CISA Warns of GeoServer RCE Vulnerability Under Active Exploitation

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent alert regarding a critical Remote Code Execution (RCE) vulnerability in GeoServer, identified as CVE-2024-36401. This vulnerability is currently under …

Pinterest Data Leak: Hackers Claiming Access to 60 Million Rows of Data

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Pinterest, the popular image-sharing platform with over 518 million monthly active users, faces a potential data leak that could affect millions of users. A hacker known as “Tchao1337” has allegedly …

Threat Actors Claims Breach of 1.1TB of Disney’s Internal Slack Chats

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Threat actors have claimed responsibility for a massive data breach involving 1.1TB of Disney’s internal Slack chats. The breach, first reported on July 12 by a hacktivist named NullBulge on …

BianLian Ransomware Leveraging RDP Credentials To Gain Initial Access

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

BianLian emerged in 2022, and after its emergence rapidly, it became one of the three most active ransomware groups.  They started their operations by exploiting RDP, ProxyShell, and SonicWall VPN …

CRYSTALRAY Hackers Exploiting Popular pentesting Tools To Evade Detections

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The threat actor Crystalray, previously observed using SSH-Snake, has significantly expanded operations, targeting over 1,500 victims.  Employing mass scanning, exploiting multiple vulnerabilities, and utilizing tools like zmap, asn, httpx, nuclei, …

Hackers Starting To Exploit The Vulnerabilities Within 22 Minutes Of PoC Release

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

The growing tension and global elections in the past year have presented major challenges to internet security, raising the volume of malicious traffic. Cloudflare cybersecurity researchers presented their Q1 2024 …

OilAlpha Hacker Group Attacking Humanitarian & Human Rights Organizations

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A pro-Houthi group, OilAlpha, is targeting humanitarian organizations in Yemen with malicious Android applications by stealing credentials and gathering intelligence, potentially disrupting aid distribution.  The applications target sensitive data and …