Hackers Exploit PHP Vulnerability in Windows To Execute Arbitrary Code Remotely

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cybersecurity researchers at Symantec recently identified a new malware that exploits a PHP vulnerability(CVE-2024-4577) in the CGI argument injection flaw. This vulnerability affects all versions of PHP installed on the …

Hackers Exploited AWS ENV Files to Attack 110,000 Domains & Steal Credentials

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A sophisticated extortion campaign targeted 110,000 domains by exploiting exposed .env files on unsecured web applications. The attackers obtained AWS IAM access keys from these files, which allowed them to …

Microsoft Launches Unified Teams App for Personal & Work Environments

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Microsoft has unveiled a significant update to its popular collaboration platform, Microsoft Teams, by launching a unified app that brings together personal, work, and education accounts in a single interface. …

Atlassian Bamboo Data Center & Server Flaw Let Attackers Execute Arbitrary Code

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Atlassian has issued a security advisory for a newly discovered high-severity vulnerability affecting its Bamboo Data Center and Server products. The vulnerability, identified as CVE-2024-21689, has a CVSS score of 7.6, …

New UULoader Attacking Users Via Weaponized PDF Documents

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Malicious .msi installers disguised as legitimate software actively target Korean and Chinese speakers by dubbing UULoader, contain a loader likely developed by a Chinese speaker, and evade detection by most …

Outlook Zero-click RCE Vulnerability Technical Details Released

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Researchers at Morphisec have uncovered critical technical details about the recently discovered zero-click remote code execution (RCE) vulnerability in Microsoft Outlook, identified as CVE-2024-38021. This vulnerability poses a significant security …

Android & iOS Users Targeted with New Phishing Attack Using PWAs & WebAPKs

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A novel type of phishing attack has been discovered, targeting both Android and iOS users. This attack combines traditional social engineering techniques with the use of Progressive Web Applications (PWAs) …

Apache DolphinScheduler Vulnerability Let Hackers Execute Remote Code

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical vulnerability has been identified in Apache DolphinScheduler, a popular open-source workflow orchestration platform. This security flaw, designated as CVE-2024-43202, allows hackers to execute remote code, posing a significant …

Multiple F5 Flaws Let Attackers Login With User Session & Cause DoS Attack

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Two vulnerabilities have been discovered in BIG-IP, which are associated with Insufficient Session Fixation and Expired Pointer Dereference. These vulnerabilities have been assigned to CVE-2024-39809 and CVE-2024-39792, and the severity …