threats, ANY.RUN has unveiled its redesigned Threat Intelligence (TI) Lookup platform. The latest update introduces an enhanced home …

New DocuSign Attacks Targeting Organizations Working With Government Agencies

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A new wave of sophisticated phishing attacks exploiting DocuSign has emerged, specifically targeting businesses that regularly interact with state, municipal, and licensing authorities. Cybersecurity researchers have reported a staggering 98% …

Bing.com XSS Vulnerability Let Attackers Send Crafted Malicious Requests

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A recent discovery of a cross-site scripting (XSS) vulnerability on Bing.com has raised significant security concerns, potentially allowing attackers to send crafted malicious requests across Microsoft’s interconnected applications. This vulnerability, …